Friday, November 21, 2025
Follow on LinkedIn

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless three-year campaign delivering BadAudio, a highly obfuscated first-stage downloader...
Broadcom Allegedly Breached

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of an ongoing exploitation campaign targeting Oracle E-Business Suite vulnerabilities. The...
Critical Grafana Vulnerability

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers to escalate privileges and impersonate users. The flaw, tracked as CVE-2025-41115,...

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers to execute malicious code with elevated system privileges. The flaw,...
Windows 11 Hide Crash Errors

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors and signage. This new mode ensures that the dreaded...
SonicOS SSLVPN Vulnerability

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service...

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The new system represents a significant leap in agentic AI capabilities,...
CSN

Cybersecurity Newsletter

Subscribe to the Cybersecurity News Briefing for the latest updates on cyber attacks, Threats, vulnerabilities, and expert insights.

Cyber News Weekly

Beware of Phishing Emails as Spam Filter Alerts Steal...

Cybercriminals have launched a new phishing campaign that tricks users by impersonating legitimate spam-filter notifications from their own company. These fake emails claim that your...
SonicOS SSLVPN Vulnerability

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service...

Hackers Using Leverage Tuoni C2 Framework Tool to Stealthily...

A new wave of cyberattacks has emerged using the Tuoni Command and Control (C2) framework, a sophisticated tool that allows threat actors to deploy...

Princeton University Data Breach – Database with Donor Info...

Princeton University faced a security incident on November 10, 2025, when outside attackers gained unauthorized access to a database managed by the University Advancement...
Google Chrome 0-Day Vulnerability Exploited

CISA Warns of Google Chrome 0-Day Vulnerability Exploited in...

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert about a zero-day vulnerability in Google Chrome, actively exploited by threat...

Expert Analysis

Oracle E-Business Suite Hack

Lessons from Oracle E-Business Suite Hack That Allegedly Compromises Nearly 30...

A sophisticated cyberattack targeting Oracle E-Business Suite (EBS) customers has exposed critical vulnerabilities in enterprise resource planning systems, compromising an estimated 100 organizations worldwide...
Calendar Files Weaponized as Attack Vector

Hackers Weaponizing Calendar Files as New Attack Vector Bypassing Traditional Email...

A surge in attacks exploiting iCalendar (.ics) files as a sophisticated threat vector that bypasses traditional email security defenses. These attacks leverage the trusted,...
Black Friday Scams

10 Popular Black Friday Scams – How to Detect the Red...

Black Friday 2025 represents the most dangerous shopping season in cybercrime history, with fraudsters leveraging artificial intelligence, deepfake technology, and sophisticated social engineering tactics...
AI Tools Promoted by Threat Actors

List of AI Tools Promoted by Threat Actors in Underground Forums...

The cybercrime landscape has undergone a dramatic transformation in 2025, with artificial intelligence emerging as a cornerstone technology for malicious actors operating in underground...

AI-Powered Ransomware Is the Emerging Threat That Could Bring Down Your...

The cybersecurity landscape has entered an unprecedented era of sophistication with the emergence of AI-powered ransomware attacks. Recent research from MIT Sloan and Safe...
Windows Command-line Utility PsExec

How Windows Command-line Utility PsExec Can Be Abused To Execute Malicious...

PsExec represents one of the most contradictory tools in the cybersecurity landscape, a legitimate system administration utility that has become a cornerstone of malicious...

Top Research and Review

Best Supply Chain Intelligence Security Companies

Top 10 Best Supply Chain Intelligence Security Companies in 2025

The digital world continues to face growing threats around software vulnerabilities, data breaches, and cyber supply chain attacks. As companies rely more heavily on...
Best Fraud Prevention Companies

Top 10 Best Fraud Prevention Companies in 2025

In 2025, digital transactions are at an all-time high, but so are the risks of fraud. Businesses in banking, e-commerce, fintech, and even social...
Best Digital Footprint Monitoring Tools

Top 10 Best Digital Footprint Monitoring Tools For Organizations in 2025

In today’s hyperconnected digital environment, organizations face increasing threats to their online presence and reputations. From cyberattacks and phishing campaigns to data breaches and...
Best Account Takeover Protection Tools

Top 10 Best Account Takeover Protection Tools in 2025

Account Takeover (ATO) attacks have become one of the most pressing security concerns for businesses in 2025. With the rise of credential stuffing, phishing,...
Best Brand Protection Solutions For Enterprises

Top 10 Best Brand Protection Solutions for Enterprises in 2025

Brand protection solutions are essential for enterprises in 2025 as digital commerce continues to grow and online threats evolve more rapidly than ever. With...
Best Digital Risk Protection (DRP) Platforms

Top 10 Best Digital Risk Protection (DRP) Platforms in 2025

In 2025, businesses are facing unprecedented challenges in the digital risk landscape. With cyber threats evolving rapidly, organizations need advanced solutions to detect, assess,...

Cyberpedia