Fortinet Urges FortiSwitch Upgrades to Patch Critical Admin Password Change Flaw

08/04/2025 0 Comments 0 tags

Fortinet has released security updates to address a critical security flaw impacting FortiSwitch that could permit an attacker to make unauthorized password changes. The vulnerability, tracked as CVE-2024-48887, carries a

Cryptocurrency Miner and Clipper Malware Spread via SourceForge Cracked Software Listings

08/04/2025 0 Comments 0 tags

Threat actors have been observed distributing malicious payloads such as cryptocurrency miner and clipper malware via SourceForge, a popular software hosting service, under the guise of cracked versions of legitimate

Amazon EC2 SSM Agent Flaw Patched After Privilege Escalation via Path Traversal

08/04/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a now-patched security flaw in the Amazon EC2 Simple Systems Manager (SSM) Agent that, if successfully exploited, could permit an attacker to achieve privilege

CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active Exploitation

08/04/2025 0 Comments 0 tags

A recently disclosed critical security flaw impacting CrushFTP has been added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities (KEV) catalog after reports emerged

UAC-0226 Deploys GIFTEDCROOK Stealer via Malicious Excel Files Targeting Ukraine

08/04/2025 0 Comments 0 tags

The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed a new set of cyber attacks targeting Ukrainian institutions with information-stealing malware. The activity is aimed at military formations, law

Agentic AI in the SOC – Dawn of Autonomous Alert Triage

08/04/2025 0 Comments 0 tags

Security Operations Centers (SOCs) today face unprecedented alert volumes and increasingly sophisticated threats. Triaging and investigating these alerts are costly, cumbersome, and increases analyst fatigue, burnout, and attrition. While artificial

Google Releases Android Update to Patch Two Actively Exploited Vulnerabilities

08/04/2025 0 Comments 0 tags

Google has shipped patches for 62 vulnerabilities, two of which it said have been exploited in the wild. The two high-severity vulnerabilities are listed below – CVE-2024-53150 (CVSS score: 7.8)

CISA and FBI Warn Fast Flux is Powering Resilient Malware, C2, and Phishing Networks

07/04/2025 0 Comments 0 tags

Cybersecurity agencies from Australia, Canada, New Zealand, and the United States have published a joint advisory about the risks associated with a technique called fast flux that has been adopted

⚡ Weekly Recap: VPN Exploits, Oracle’s Silent Breach, ClickFix Comeback and More

07/04/2025 0 Comments 0 tags

Today, every unpatched system, leaked password, and overlooked plugin is a doorway for attackers. Supply chains stretch deep into the code we trust, and malware hides not just in shady

Security Theater: Vanity Metrics Keep You Busy – and Exposed

07/04/2025 0 Comments 0 tags

After more than 25 years of mitigating risks, ensuring compliance, and building robust security programs for Fortune 500 companies, I’ve learned that looking busy isn’t the same as being secure.