🚨A SharePoint zero-day (CVE-2025-53770) is under active exploitation, with attackers stealing MachineKey secrets to forge __VIEWSTATE and maintain RCE. No patch exists.
If you expose SharePoint to the Internet, assume breach. Reach out to via our website if you need support.
"Threat intelligence researchers are warning of hackers breaching multiple U.S. companies in the insurance industry using all the tactics observed with Scattered Spider activity."
https://t.co/GXeRO78glE
China and the US are locked in a constant struggle for information, using cyber espionage to gain strategic advantage. Recently leaked files have shed light on rapid advances in China’s cyber capabilities as both nations prepare for any future conflict. https://t.co/kNpzpLEwr5
.@CatoNetworks demonstrated how a threat intelligence researcher with no prior malware coding experience was able to trick popular large language model (LLM) tools to develop a Google Chrome infostealer. #cybersecurity#infosec#AI#ITsecurity https://t.co/vSNUfKD9G1
"The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence." https://t.co/f9nCgxvLwr
It is only a matter of time before a business is attacked. And when that happens, you're either in a resilient position, or you're not. Be proactive. Get your organization assessed and get those vulnerabilities resolved before they can be exploited. https://t.co/zxT6S3RG88
'Darcula' Phishing Kit Can Now Impersonate Any Brand
With Version 3, would-be phishers can cut and paste a big brand's URL into a template and let automation do the rest.
https://t.co/ZCu66D7DYg
“Ivanti has released updates for Ivanti Connect Secure (ICS),Ivanti Policy Secure (IPS) and Ivanti Secure Access Client (ISAC) which addresses medium, high and critical severity vulnerabilities.” https://t.co/yD3fDfo2c4
"Fortinet warned today that attackers are exploiting another authentication bypass zero-day bug in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks." https://t.co/klgd6tRPzp
https://t.co/4pmzaohatS "CISA warned U.S. federal agencies on Thursday to secure their systems against ongoing attacks targeting a critical Microsoft Outlook remote code execution (RCE) vulnerability."
"The hack of a company that helps schools track tens of millions of students appears to be the largest breach of American children’s personal information to date, school officials and cybersecurity experts say."
https://t.co/Z6YFXmh7Od #MFA#cyberattack#hacking#infosec
"SonicWall said in an advisory that the vulnerability in its SMA1000 remote access appliance allows anyone over the Internet to plant malware on affected devices without needing a login for the system." https://t.co/ioeHgdPnG6