“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker [email protected] (The Hacker News)
A 39-year-old Australian national who was previously employed at U.S. defense contractor L3Harris has been sentenced to a little over seven years in prison for selling eight zero-day exploits to Russian exploit broker Operation Zero in exchange for millions of dollars. Peter Williams pleaded guilty to two counts of theft of trade secrets in October…
-

SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution [email protected] (The Hacker News)
SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution. The vulnerabilities, all rated 9.1 on the CVSS scoring system, are listed below – CVE-2025-40538 – A broken access control vulnerability that allows an attacker to create a system…
-

CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed vulnerability in FileZen to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-25108 (CVSS v4 score: 8.7), is a case of operating system (OS) command injection that could allow an authenticated user to executeRead…
-

RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN [email protected] (The Hacker News)
A vulnerability in GitHub Codespaces could have been exploited by bad actors to seize control of repositories by injecting malicious Copilot instructions in a GitHub issue. The artificial intelligence (AI)-driven vulnerability has been codenamed RoguePilot by Orca Security. It has since been patched by Microsoft following responsible disclosure. “Attackers can craft hidden instructions inside aRead…
-

UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware [email protected] (The Hacker News)
A Russia-aligned threat actor has been observed targeting a European financial institution as part of a social engineering attack to likely facilitate intelligence gathering or financial theft, signaling a possible expansion of the threat actor’s targeting beyond Ukraine and into entities supporting the war-torn nation. The activity, which targeted an unnamed entity involved in regionalRead…
-

Identity Prioritization isn’t a Backlog Problem – It’s a Risk Math Problem [email protected] (The Hacker News)
Most identity programs still prioritize work the way they prioritize IT tickets: by volume, loudness, or “what failed a control check.” That approach breaks the moment your environment stops being mostly-human and mostly-onboarded. In modern enterprises, identity risk is created by a compound of factors: control posture, hygiene, business context, and intent. Any one of…
-

Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks [email protected] (The Hacker News)
The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East, according to a new report by the Symantec and Carbon Black Threat Hunter Team. Broadcom’s threat intelligence division said it also identified the same threat actors mounting an…
-
Top threat modeling tools, plus features to look for
Automated threat modeling tools make identifying threats simpler, but the tools themselves can be fairly complex. Understanding where risks exist is only one part of the process.Read More
-

UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors [email protected] (The Hacker News)
The threat activity cluster known as UnsolicitedBooker has been observed targeting telecommunications companies in Kyrgyzstan and Tajikistan, marking a shift from prior attacks aimed at Saudi Arabian entities. The attacks involve the deployment of two distinct backdoors codenamed LuciDoor and MarsSnake, according to a report published by Positive Technologies last week. “The group used severalRead…
-
5G security: Everything you should know for a secure network
5G has better security than 4G, including stronger encryption, privacy and authentication. But enterprises need to know the challenges of 5G’s complex, virtualized architecture.Read More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
