CISA added 5 critical vulnerabilities to its Known Exploited list, affecting Advantive VeraCore and Ivanti Endpoint Manager.
These flaws are actively being exploited, putting your systems at risk of remote access and credential theft.
Get the full details here: https://thehackernews.com/2025/03/cisa-adds-five-actively-exploited.html
These flaws are actively being exploited, putting your systems at risk of remote access and credential theft.
Get the full details here: https://thehackernews.com/2025/03/cisa-adds-five-actively-exploited.html
π13π₯2π1π1
β οΈ A critical flaw (CVE-2024-12297) in Moxa PT switches could let attackers bypass authentication, with a CVSS score of 9.2/10.
This could lead to unauthorized access or service disruptions.
Protect your systems now: https://thehackernews.com/2025/03/moxa-issues-fix-for-critical.html
This could lead to unauthorized access or service disruptions.
Protect your systems now: https://thehackernews.com/2025/03/moxa-issues-fix-for-critical.html
π9π₯6π€―1
SideWinder APT is still targeting high-profile sectors like maritime, nuclear energy, and consulting.
Their main tactic: spear-phishing emails with malicious documents about critical infrastructures.
Get the full details here: https://thehackernews.com/2025/03/sidewinder-apt-targets-maritime-nuclear.html
Their main tactic: spear-phishing emails with malicious documents about critical infrastructures.
Get the full details here: https://thehackernews.com/2025/03/sidewinder-apt-targets-maritime-nuclear.html
β‘8
Identity-based attacks are escalating, and traditional security isnβt sufficient.
Misconfigurations, excessive permissions, and stolen credentials in SaaS apps cause 61% of data breaches.
Learn to secure your SaaS environment here: https://thehackernews.com/expert-insights/2025/03/identity-attacksprevention-isnt-enough.html
Misconfigurations, excessive permissions, and stolen credentials in SaaS apps cause 61% of data breaches.
Learn to secure your SaaS environment here: https://thehackernews.com/expert-insights/2025/03/identity-attacksprevention-isnt-enough.html
π₯6π2π1
β οΈ A new botnet, Ballista, is exploiting unpatched TP-Link Archer routers through the CVE-2023-1389 vulnerability.
This critical flaw allows attackers to execute remote code, triggering widespread malware infections. Thousands of devices, including those in healthcare and manufacturing, are at risk.
Read the full analysis here: https://thehackernews.com/2025/03/ballista-botnet-exploits-unpatched-tp.html
This critical flaw allows attackers to execute remote code, triggering widespread malware infections. Thousands of devices, including those in healthcare and manufacturing, are at risk.
Read the full analysis here: https://thehackernews.com/2025/03/ballista-botnet-exploits-unpatched-tp.html
π10π6π₯5π3β‘1
Cybercriminals are hiding malware in images, making it nearly invisible to security tools.
A harmless landscape photo πΌοΈ could be carrying a payload that steals data or takes over your system. Traditional security tools miss this, leaving you exposed.
Learn how to protect your systems: https://thehackernews.com/2025/03/steganography-explained-how-xworm-hides.html
A harmless landscape photo πΌοΈ could be carrying a payload that steals data or takes over your system. Traditional security tools miss this, leaving you exposed.
Learn how to protect your systems: https://thehackernews.com/2025/03/steganography-explained-how-xworm-hides.html
π₯33π±5β‘2π2π€―1
π¨ Apple just patched a zero-day under active attack!
CVE-2025-24201 lets hackers escape the WebKit sandboxβApple calls the exploit βextremely sophisticated.β
Targeted? Unknown
Duration? Unknown
But if you use an iPhone, Mac, or Vision Proβupdate NOW.
π² Details: https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html
CVE-2025-24201 lets hackers escape the WebKit sandboxβApple calls the exploit βextremely sophisticated.β
Targeted? Unknown
Duration? Unknown
But if you use an iPhone, Mac, or Vision Proβupdate NOW.
π² Details: https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html
π₯23π8β‘4π€3π2π€―1
β‘ Proactive security > Reactive fixes.
ASPM's "shift-left" approach empowers teams to prevent vulnerabilities BEFORE they spread. Don't miss out on how this could save you time and money.
π Learn more in this expert webinar β https://thehacker.news/aspm-future-appsec
ASPM's "shift-left" approach empowers teams to prevent vulnerabilities BEFORE they spread. Don't miss out on how this could save you time and money.
π Learn more in this expert webinar β https://thehacker.news/aspm-future-appsec
π9
π¨ 6,000+ fake Play Store pages exposed!
PlayPraetor Trojan malware is tricking users into downloading apps that steal banking info, intercept 2FA, and spy on you. CTM360 uncovered this global scam, where cybercriminals use realistic fake pages to hijack devices and steal data.
Protect yourself:
β Download from trusted stores only
β Check reviews & permissions
β Use mobile security tools
π Full report: https://thehackernews.com/expert-insights/2025/03/ctm360-uncovers-large-scale-fake-play.html
PlayPraetor Trojan malware is tricking users into downloading apps that steal banking info, intercept 2FA, and spy on you. CTM360 uncovered this global scam, where cybercriminals use realistic fake pages to hijack devices and steal data.
Protect yourself:
β Download from trusted stores only
β Check reviews & permissions
β Use mobile security tools
π Full report: https://thehackernews.com/expert-insights/2025/03/ctm360-uncovers-large-scale-fake-play.html
π16π4π€―1
π¨ UPDATE: Microsoft has uncovered major upgrades in the latest XCSSET variant:
β οΈ New persistence method β Uses dockutil to swap in a fake Launchpad app, ensuring the malware runs every time you open it.
β οΈ Stronger obfuscation β Harder to detect, harder to analyze.
β οΈ Still spreading via Xcode projects β Developers, your builds could be compromised.
This marks the first major XCSSET update since 2022βand it's more deceptive than ever. Inspect Xcode projects carefully.
π More details: https://thehackernews.com/2025/02/microsoft-uncovers-new-xcsset-macos.html
β οΈ New persistence method β Uses dockutil to swap in a fake Launchpad app, ensuring the malware runs every time you open it.
β οΈ Stronger obfuscation β Harder to detect, harder to analyze.
β οΈ Still spreading via Xcode projects β Developers, your builds could be compromised.
This marks the first major XCSSET update since 2022βand it's more deceptive than ever. Inspect Xcode projects carefully.
π More details: https://thehackernews.com/2025/02/microsoft-uncovers-new-xcsset-macos.html
π8π4π±2π€1
This media is not supported in your browser
VIEW IN TELEGRAM
π₯ Microsoft warns: 6 zero-days under active attack!
This monthβs Patch Tuesday fixes 57 security flaws, including 6 exploited zero-days that attackers are already using for privilege escalation, data theft, and remote code execution.
πΉ Key threats:
CVE-2025-24985 & CVE-2025-24993 β File system flaws allowing remote code execution
CVE-2025-24983 β A Win32k zero-day used in the wild with PipeMagic malware
CVE-2025-26633 β Security bypass flaw in Microsoft Management Console
CISA has mandated patches by April 1. Donβt waitβsecure your systems now!
π Full patch details: https://thehackernews.com/2025/03/urgent-microsoft-patches-57-security.html
This monthβs Patch Tuesday fixes 57 security flaws, including 6 exploited zero-days that attackers are already using for privilege escalation, data theft, and remote code execution.
πΉ Key threats:
CVE-2025-24985 & CVE-2025-24993 β File system flaws allowing remote code execution
CVE-2025-24983 β A Win32k zero-day used in the wild with PipeMagic malware
CVE-2025-26633 β Security bypass flaw in Microsoft Management Console
CISA has mandated patches by April 1. Donβt waitβsecure your systems now!
π Full patch details: https://thehackernews.com/2025/03/urgent-microsoft-patches-57-security.html
π22π7π2π€―1
Do you know how secure your software supply chain really is?
According to ActiveState's 2025 State of Vulnerability Management and Remediation Report, DevSecOps pros signaled a 54% YoY increase in high-risk vulnerabilitiesβdownload the FREE report to learn how to stay ahead of the curve.
https://thn.news/vulnerability-report-2025
According to ActiveState's 2025 State of Vulnerability Management and Remediation Report, DevSecOps pros signaled a 54% YoY increase in high-risk vulnerabilitiesβdownload the FREE report to learn how to stay ahead of the curve.
https://thn.news/vulnerability-report-2025
π€―5π1π±1
π¨ Massive SSRF Attack Surge Detected π
GreyNoise warns of a coordinated wave of SSRF exploits hitting at least 400 IPsβtargeting U.S., Germany, Singapore, Israel, and more.
π΄ Exploiting multiple CVEs at once, including:
β’ CVE-2020-7796 (Zimbra, CVSS 9.8)
β’ CVE-2021-22175 (GitLab, CVSS 9.8)
β’ CVE-2023-5830 (ColumbiaSoft, CVSS 9.8)
π Automated? Pre-compromise recon? Either wayβpatch now, restrict outbound traffic, and monitor logs.
Details: https://thehackernews.com/2025/03/over-400-ips-exploiting-multiple-ssrf.html
GreyNoise warns of a coordinated wave of SSRF exploits hitting at least 400 IPsβtargeting U.S., Germany, Singapore, Israel, and more.
π΄ Exploiting multiple CVEs at once, including:
β’ CVE-2020-7796 (Zimbra, CVSS 9.8)
β’ CVE-2021-22175 (GitLab, CVSS 9.8)
β’ CVE-2023-5830 (ColumbiaSoft, CVSS 9.8)
π Automated? Pre-compromise recon? Either wayβpatch now, restrict outbound traffic, and monitor logs.
Details: https://thehackernews.com/2025/03/over-400-ips-exploiting-multiple-ssrf.html
π€―9π₯5π3β‘2π€2
With a Georgetown master's you'll gain the tactical skills to plan for, respond to, and mitigate cyber security threats.
View event: https://thn.news/cyber-risk-webinar-2025-li
View event: https://thn.news/cyber-risk-webinar-2025-li
π6π3π€2
π¨ China-backed hackers are hitting routersβundetected.
UNC3886 is targeting Juniper Networks routers, deploying stealthy TinyShell-based backdoors to control critical infrastructure. These implants evade security, disable logs, and hijack SSH credsβall in silence. π
Mandiant warns: "Long-term persistence, minimal detection."
Why does this matter? Routers are now the frontline. If theyβre compromised, so is everything behind them.
π Details on the latest cyber espionage:
https://thehackernews.com/2025/03/chinese-hackers-breach-juniper-networks.html
UNC3886 is targeting Juniper Networks routers, deploying stealthy TinyShell-based backdoors to control critical infrastructure. These implants evade security, disable logs, and hijack SSH credsβall in silence. π
Mandiant warns: "Long-term persistence, minimal detection."
Why does this matter? Routers are now the frontline. If theyβre compromised, so is everything behind them.
π Details on the latest cyber espionage:
https://thehackernews.com/2025/03/chinese-hackers-breach-juniper-networks.html
π19π5β‘4π₯4π±4
π¨ UPDATE: Garantex Co-Founder ARRESTED in India!
Besciokov was caught in Thiruvananthapuram while trying to flee after a U.S. extradition request (March 10). He was vacationing in Varkala when Indiaβs CBI moved in.
More: https://thehackernews.com/2025/03/us-secret-service-seizes-russian.html
Besciokov was caught in Thiruvananthapuram while trying to flee after a U.S. extradition request (March 10). He was vacationing in Varkala when Indiaβs CBI moved in.
More: https://thehackernews.com/2025/03/us-secret-service-seizes-russian.html
π±11π4π3
π¨ Firefox Warning: Update Before March 14.
A critical root certificate will expire on March 14, 2025. If youβre using an old Firefox version (before 128 or ESR 115.13+), your add-ons may stop working, DRM media could break, and security features may fail.
π’ Fix it now: Update to Firefox 128+ (or ESR 115.13+) to avoid issues.
π Read: https://thehackernews.com/2025/03/warning-expiring-root-certificate-may.html
A critical root certificate will expire on March 14, 2025. If youβre using an old Firefox version (before 128 or ESR 115.13+), your add-ons may stop working, DRM media could break, and security features may fail.
π’ Fix it now: Update to Firefox 128+ (or ESR 115.13+) to avoid issues.
π Read: https://thehackernews.com/2025/03/warning-expiring-root-certificate-may.html
π23π₯8π3π€2
π¨ Critical Alert: A severe vulnerability (CVE-2025-27363) in the FreeType font library, used by millions, is being actively exploited.
This flaw allows RCE, risking numerous systems. Affected platforms include Linux distributions, Android, and iOS.
Read: https://thehackernews.com/2025/03/meta-warns-of-freetype-vulnerability.html
Update to FreeType version 2.13.3 immediately to protect your devices. Act now!
This flaw allows RCE, risking numerous systems. Affected platforms include Linux distributions, Android, and iOS.
Read: https://thehackernews.com/2025/03/meta-warns-of-freetype-vulnerability.html
Update to FreeType version 2.13.3 immediately to protect your devices. Act now!
π₯20π€―9π2π±2β‘1
π΄ ruby-saml Flaws Open SAML Auth to Hijacking
GitHub Security Lab found CVE-2025-25291 & CVE-2025-25292 (CVSS 8.8) in ruby-saml, allowing attackers to bypass authentication using a valid signature.
π Read: https://thehackernews.com/2025/03/github-uncovers-new-ruby-saml.html
π Update now or risk account takeover.
GitHub Security Lab found CVE-2025-25291 & CVE-2025-25292 (CVSS 8.8) in ruby-saml, allowing attackers to bypass authentication using a valid signature.
π Read: https://thehackernews.com/2025/03/github-uncovers-new-ruby-saml.html
π Update now or risk account takeover.
π€―9π4β‘1π₯1
What are the top priorities for security teams in 2025? And what's threatening to derail them?
IDC asked 900+ security leaders across the US, Europe, and Australia. In a webinar on March 26, Voice of Security 2025 sponsors Tines and AWS will unpack the results.
Join them to uncover:
πΈ How AI and automation are transforming security strategies
πΈ The biggest challenges leaders face - and whatβs holding them back
πΈ What drives job satisfaction (and frustration) in security leadership
πΈ Where tooling helps vs. where itβs adding to the pain
πΈ What leaders look for when hiring security analysts
Sign up for a deep dive into the data: https://thn.news/voice-of-security-2025-x
IDC asked 900+ security leaders across the US, Europe, and Australia. In a webinar on March 26, Voice of Security 2025 sponsors Tines and AWS will unpack the results.
Join them to uncover:
πΈ How AI and automation are transforming security strategies
πΈ The biggest challenges leaders face - and whatβs holding them back
πΈ What drives job satisfaction (and frustration) in security leadership
πΈ Where tooling helps vs. where itβs adding to the pain
πΈ What leaders look for when hiring security analysts
Sign up for a deep dive into the data: https://thn.news/voice-of-security-2025-x
Tines
Voice of Security 2025 - Essential insights from 900 security leaders | Tines
Mar 26 2025, 11:00 AM β’ US Eastern Time β’ Learn what 900+ security leaders think about people, processes, and technologies this year, and uncover how to build a more resilient security strategy with your team in 2025 and beyond.
π7π1