Tag: cyber
-
Acronis Cyber Protect Sicherheitslücken gefährden Windows-Systeme
Kurzer Hinweis für Nutzer, die Acronis Cyber Protect in einer Windows-Umgebung einsetzen. Es gibt eine aktuelle Sicherheitswarnung des Bundesamts für Sicherheit in der Informationstechnik (BSI). Demnach sind mehrere Schwachstellen im Produkt bekannt geworden, die die Sicherheit von Windows gefährden. Acronis … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/10/acronis-cyber-protect-sicherheitsluecken-gefaehrden-windows-systeme/
-
SAP Security Patch Day: 14 Vulnerabilities Resolved Across Various Products
SAP’s June 10, 2025 Security Patch Day delivered critical security updates addressing 14 distinct vulnerabilities across the enterprise software portfolio. The security notes span severity levels from Critical (CVSS 9.6) to Low (CVSS 3.0), encompassing core platform components, business applications, and integration frameworks. Organizations are strongly advised to prioritize patch deployment based on vulnerability severity…
-
Exploitation of Critical Wazuh Server RCE Vulnerability Leads to Mirai Variant Deployment
The Akamai Security Intelligence and Response Team (SIRT) has uncovered active exploitation of a critical remote code execution (RCE) vulnerability in Wazuh servers, identified as CVE-2025-24016 with a CVSS score of 9.9. Disclosed in February 2025, this vulnerability affects Wazuh versions 4.4.0 through 4.9.0 and stems from unsafe deserialization in the Distributed API (DAPI) requests,…
-
Sensata Technologies Faces Disruption Due to Ransomware Attack
Sensata Technologies, Inc., a major technology company based in Attleboro, Massachusetts, has disclosed a significant cybersecurity incident that compromised personal information of hundreds of individuals. The external system breach, discovered in late May, affected at least 362 Maine residents and potentially thousands more across the United States, prompting the company to offer comprehensive identity protection…
-
M&S resumes online orders six weeks after cyber-attack
Retailer estimated to have lost about £25m a week after it was forced to pause online shopping<ul><li><a href=”https://www.theguardian.com/business/live/2025/jun/10/us-china-trade-talks-resume-uk-jobs-market-weakening-payrolls-tumble-growth-economy-business-live-news”>Business live latest updates</li></ul>Marks & Spencer has reopened its website to shoppers, six weeks after it was forced to halt online orders after a cyber-attack.On its website, M&S said customers “can now place online orders with standard delivery…
-
China-linked threat actor targeted +70 orgs worldwide, SentinelOne warns
Tags: attack, china, cyber, cyberespionage, cybersecurity, espionage, government, infrastructure, threatChina-linked threat actor targeted over 70 global organizations, including governments and media, in cyber-espionage attacks from July 2024 to March 2025. In April 2025, cybersecurity firm SentinelOne warned that a China-linked threat actor, tracked as PurpleHaze, attempted to conduct reconnaissance on its infrastructure and high-value clients. The activity suggests targeted cyberespionage efforts aimed at gathering…
-
How to Protect Against Cyber Threats Before They Hit
TechRepublic consolidated expert advice on how businesses can defend themselves against the most common cyberthreats, including zero-days, ransomware and deepfakes. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/how-to-defend-businesses-against-cyber-threats/
-
Vulnerability in DanaBot Malware C2 Server Leaks Threat Actor Usernames and Crypto Keys
Tags: breach, control, crypto, cyber, cybersecurity, data, infrastructure, leak, malicious, malware, threat, vulnerabilityA severe vulnerability in the command-and-control (C2) infrastructure of the notorious DanaBot malware has been uncovered, potentially exposing critical data belonging to threat actors. Researchers have identified a misconfiguration in the server setup that inadvertently leaks usernames and cryptographic keys used by malicious operators to manage their campaigns. This breach could provide cybersecurity defenders with…
-
Over 84,000 Roundcube Webmail Installations Exposed to Remote Code Vulnerabilities
Security researchers have identified a critical vulnerability in Roundcube Webmail that affects over 84,000 unpatched installations worldwide, according to data from The Shadowserver Foundation. The vulnerability, designated CVE-2025-49113, enables authenticated attackers to execute arbitrary code remotely and has already been exploited in targeted attacks potentially conducted by state actors. The vulnerability affects all Roundcube versions…
-
Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprises
The threat actor known as Rare Werewolf (formerly Rare Wolf) has been linked to a series of cyber attacks targeting Russia and the Commonwealth of Independent States (CIS) countries.”A distinctive feature of this threat is that the attackers favor using legitimate third-party software over developing their own malicious binaries,” Kaspersky said. “The malicious functionality of…
-
M&S website resumes online orders six weeks after cyber-attack
Retailer estimated to have lost about £25m a week after it was forced to pause online shopping<ul><li><a href=”https://www.theguardian.com/business/live/2025/jun/10/us-china-trade-talks-resume-uk-jobs-market-weakening-payrolls-tumble-growth-economy-business-live-news”>Business live latest updates</li></ul>Marks & Spencer has reopened its website to shoppers, six weeks after it was forced to halt online orders after a cyber-attack.The retailer said on its website that customers “can now place online orders with…
-
ManageEngine Exchange Reporter Plus Vulnerability Enables Remote Code Execution
A critical security vulnerability has been discovered in ManageEngine Exchange Reporter Plus, a popular email monitoring and reporting solution, that could allow attackers to execute arbitrary commands on target servers. The vulnerability, assigned CVE-2025-3835, affects all builds up to version 5721 and has been addressed in the emergency security update released on May 29, 2025.…
-
Hit by a cyber-attack? Seven ways to protect yourself
As big companies become victims, here’s what you can do, from changing passwords to using two-step authenticationAlmost every week seems to bring news of a cyber-attack on a company, or organisation, and fears over what personal data the hackers have managed to get hold of. <a href=”https://www.theguardian.com/money/2025/jun/10/cyber-attack-ways-to-protect-passwords-two-step-authentication”>Continue reading… First seen on theguardian.com Jump to article:…
-
The legal questions to ask when your systems go dark
At Span Cyber Security Arena, I sat down with Iva MiÅ¡ković, Partner at the ISO-certified MiÅ¡ković MiÅ¡ković law firm, to discuss the role of legal teams during cyber … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/06/10/iva-miskovic-law-firm-cyber-legal-stategy/
-
Google Vulnerability Allowed Hackers to Access User Phone Numbers
A security researcher has disclosed a critical vulnerability in Google’s account recovery system that allowed attackers to brute-force and obtain the phone numbers of any Google user. The vulnerability , discovered in 2025, exploited Google’s username recovery form that continued to function without JavaScript, bypassing modern security protections and enabling systematic phone number enumeration attacks.…
-
Cyberangriff auf einen Sportverband in Großbritannien
BHA believed to be latest organisation to be hit by a cyber attack First seen on racingpost.com Jump to article: www.racingpost.com/news/britain/bha-believed-to-be-latest-organisation-to-be-hit-by-a-cyber-attack-arubK5n9AzDw/
-
New Trump Cybersecurity Order Reverses Biden, Obama Priorities
The White House put limits on cyber sanctions, killed the digital ID program, and refocused the government’s cyber activities to enabling AI, rolling out post-quantum cryptography, and promoting secure software design. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/trump-cybersecurity-order-reverses-biden-obama-priorities
-
EU Updates Cyber Crisis Blueprint to Strengthen Regional Response
First seen on scworld.com Jump to article: www.scworld.com/brief/eu-updates-cyber-crisis-blueprint-to-strengthen-regional-response
-
Black Kite Launches AI Cyber Assessments to Streamline Third-Party Risk at Scale
First seen on scworld.com Jump to article: www.scworld.com/news/black-kite-launches-ai-cyber-assessments-to-streamline-third-party-risk-at-scale
-
Connected and exposed: Building a cyber future America can trust
First seen on scworld.com Jump to article: www.scworld.com/perspective/connected-and-exposed-building-a-cyber-future-america-can-trust
-
MSSPs, MSPs See Growing Strategic Role in Cyber Insurance
First seen on scworld.com Jump to article: www.scworld.com/news/mssps-msps-see-growing-strategic-role-in-cyber-insurance
-
HostBreach Offers Free Cyber Snapshot For CMMC Compliance Requirements
Philadelphia-based cybersecurity firm HostBreach is offering a free CMMC Cyber Snapshot to businesses looking to maintain CMMC compliance. In particular, this refers to government contractors (GovCon) and federal contractors so they can organise their cybersecurity posture pending the Cybersecurity Maturity Model Certification (CMMC) 2.0 standards. This free offer comes at the right time, with the Department of…
-
Brett Leatherman to follow Bryan Vorndran as head of FBI Cyber Division
A longtime FBI official with deep cybersecurity experience is the new leader for the bureau’s Cyber Division. First seen on therecord.media Jump to article: therecord.media/brett-leatherman-fbi-cyber-replacing-bryan-vorndran
-
FBI veteran Brett Leatherman to lead Cyber division
Tags: cyberLeatherman, a 22-year FBI veteran, has been heavily involved in cyber investigations as section chief and deputy assistant director over the past three years. First seen on cyberscoop.com Jump to article: cyberscoop.com/fbi-cyber-division-brett-leatherman-assistant-director/
-
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS
SentinelLABS uncovers widespread China-linked cyber espionage targeting over 70 global organizations and cybersecurity firms between July 2024 and… First seen on hackread.com Jump to article: hackread.com/chinese-linked-hackers-targeted-global-organizations/
-
New Report Reveals Chinese Hackers Attempted to Breach SentinelOne Servers
SentinelLABS, a sophisticated reconnaissance operation targeting SentinelOne, a leading cybersecurity vendor, has been detailed as part of a broader espionage campaign linked to China-nexus threat actors. Tracked under the activity clusters PurpleHaze and ShadowPad, these operations spanned from July 2024 to March 2025, affecting over 70 organizations worldwide across sectors like government, media, manufacturing, finance,…
-
Bitter Malware Employs Custom-Built Tools to Evade Detection in Advanced Attacks
In a recent research by Proofpoint and Threatray has unveiled the intricate and evolving malware arsenal of the Bitter group, also known as TA397, believed to be a state-backed actor aligned with the interests of the Indian government. Active since 2016, Bitter has transformed its operations from deploying rudimentary downloaders to orchestrating sophisticated Remote Access…
-
Over 70 Organizations Across Multiple Sectors Targeted by China-Linked Cyber Espionage Group
The reconnaissance activity targeting American cybersecurity company SentinelOne was part of a broader set of partially-related intrusions into several targets between July 2024 and March 2025.”The victimology includes a South Asian government entity, a European media organization, and more than 70 organizations across a wide range of sectors,” security researchers Aleksandar Milenkoski and Tom First…

