Cybersecurity News
-
Krispy Kreme Cyberattack: A Sweet Disruption
Last week, Krispy Kreme was in a sticky situation as the beloved doughnut chain experienced…
-
Navigating the Future: AI Advancements and Cybersecurity Challenges in 2025
As we approach 2025, the tech landscape is poised for significant transformations, particularly in the…
-
Chinese Salt Typhoon Hacked 8+ Telecoms To Stole U.S. Citizens Data
A Chinese hacking campaign, codenamed “Salt Typhoon” by Microsoft, has infiltrated more than 8 American…
-
Isreali NSO Group’s Pegasus Spyware Detected in New Mobile Devices
Cybersecurity researchers from iVerify have revealed widespread new infections of the Pegasus spyware, developed by…
-
CISA Warns Of CyberPanel, North Grid, ProjectSend & Zyxel Firewalls Flaws Exploited In Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding four critical…
-
Thinkware Cloud APK Vulnerability Let Attackers Execute Arbitrary Code
A critical security flaw has been uncovered recently in the Thinkware Cloud APK version 4.3.46,…
-
Beware Of New HR Payroll Phishing Attack Targeting Numerous Employees
A sophisticated phishing campaign dubbed “Payroll Pirates” is currently targeting employees of various high-profile organizations.…
-
Secret Blizzard Hackers Attack Windows Infrastructure Using Multiple Hacking Tools
In a recent joint report by Microsoft Threat Intelligence and Black Lotus Labs, new insights…
-
Deloitte Hacked – Brain Cipher Ransomware Group Allegedly Stolen 1 TB of Data
Notorious ransomware group Brain Cipher has claimed to have breacked Deloitte UK, allegedly exfiltrating over…
-
The Power of Strong Passwords in a Cybersecure World
In an era where cyber threats are growing increasingly sophisticated, the importance of a strong…
About Author
Chad Barr
Chad Barr is a visionary and executive leader, blending over two decades of expertise with a unique ability to demystify complex technical concepts. As a cybersecurity leader, prolific author, and director at AccessIT Group, Chad has empowered organizations across diverse industries to build resilient security frameworks. His engaging writing, speaking engagements, and thought leadership inspire proactive cybersecurity practices, making him a trusted voice in the ever-evolving digital landscape.
My Books
Cybersecurity News
- Palo Alto Networks Expedition Tool Vulnerability Exposes Firewall Credentialsby Guru Baran on January 9, 2025 at 7:24 am
Multiple vulnerabilities in Palo Alto Networks’ Expedition migration tool have been discovered, potentially exposing sensitive firewall credentials, including usernames, cleartext passwords, device configurations, and API keys. These vulnerabilities pose significant risks to organizations using the tool for firewall migration and optimization. Expedition, formerly known as the Migration Tool, is a free utility designed to assist The post Palo Alto Networks Expedition Tool Vulnerability Exposes Firewall Credentials appeared first on Cyber Security News.
- Hackers Actively Exploited Ivanti VPN 0-Day Vulnerability (CVE-2025-0282): Technical Analysisby Balaji N on January 9, 2025 at 4:52 am
Ivanti publicly disclosed two critical vulnerabilities CVE-2025-0282 and CVE-2025-0283 affecting its Connect Secure (ICS) VPN appliances. The announcement comes amidst alarming reports of active zero-day exploitation of CVE-2025-0282, identified by cybersecurity firm Mandiant as having begun in mid-December 2024. The exploitation has raised concerns about potential network breaches and downstream compromises for affected organizations. CVE-2025-0282, The post Hackers Actively Exploited Ivanti VPN 0-Day Vulnerability (CVE-2025-0282): Technical Analysis appeared first on Cyber Security News.
- Ivanti Flaw CVE-2025-0282 Actively Exploited, Impacts Connect Secure and Policy Secureby [email protected] (The Hacker News) on January 9, 2025 at 4:40 am
Ivanti is warning that a critical security flaw impacting Ivanti Connect Secure, Policy Secure, and ZTA Gateways has come under active exploitation in the wild beginning mid-December 2024. The security vulnerability in question is CVE-2025-0282 (CVSS score: 9.0), a stack-based buffer overflow that affects Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2
- Wireshark 4.4.3 Released – What’s New!by Guru Baran on January 9, 2025 at 2:51 am
The Wireshark Foundation has announced the release of Wireshark 4.4.3, the latest version of the world’s most popular network protocol analyzer. This update brings a host of bug fixes and protocol support improvements, enhancing the tool’s capabilities for network troubleshooting, analysis, development, and education. What is Wireshark? Wireshark is a powerful, open-source network analysis tool The post Wireshark 4.4.3 Released – What’s New! appeared first on Cyber Security News.
- Ivanti VPN Zero-Day Vulnerability Actively Exploited in the Wildby Guru Baran on January 9, 2025 at 2:27 am
Ivanti has disclosed actively exploiting a critical zero-day vulnerability, CVE-2025-0282, in its Connect Secure VPN appliances. This vulnerability allows unauthenticated remote code execution and has already been exploited in a limited number of cases. A second vulnerability, CVE-2025-0283, which enables local privilege escalation, has also been identified but is not known to have been exploited. The post Ivanti VPN Zero-Day Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News.