“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps [email protected] (The Hacker News)
A high-severity security flaw has been disclosed in the One Identity OneLogin Identity and Access Management (IAM) solution that, if successfully exploited, could expose sensitive OpenID Connect (OIDC) application client secrets under certain circumstances. The vulnerability, tracked as CVE-2025-59363, has been assigned a CVSS score of 7.7 out of 10.0. It has been described as…
-

How Leading Security Teams Blend AI + Human Workflows (Free Webinar) [email protected] (The Hacker News)
AI is changing automation—but not always for the better. That’s why we’re hosting a new webinar, “Workflow Clarity: Where AI Fits in Modern Automation,” with Thomas Kinsella, Co-founder & Chief Customer Officer at Tines, to explore how leading teams are cutting through the hype and building workflows that actually deliver.The rise of AI has changed…
-

Red Hat OpenShift AI Flaw Exposes Hybrid Cloud Infrastructure to Full Takeover [email protected] (The Hacker News)
A severe security flaw has been disclosed in the Red Hat OpenShift AI service that could allow attackers to escalate privileges and take control of the complete infrastructure under certain conditions. OpenShift AI is a platform for managing the lifecycle of predictive and generative artificial intelligence (GenAI) models at scale and across hybrid cloud environments.…
-
Databricks boosts data security with AI-powered suite
With cyberattacks becoming more sophisticated, the vendor’s new set of features includes agents, AI-powered dashboards and integrations with specialists.Read More
-

Hackers Exploit Milesight Routers to Send Phishing SMS to European Users [email protected] (The Hacker News)
Unknown threat actors are abusing Milesight industrial cellular routers to send SMS messages as part of a smishing campaign targeting users in European countries since at least February 2022. French cybersecurity company SEKOIA said the attackers are exploiting the cellular router’s API to send malicious SMS messages containing phishing URLs, with the campaigns primarily targeting…
-

2025 Cybersecurity Reality Check: Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising [email protected] (The Hacker News)
Bitdefender’s 2025 Cybersecurity Assessment Report paints a sobering picture of today’s cyber defense landscape: mounting pressure to remain silent after breaches, a gap between leadership and frontline teams, and a growing urgency to shrink the enterprise attack surface. The annual research combines insights from over 1,200 IT and security professionals across six countries, along with…
-

New Android Banking Trojan “Klopatra” Uses Hidden VNC to Control Infected Smartphones [email protected] (The Hacker News)
A previously undocumented Android banking trojan called Klopatra has compromised over 3,000 devices, with a majority of the infections reported in Spain and Italy. Italian fraud prevention firm Cleafy, which discovered the sophisticated malware and remote access trojan (RAT) in late August 2025, said it leverages Hidden Virtual Network Computing (VNC) for remote control of…
-

Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs [email protected] (The Hacker News)
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of new targeted cyber attacks in the country using a backdoor called CABINETRAT. The activity, observed in September 2025, has been attributed to a threat cluster it tracks as UAC-0245. The agency said it spotted the attack following the discovery of software tools taking the…
-

$50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections [email protected] (The Hacker News)
A group of academics from KU Leuven and the University of Birmingham has demonstrated a new vulnerability called Battering RAM to bypass the latest defenses on Intel and AMD cloud processors. “We built a simple, $50 interposer that sits quietly in the memory path, behaving transparently during startup and passing all trust checks,” researchers Jesse…
-

Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth Malware [email protected] (The Hacker News)
Government and telecommunications organizations across Africa, the Middle East, and Asia have emerged as the target of a previously undocumented China-aligned nation-state actor dubbed Phantom Taurus over the past two-and-a-half years. “Phantom Taurus’ main focus areas include ministries of foreign affairs, embassies, geopolitical events, and military operations,” Palo Alto Networks Unit 42Read More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
