New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module

26/09/2025 0 Comments 0 tags

Cybersecurity researchers have discovered an updated version of a known Apple macOS malware called XCSSET that has been observed in limited attacks. “This new variant of XCSSET brings key changes

Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure

26/09/2025 0 Comments 0 tags

Cybersecurity company watchTowr Labs has disclosed that it has “credible evidence” of active exploitation of the recently disclosed security flaw in Fortra GoAnywhere Managed File Transfer (MFT) software as early

Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware

26/09/2025 0 Comments 0 tags

The U.K. National Cyber Security Centre (NCSC) has revealed that threat actors have exploited the recently disclosed security flaws impacting Cisco firewalls as part of zero-day attacks to deliver previously

Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network

25/09/2025 0 Comments 0 tags

The threat actor known as Vane Viper has been outed as a purveyor of malicious ad technology (adtech), while relying on a tangled web of shell companies and opaque ownership

Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive

25/09/2025 0 Comments 0 tags

Cisco is urging customers to patch two security flaws impacting the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD)

Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection

25/09/2025 0 Comments 0 tags

Cybersecurity researchers have disclosed a critical flaw impacting Salesforce Agentforce, a platform for building artificial intelligence (AI) agents, that could allow attackers to potentially exfiltrate sensitive data from its customer

North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers

25/09/2025 0 Comments 0 tags

The North Korea-linked threat actors associated with the Contagious Interview campaign have been attributed to a previously undocumented backdoor called AkdoorTea, along with tools like TsunamiKit and Tropidoor. Slovak cybersecurity

Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More

25/09/2025 0 Comments 0 tags

/* ===== Container ===== */ .td-wrap {} /* ===== Section ===== */ .td-section { } .td-title { margin: 16px 0 4px; font-size: 32px; line-height: 1.2; font-weight: 800; } .td-subtitle {

CTEM’s Core: Prioritization and Validation

25/09/2025 0 Comments 0 tags

Despite a coordinated investment of time, effort, planning, and resources, even the most up-to-date cybersecurity systems continue to fail. Every day. Why?  It’s not because security teams can’t see enough.

Tech Overtakes Gaming as Top DDoS Attack Target, New Gcore Radar Report Finds

25/09/2025 0 Comments 0 tags

The latest Gcore Radar report analyzing attack data from Q1–Q2 2025, reveals a 41% year-on-year increase in total attack volume. The largest attack peaked at 2.2 Tbps, surpassing the 2