Tag: update
-
Apple Security Update Addresses Critical Font Parser Vulnerability Across Multiple Platforms
Apple has rolled out a series of important security updates across multiple platforms, addressing a vulnerability affecting the system font parser. These Apple security updates cover iOS, iPadOS, macOS, visionOS, watchOS, and tvOS. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/apple-security-updates/
-
Feed mit Indicators of Compromise von Artic Wolf für eigene Sicherheitslösungen
Arctic Wolf gibt Erweiterungen für Arctic-Wolf-Threat-Intelligence-Plus bekannt. Mit diesen haben Unternehmen die Möglichkeit, denselben hochwertigen Feed mit Indicators of Compromise (IoCs) einzusetzen, den auch das KI-gestützte Security-Operations-Center (SOC) von Arctic Wolf nutzt und zwar direkt in ihren vorhandenen Sicherheitslösungen. Durch das Update von Threat-Intelligence-Plus werden Unternehmen dabei unterstützt, sich proaktiv vor adaptiven Cyberbedrohungen zu […]…
-
Windows 11 KB5065789 update released with 41 changes and fixes
Microsoft has released the KB5065789 preview cumulative update for Windows 11 24H2, which includes 41 improvements, including new AI actions in File Explorer and bug fixes for Windows Update and Windows Sandbox. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5065789-update-released-with-41-changes-and-fixes/
-
Broadcom fixes high-severity VMware NSX bugs reported by NSA
Broadcom has released security updates to patch two high-severity VMware NSX vulnerabilities reported by the U.S. National Security Agency (NSA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/broadcom-fixes-high-severity-vmware-nsx-bugs-reported-by-nsa/
-
Weiterhin Ausnahmesituation Angriff auf Berliner Flughafen
First seen on security-insider.de Jump to article: www.security-insider.de/cyberangriff-berliner-flughafen-ransomware-a-4cb1a58bbad2f0e9d9df7e25a8e63ff6/
-
Apple Font Parser Vulnerability Allowing Memory Corruption Attacks
Apple has released a security update for macOS Sequoia 15.7.1 to address a serious vulnerability in its font parser. The flaw, tracked as CVE-2025-43400, allows a maliciously crafted font file to trigger an out-of-bounds write. Exploitation could cause unexpected application crashes or corrupt process memory on affected systems. Apple patched this issue on September 29, 2025, as…
-
KI-Gefahren rücken Integritätsschutz in den Mittelpunkt
Tags: ai, ciso, cloud, compliance, cyberattack, data, data-breach, DSGVO, exploit, governance, injection, LLM, ml, risk, tool, training, updateData Poisoning gefährdet die Integrität von KI-Modellen.Für CISOs reduziert KI selten die Komplexität, sondern füllt vielmehr ihre ohnehin schon volle Agenda. Neben den traditionellen Sicherheitsprioritäten müssen sie sich nun auch mit neuen KI-bedingten Risiken auseinandersetzen, etwa wenn KI-Lösungen unkontrolliert für geschäftliche Zwecke genutzt, Modelle manipuliert und neue Vorschriften nicht eingehalten werden. Eine der drängendsten Herausforderungen…
-
Unpatched Cognex Cameras Expose Industrial Systems
Cognex Says It Won’t Patch Flaws. Nearly a dozen serious vulnerabilities in a Cognex industrial smart camera will go without a patch because the company says the model is too old to merit a fix. Industrial security firm Nozomi Networks uncovered nine flaws during a security assessment. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/unpatched-cognex-cameras-expose-industrial-systems-a-29592
-
CISA orders feds to patch Cisco flaws used in multiple agency hacks
One U.S. official called the ongoing cyberattack campaign “very sophisticated.” First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-emergency-directive-cisco-vulnerabilities-arcanedoor/761150/
-
Chinese hackers breached critical infrastructure globally using enterprise network gear
Tags: access, backdoor, breach, business, china, communications, control, cve, defense, exploit, framework, germany, government, group, hacker, infrastructure, Internet, korea, law, malware, military, monitoring, network, open-source, penetration-testing, programming, service, threat, tool, update, vpn, vulnerability72-hour vulnerability exploitation window: RedNovember demonstrated the ability to weaponize newly disclosed vulnerabilities faster than most organizations could deploy patches, researchers found. When researchers published proof-of-concept code for Check Point VPN vulnerability CVE-2024-24919 on May 30, 2024, RedNovember was attacking vulnerable systems by June 3.That campaign hit at least 60 organizations across Brazil, Germany, Japan,…
-
âš¡ Weekly Recap: Cisco 0-Day, Record DDoS, LockBit 5.0, BMC Bugs, ShadowV2 Botnet & More
Cybersecurity never stops”, and neither do hackers. While you wrapped up last week, new attacks were already underway.From hidden software bugs to massive DDoS attacks and new ransomware tricks, this week’s roundup gives you the biggest security moves to know. Whether you’re protecting key systems or locking down cloud apps, these are the updates you…
-
China Prepares for Cyberattacks
China has implemented regulations for 1-hour reporting of severe cybersecurity incidents. This would include disruptions that impact over 50% of the people in a province or 10 million people, such as critical infrastructure attacks. The irony is that China is recognized for its advanced and aggressive foreign cyber operations. But there is brilliance in this…
-
Meet LockBit 5.0: Faster ESXi drive encryption, better at evading detection
the Windows binary uses heavy obfuscation and packing: it loads its payload through DLL reflection while implementing anti-analysis techniques like Event Tracing for Windows (ETW) patching and terminating security services;the Linux variant maintains similar functionality with command-line options for targeting specific directories and file types;the ESXi variant specifically targets VMware virtualization environments, and is designed…
-
CISA Orders Urgent Patching of Cisco Firewall Zero-Day Vulnerabilities
CISA warns of active Cisco ASA exploits. Patch now to block remote code execution and privilege escalation risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/cisa-urgent-patch-cisco-firewall/
-
Cybersecurity Snapshot: CISA Highlights Vulnerability Management Importance in Breach Analysis, as Orgs Are Urged To Patch Cisco Zero-Days
Tags: 2fa, access, advisory, api, attack, authentication, breach, business, cisa, cisco, cloud, control, credentials, crime, cve, cyber, cybersecurity, data, defense, endpoint, exploit, fido, finance, firewall, framework, github, grc, guide, identity, incident response, infrastructure, Internet, ISO-27001, kev, law, lessons-learned, malicious, malware, mfa, mitigation, monitoring, network, open-source, phishing, privacy, ransomware, risk, saas, scam, security-incident, service, soc, software, supply-chain, tactics, threat, update, vpn, vulnerability, vulnerability-management, worm, zero-dayCISA’s takeaways of an agency hack include a call for timely vulnerability patching. Plus, Cisco zero-day bugs are under attack, patch now. Meanwhile, the CSA issued a framework for SaaS security. And get the latest on the npm breach, the ransomware attack that disrupted air travel and more! Here are six things you need to…
-
Attackers exploited critical Fortra GoAnywhere flaw in zero-day attacks (CVE-2025-10035)
CVE-2025-10035, a perfect CVSS 10.0 vulnerability in the Fortra GoAnywhere managed file transfer solution, has apparently been exploited in zero-day attacks before the patch … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/09/26/fortra-goanywhere-zero-day-cve-2025-10035/
-
Agencies Around the Globe Urge Patching of Cisco ASA Bug Under Active Exploit
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Emergency Directive 25-03 in response to an ongoing and severe cybersecurity threat targeting vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Cisco Firepower devices. The directive mandates immediate action from all federal civilian executive branch agencies to identify and mitigate potential compromises affecting vulnerable systems.…
-
Microsoft releases the final Windows 10 22H2 preview update
Microsoft has released the final non-security preview update for Windows 10, version 22H2, which includes fixes for the out-of-box experience and SMBv1 protocol connectivity. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-releases-the-final-windows-10-22h2-preview-update/
-
MS-Account vorausgesetzt Update – – Europa erhält Windows-10-Updates ein Jahr (ohne Auflagen)
Im Europäischen Wirtschaftsraum erleichtert Microsoft den Zugang zu Windows-10-Sicherheitsupdates, wenn der offizielle Support endet. First seen on computerbase.de Jump to article: www.computerbase.de/news/betriebssysteme/12-monate-aufschub-europa-erhaelt-windows-10-updates-fuer-ein-jahr-ohne-auflagen.94469
-
UK and US security agencies order urgent fixes as Cisco firewall bugs exploited in wild
CISA gives feds 24 hours to patch, NCSC urges rapid action as flaws linked to ArcaneDoor spies First seen on theregister.com Jump to article: www.theregister.com/2025/09/26/cisco_firewall_flaws/
-
MS-Account vorausgesetzt Update – – Europa erhält Windows-10-Updates ein Jahr (ohne Auflagen)
Im Europäischen Wirtschaftsraum erleichtert Microsoft den Zugang zu Windows-10-Sicherheitsupdates, wenn der offizielle Support endet. First seen on computerbase.de Jump to article: www.computerbase.de/news/betriebssysteme/12-monate-aufschub-europa-erhaelt-windows-10-updates-fuer-ein-jahr-ohne-auflagen.94469
-
UK and US security agencies order urgent fixes as Cisco firewall bugs exploited in wild
CISA gives feds 24 hours to patch, NCSC urges rapid action as flaws linked to ArcaneDoor spies First seen on theregister.com Jump to article: www.theregister.com/2025/09/26/cisco_firewall_flaws/
-
Deutsche Umwelthilfe: Microsofts Update-Pläne für Windows 10 sind Augenwischerei
Umwelt- und Verbraucherschützer sind unzufrieden mit Microsofts kostenlosen Windows-10-Updates für ein weiteres Jahr. Der Vorstoß geht ihnen nicht weit genug. First seen on golem.de Jump to article: www.golem.de/news/deutsche-umwelthilfe-microsofts-update-plaene-fuer-windows-10-sind-augenwischerei-2509-200536.html
-
Deutsche Umwelthilfe: Microsofts Update-Pläne für Windows 10 sind Augenwischerei
Umwelt- und Verbraucherschützer sind unzufrieden mit Microsofts kostenlosen Windows-10-Updates für ein weiteres Jahr. Der Vorstoß geht ihnen nicht weit genug. First seen on golem.de Jump to article: www.golem.de/news/deutsche-umwelthilfe-microsofts-update-plaene-fuer-windows-10-sind-augenwischerei-2509-200536.html
-
Microsoft knickt ein: Künftige Windows-10-Updates werden noch kostenloser
Zumindest Privatnutzer aus Europa brauchen nur einen Microsoft-Account, um nach Oktober 2025 weiter Updates für Windows 10 zu beziehen. First seen on golem.de Jump to article: www.golem.de/news/microsoft-knickt-ein-kuenftige-windows-10-updates-werden-noch-kostenloser-2509-200527.html
-
New XCSSET Malware Variant Targets macOS App Developers
Cybersecurity researchers have discovered an advanced variant of the XCSSET malware specifically targeting macOS developers through infected Xcode projects, introducing sophisticated clipboard hijacking and enhanced data exfiltration capabilities. Microsoft Threat Intelligence has identified yet another XCSSET variant in the wild that introduces further updates and new modules beyond those detailed in previous security analyses. The…
-
Cisco’s Wave of Actively Exploited Zero-Day Bugs Targets Firewalls, IOS
Patch now: Cisco recently disclosed four actively exploited zero-days affecting millions of devices, including three targeted by a nation-state actor previously discovered to be behind the ArcaneDoor campaign. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cisco-actively-exploited-zero-day-bugs-firewalls-ios

