Three critical security flaws have been disclosed in an open-source utility called #Picklescan that could allow malicious actors to execute arbitrary code by loading untrusted #PyTorch models, effectively bypassing the tool's protections.#2025 #Infosec#BT
https://t.co/WmfCnl5he9
#AsahiGroupHoldings, Japan’s largest beer producer, has finished the investigation into the September cyberattack and found that the incident has impacted up to 1.9 million individuals.#2025 #Infosec#BT
https://t.co/bJEHwKVmYq
https://t.co/tDYJZGomD7
The U.S. Cybersecurity and Infrastructure Security Agency #CISA has updated its Known Exploited Vulnerabilities (KEV) catalog to include a security flaw impacting OpenPLC ScadaBR, citing evidence of active exploitation.#2025 #Infosec#BT
https://t.co/d5n4SjGwY7
The threat actor known as #Tomiris has been attributed to attacks targeting foreign ministries, intergovernmental organizations, and government entities in Russia with an aim to establish remote access and deploy additional tools.#2025 #Infosec#BT
https://t.co/KvtD2awHJi
#ASUS has released new firmware to patch nine security vulnerabilities, including a critical authentication bypass flaw in routers with #AiCloud enabled. #2025 #Infosec#BT
https://t.co/R8JzHwEl6N
https://t.co/tDYJZGomD7
Cybersecurity researchers have discovered a new malicious extension #ChromeWebStore that's capable of injecting a stealthy #Solana transfer into a swap transaction and transferring the funds to an cryptocurrency wallet.#2025 #Infosec#BT
https://t.co/NHsPWYDh0Z
South Korea's financial sector has been targeted by what has been described as a sophisticated supply chain attack that led to the deployment of #Qilin#ransomware.#2025 #Infosec#BT
https://t.co/7gouvDbfmf
https://t.co/tDYJZGomD7
Harvard University disclosed over the weekend that its Alumni Affairs and Development systems were compromised in a voice #phishing attack, exposing the personal information of students, alumni, donors, staff, and faculty members.#2025 #Infosec#BT
https://t.co/O0Ay9NfRR8
New research from CrowdStrike has revealed that DeepSeek's artificial intelligence (AI) reasoning model DeepSeek-R1 produces more security vulnerabilities in response to prompts that contain topics deemed politically sensitive by China.#2025 #Infosec#BT
https://t.co/3SO4Y5N9mr
Multiple security vendors are sounding the alarm about a second wave of attacks targeting the npm registry in a manner that's reminiscent of the Shai-Hulud attack.#2025 #Infosec#BT
https://t.co/sqYO7fNNEl
https://t.co/pbZKTHAt1N
While #DevOps drives innovation and simplifies collaboration, it also comes with its own set of risks and vulnerabilities. Developers rely on Git-based platforms like #GitHub#Azure DevOps #Bitbucket or #GitLab to work on code.#2025 #Infosec#BT
https://t.co/QQVFSwhOyy
The threat actor known as #PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed #EdgeStepper to facilitate adversary-in-the-middle (AitM) attacks.#2025 #Infosec#BT
https://t.co/OiZhLTXtqb
A newly discovered campaign has compromised tens of thousands of outdated or end-of-life (EoL) ASUS routers worldwide, predominantly in Taiwan, the U.S., and Russia, to rope them into a massive network.#2025 #Infosec#BT
https://t.co/d39eIdwtzR
https://t.co/tDYJZGomD7
The #DanaBot#malware has returned with a new version observed in attacks, six-months after law enforcement's Operation Endgame disrupted its activity in May.#2025 #Infosec#BT
https://t.co/Lx0liIUpvw
https://t.co/tDYJZGomD7
#Google has filed a civil lawsuit in the U.S. District Court for the Southern District of New York #SDNY against China-based hackers who are behind a massive Phishing-as-a-Service #PhaaS platform called Lighthouse.#2025 #Infosec#BT
https://t.co/xtEXDoiWNz
#Microsoft on Tuesday released patches for 63 new security vulnerabilities identified in its software, including one that has come under active exploitation in the wild.#2025 #Infosec#BT
https://t.co/v3ElQEpW7v
https://t.co/tDYJZGomD7
Three newly disclosed vulnerabilities in the runC container runtime used in Docker and Kubernetes could be exploited to bypass isolation restrictions and get access to the host system.#2025 #2025 #Infosec#BT
https://t.co/FtC8wd0cLa
Cybersecurity researchers have called attention to a massive phishing campaign targeting the hospitality industry that lures hotel managers to #ClickFix-style pages and harvest their credentials by deploying malware like #PureRAT.#2025 #Infosec#BT
https://t.co/RpkzaJC4Mj
Cyber threats didn't slow down last week—and attackers are getting smarter. We're seeing malware hidden in virtual machines, side-channel leaks exposing AI chats, and spyware quietly targeting Android devices in the wild.#2025 #Infosec#BT
https://t.co/E05EPmdoZT