Friday, November 21, 2025
Follow on LinkedIn
SonicOS SSLVPN Vulnerability

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service...

OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently

OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The new system represents a significant leap in agentic AI capabilities,...

Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations

The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions against Media Land. This Russia-based bulletproof hosting company provides infrastructure...
Salesforce Gainsight Breach

Salesforce Confirms that Customers’ Data Was Accessed Following the Gainsight Breach

Salesforce has issued a critical security alert identifying "unusual activity" involving Gainsight-published applications connected to customer environments. The CRM giant’s investigation indicates that this activity...
Oracle Breach Clop Ransomware

Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The notorious Clop ransomware gang has listed Oracle on its dark web leak site, alleging a successful breach of the tech giant's internal systems. This...
Critical Windows Graphics Vulnerability

Critical Windows Graphics Vulnerability Lets Hackers Seize Control with a Single Image

A critical remote code execution flaw in Microsoft's Windows Graphics Component allows attackers to seize control of systems using specially crafted JPEG images. With a...

Tsundere Botnet Abusing Popular Node.js and Cryptocurrency Packages to Attack Windows, Linux, and macOS...

Tsundere represents a significant shift in botnet tactics, leveraging the power of legitimate Node.js packages and blockchain technology to distribute malware across multiple operating...
CSN

Cybersecurity Newsletter

Subscribe to the Cybersecurity News Briefing for the latest updates on cyber attacks, Threats, vulnerabilities, and expert insights.

Cyber News Weekly

IBM AIX Vulnerabilities

IBM AIX Vulnerabilities Let Remote Attacker Execute Arbitrary Commands

IBM has released critical security updates addressing two severe vulnerabilities in its AIX operating system that could allow remote attackers to execute arbitrary commands...
XWiki Vulnerability Exploited in the Wild

Hackers Exploiting XWiki Vulnerability in the Wild to Hire...

A sharp increase in attacks targeting a critical vulnerability in XWiki servers. Multiple threat actors are actively exploiting CVE-2025-24893 to deploy botnets and coin miners, and...
pi GPT Tool for Raspberry Pi

pi GPT Tool Turns Your Raspberry Pi into A...

pi GPT, a custom integration for OpenAI's ChatGPT that transforms everyday Raspberry Pi devices into fully managed AI-powered workstations. Announced on November 18, 2025, this...

A Multi-Stage Phishing Kit Using Telegram to Harvest Credentials...

Phishing attacks continue to be one of the most persistent threats targeting organizations worldwide. Cybercriminals are constantly improving their methods to steal sensitive information, and...
Oracle Breach Clop Ransomware

Oracle Allegedly Breached by Clop Ransomware via E-Business Suite...

The notorious Clop ransomware gang has listed Oracle on its dark web leak site, alleging a successful breach of the tech giant's internal systems. This...

Expert Analysis

Oracle E-Business Suite Hack

Lessons from Oracle E-Business Suite Hack That Allegedly Compromises Nearly 30...

A sophisticated cyberattack targeting Oracle E-Business Suite (EBS) customers has exposed critical vulnerabilities in enterprise resource planning systems, compromising an estimated 100 organizations worldwide...
Calendar Files Weaponized as Attack Vector

Hackers Weaponizing Calendar Files as New Attack Vector Bypassing Traditional Email...

A surge in attacks exploiting iCalendar (.ics) files as a sophisticated threat vector that bypasses traditional email security defenses. These attacks leverage the trusted,...
Black Friday Scams

10 Popular Black Friday Scams – How to Detect the Red...

Black Friday 2025 represents the most dangerous shopping season in cybercrime history, with fraudsters leveraging artificial intelligence, deepfake technology, and sophisticated social engineering tactics...
AI Tools Promoted by Threat Actors

List of AI Tools Promoted by Threat Actors in Underground Forums...

The cybercrime landscape has undergone a dramatic transformation in 2025, with artificial intelligence emerging as a cornerstone technology for malicious actors operating in underground...

AI-Powered Ransomware Is the Emerging Threat That Could Bring Down Your...

The cybersecurity landscape has entered an unprecedented era of sophistication with the emergence of AI-powered ransomware attacks. Recent research from MIT Sloan and Safe...
Windows Command-line Utility PsExec

How Windows Command-line Utility PsExec Can Be Abused To Execute Malicious...

PsExec represents one of the most contradictory tools in the cybersecurity landscape, a legitimate system administration utility that has become a cornerstone of malicious...

Top Research and Review

Best Supply Chain Intelligence Security Companies

Top 10 Best Supply Chain Intelligence Security Companies in 2025

The digital world continues to face growing threats around software vulnerabilities, data breaches, and cyber supply chain attacks. As companies rely more heavily on...
Best Fraud Prevention Companies

Top 10 Best Fraud Prevention Companies in 2025

In 2025, digital transactions are at an all-time high, but so are the risks of fraud. Businesses in banking, e-commerce, fintech, and even social...
Best Digital Footprint Monitoring Tools

Top 10 Best Digital Footprint Monitoring Tools For Organizations in 2025

In today’s hyperconnected digital environment, organizations face increasing threats to their online presence and reputations. From cyberattacks and phishing campaigns to data breaches and...
Best Account Takeover Protection Tools

Top 10 Best Account Takeover Protection Tools in 2025

Account Takeover (ATO) attacks have become one of the most pressing security concerns for businesses in 2025. With the rise of credential stuffing, phishing,...
Best Brand Protection Solutions For Enterprises

Top 10 Best Brand Protection Solutions for Enterprises in 2025

Brand protection solutions are essential for enterprises in 2025 as digital commerce continues to grow and online threats evolve more rapidly than ever. With...
Best Digital Risk Protection (DRP) Platforms

Top 10 Best Digital Risk Protection (DRP) Platforms in 2025

In 2025, businesses are facing unprecedented challenges in the digital risk landscape. With cyber threats evolving rapidly, organizations need advanced solutions to detect, assess,...

Cyberpedia