“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

WARNING: Expiring Root Certificate May Disable Firefox Add-Ons, Security Features, and DRM Playback [email protected] (The Hacker News)
Browser maker Mozilla is urging users to update their Firefox instances to the latest version to avoid facing issues with using add-ons due to the impending expiration of a root certificate. “On March 14, 2025, a root certificate used to verify signed content and add-ons for various Mozilla projects, including Firefox, will expire,” Mozilla said.…
-
Cyber Trust Mark explained: Everything you need to know
Post ContentRead More
-

Chinese Hackers Breach Juniper Networks Routers With Custom Backdoors and Rootkits [email protected] (The Hacker News)
The China-nexus cyber espionage group tracked as UNC3886 has been observed targeting end-of-life MX routers from Juniper Networks as part of a campaign designed to deploy custom backdoors, highlighting their ability to focus on internal networking infrastructure. “The backdoors had varying custom capabilities, including active and passive backdoor functions, as well as an embedded script…
-
How to deal with unmanaged devices in the enterprise
Post ContentRead More
-

Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber Attack [email protected] (The Hacker News)
Threat intelligence firm GreyNoise is warning of a “coordinated surge” in the exploitation of Server-Side Request Forgery (SSRF) vulnerabilities spanning multiple platforms. “At least 400 IPs have been seen actively exploiting multiple SSRF CVEs simultaneously, with notable overlap between attack attempts,” the company said, adding it observed the activity on March 9, 2025. The countries…
-

Pentesters: Is AI Coming for Your Role? [email protected] (The Hacker News)
We’ve been hearing the same story for years: AI is coming for your job. In fact, in 2017, McKinsey printed a report, Jobs Lost, Jobs Gained: Workforce Transitions in a Time of Automation, predicting that by 2030, 375 million workers would need to find new jobs or risk being displaced by AI and automation. Queue…
-

URGENT: Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited Zero-Days [email protected] (The Hacker News)
Microsoft on Tuesday released security updates to address 57 security vulnerabilities in its software, including a whopping six zero-days that it said have been actively exploited in the wild. Of the 56 flaws, six are rated Critical, 50 are rated Important, and one is rated Low in severity. Twenty-three of the addressed vulnerabilities are remote…
-

Apple Releases Patch for WebKit Zero-Day Vulnerability Exploited in Targeted Attacks [email protected] (The Hacker News)
Apple on Tuesday released a security update to address a zero-day flaw that it said has been exploited in “extremely sophisticated” attacks. The vulnerability has been assigned the CVE identifier CVE-2025-24201 and is rooted in the WebKit web browser engine component. It has been described as an out-of-bounds write issue that could allow an attacker…
-
Incident response for web application attacks
Post ContentRead More
-

Blind Eagle Hacks Colombian Institutions Using NTLM Flaw, RATs and GitHub-Based Attacks [email protected] (The Hacker News)
The threat actor known as Blind Eagle has been linked to a series of ongoing campaigns targeting Colombian institutions and government entities since November 2024. “The monitored campaigns targeted Colombian judicial institutions and other government or private organizations, with high infection rates,” Check Point said in a new analysis. “More than 1,600 victims were affected…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
