A critical Fortinet FortiWeb auth bypass (CVE-2025-64446) is being actively exploited, giving attackers full control of vulnerable devices. CISA has added it to the KEV with a Nov 21 deadline. Learn about the exploit, affected versions, & mitigation steps: https://bit.ly/4o0shEt
15.11.2025 02:27 β π 0 π 0 π¬ 0 π 0
Oracle has issued its third Critical Patch Update of the year, addressing 374 vulnerabilities across its portfolio. Oracle Communications received the most fixes, followed by Communications Applications and Financial Services. Read the full analysis: https://bit.ly/4noXkd5
23.10.2025 15:19 β π 0 π 0 π¬ 0 π 0
F5 has disclosed a long-term breach by a nation-state attacker involving stolen BIG-IP source code & unpatched vulnerabilities. With CISA warning of an imminent threat, organizations must quickly identify exposed assets & speed up remediation. Read more: https://bit.ly/4oy4nRG
21.10.2025 00:27 β π 0 π 1 π¬ 0 π 0
Oracle addressed a high-severity vulnerability in its E-Business Suite. Exploitation could let an unauthenticated remote attacker compromise Oracle Configurator Runtime UI. Read the blog for affected versions and mitigation guidance: https://bit.ly/3W5B4cU
#ThreatProtection
14.10.2025 22:59 β π 1 π 0 π¬ 0 π 0
Expert-led cybersecurity training at #ROCon25. Hereβs a glimpse as our instructor walks through the 5 Steps to TruRisk Reduction dashboard β demonstrating how to identify what truly needs your focus across complex vulnerability data.
#RiskManagement
14.10.2025 19:50 β π 0 π 0 π¬ 0 π 0
This monthβs @MsftSecIntel Patch Tuesday fixes 193 vulnerabilities, including 9 Critical & 6 zero-days, with 4 actively exploited & 2 publicly disclosed. Get the details in this blog: https://bit.ly/48vQNcH.
Join the @Qualys TRU webinar this Thursday: https://bit.ly/474T78a
14.10.2025 19:45 β π 0 π 0 π¬ 0 π 0
Broadcom addressed a critical CVE in VMwareβs guest service discovery features. Exploitation could allow an unprivileged user to escalate privileges to root on the same VM. Researchers confirmed that it has been exploited in the wild. Learn more: https://bit.ly/4mKu9Rq
02.10.2025 15:28 β π 0 π 0 π¬ 0 π 0
Researchers discovered a malicious modification in the npm package postmark-mcp. By adding a blind copy to an external domain, attackers secretly exfiltrated email contents. This is the first known case of an MCP server exploited in the wild. Blog: https://bit.ly/474o8dy
30.09.2025 19:28 β π 0 π 0 π¬ 0 π 0
SolarWinds fixed a critical CVE in its Web Help Desk software. Successful exploitation of the flaw could allow an unauthenticated attacker to execute arbitrary code on the target system. Learn more about the vulnerability, affected versions & mitigation: https://bit.ly/46yJPAZ
26.09.2025 21:06 β π 0 π 0 π¬ 0 π 0
@Cisco patched a critical zero-day flaw in IOS & IOS XE Software. Exploitation could let low-privileged attackers cause DoS, while high-privileged attackers could execute code as root and fully compromise systems. Read the blog for mitigation details: https://bit.ly/3IChLok
25.09.2025 23:16 β π 0 π 0 π¬ 0 π 0
Fortra released security updates for a critical flaw (CVE-2025-10035) in GoAnywhere MFT License Servlet. With a CVSS of 10, exploitation could allow unauthenticated remote code execution. Learn more in this blog: https://bit.ly/4nkBFDA
#ThreatProtection #VulnerabilityManagement
23.09.2025 16:41 β π 0 π 0 π¬ 0 π 0
Attackers exploited SharePoint ToolShell flaws to hit 145+ orgs, incl. US agencies. The campaign persisted even after patches with stealth tactics. Saeed Abbasi of @qualys.bsky.social says that when patching isnβt possible, use advanced remediation: https://bit.ly/3K6LbeU via @ismsonline.bsky.social
19.09.2025 17:45 β π 1 π 0 π¬ 0 π 0
Google released security updates to fix a critical CVE in the Chrome browser. Successful exploitation of the type confusion flaw in the V8 JavaScript & WebAssembly engine, has already been observed in the wild by Google Threat Analysis Group. Learn more: https://bit.ly/42EBpa1
19.09.2025 13:40 β π 0 π 0 π¬ 0 π 0
Over 400 npm packages have been compromised in in an ongoing supply chain attack. With 2.6B weekly downloads, thousands of apps are at risk, along with likelihood of further impact. No patches yes, users should uninstall the affected packages. Learn more: https://bit.ly/3IpDoZ3
17.09.2025 20:07 β π 0 π 0 π¬ 0 π 0
Ivanti released its Sept security bulletin, addressing 13 CVEs across its popular products. There is currently no evidence of active exploitation.
Get the details in this blog, including exploitation methods, affected versions, & detection steps: https://bit.ly/46kQWNs
#VulnerabilityManagement
12.09.2025 20:55 β π 0 π 0 π¬ 0 π 0
Apple addressed a critical CVE across its operating systems, including macOS & iOS. The flaw could be exploited through a malicious image file to cause memory corruption. The vulnerability is already being exploited in the wild.
Learn more in this blog: https://bit.ly/3JlkzGJ
#ThreatProtection
22.08.2025 23:57 β π 0 π 0 π¬ 0 π 0
Big win at #DefCon33! Qualys Threat Research Unit (TRU) takes homeΒ Epic AchievementΒ +Β Best RCEΒ at the #PwnieAwards for:
πΉ CVE-2024-6387 (regreSSHion) β 1st pre-auth RCE in OpenSSH in 20 yrs
πΉ CVE-2025-26465 β MITM attack on OpenSSH client
#vulnerabilityresearch #Qualys #TRU
09.08.2025 23:38 β π 3 π 1 π¬ 0 π 0
Security and compliance nerd, sword fighter. Opinions are my own, not my employer's.
Other social media profiles:
Mastodon: @christopherkunz@chaos.social
LinkedIn: https://www.linkedin.com/in/christopherkunz/
Cyber since '97: Check Point Software, Qualys, Sourcefire, Tufin, Attivo, Thales & ISSA-Chicago. Univ. of Wisco.
Visitor to, mainly, the EU, the PIGS, the BRICs, Cono Sur, Israel, Morrocco, Egypt, Turkey...
Amanda Katz said this was the cool kids table.
Chief Security Fanatic | CISO | Speaker | AI Risk | Political Risk | Columnist | Author | Radio Host | Board Member | Forbes Tech Council | TEDx | Canadian-American
Every day I write about #osint (Open Source Intelligence) tools and techniques. Also little bit about forensics and other cybersecurity related themes
Cybersecurity Reporter, Ars Technica: https://arstechnica.com/author/dan-goodin/ Hungry for tips. Text me on Signal: DanArs.82. "The world isnβt run by weapons anymore, or energy, or money. Itβs run by little 1s and 0s, little bits of data."
NPR Correspondent covering technology and national security.
Send me a tip: Text JennaMcLaughlin.54 on Signal from personal (nonwork) devices.
Cyber guy. Former NSA cybersecurity director and chief of TAO. Lover of memes. Warning - occasional outrageous Christmas light content.
Home of the Cybersecurity News hub. Information sharing and raising awareness. Think, talk and grow while on the go. Visit https://www.cybersecuritynews.today/ for more coverage.
Cybersecurity News Today! is on buymeacoffee.com/cybersecuritynewstoday
Award-winning #cybersecurity and #AI keynote speaker, writer, podcaster | Host of @theaifix.show and @smashingsecurity.com podcasts
β€οΈ #DoctorWho, #Beatles, #Chess
π https://grahamcluley.com
ποΈ https://theaifix.show
ποΈ https://www.smashingsecurity.com
News rund um Technik, IT und Digitales.
Β
heise.de/impressum.html & http://heise.de/privacy
Journalist: Senior Editor at Datacenter Dynamics. Previously IDG, CSO Online.
Midlander. Metalhead.
dad, a reporter, data reporter (writing about tech at The Washington Post)
I don't have digital; I don't have diddly squat.
Linguistics, NLP, news, Jews, Atlanta, crypto regs/politics, ads, fraud, etc.
Washington Post technology reporter, hopscotch enthusiast. heather.kelly@washpost.com.
Signal: @hkelly.11
technology mother @ the washington post. baddie in the digital badlands. signal: nitasha.10
Chief features writer, Financial Times. https://www.ft.com/henry-mance
West Coast Financial Editor at the Financial Times in San Francisco. Leading the FT's coverage of finance in Silicon Valley // Via Hong Kong and London
The best of FT journalism, including breaking news and analysis.
https://www.ft.com
The users this account follows are verified FT staff or contributors.
Ex BBC World Service. Who knew there was life outside?
That BBC News tech/gaming journo with the silly name, follow me for tech, rabbits and dyspraxia chat + constant references to a funny grief podcast about my dad dying: Our Dads Died: https://linktr.ee/ourdadsdied