Security Affairs

Qilin Ransomware Gang Claims the Hack of the Ministry of Foreign Affairs of Ukraine

The group stated that it stole sensitive data such as private correspondence, personal information, and official decrees. The ransomware group declared that they had already sold some of the alleged stolen information to third parties.

Attackers Could Hack Smart Solar Systems and Cause Serious Damages

Experts say millions of solar units worldwide can be accessed due to these flaws, and they could have manipulated power supplies to cause blackouts, especially amid the ongoing hybrid warfare tensions involving Russia.

Cisco Fixed Command Injection and DoS Flaws in Nexus Switches

The most severe issue, tracked as CVE-2025-20111 (CVSS Score of 7.4), resides in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode.

China-Linked Threat Actors Allegedly Stole 10% of Belgian State Security Service’s Staff Emails Over Two Years

The Belgian federal prosecutor’s office is probing a potential breach of its State Security Service (VSSE) by China-linked threat actors. The hackers accessed the VSSE’s email server between 2021 and May 2023, stealing 10% of staff emails.

Salt Typhoon used custom malware JumbledPath to spy on U.S. telecom providers

Cisco Talos researchers reported that China-linked APT group Salt Typhoon uses a custom-built utility, dubbed JumbledPath, to spy on network traffic of U.S. telecommunication providers.

Valve Removed the Game PirateFi From the Steam Platform After Discovery of Hidden Malware

Valve removed the game PirateFi from the Steam video game platform because it contained malicious code designed to steal browser cookies and hijack accounts. The company also advised affected users to reformat their operating systems for mitigation.

CISA Adds Microsoft Windows, Zyxel Device Dlaws to its Known Exploited Vulnerabilities Catalog

The CISA added four vulnerabilities to its KEV catalog, including OS command injection flaws in Zyxel CPE Series devices (CVE-2024-40891 and CVE-2024-40890) and two Windows flaws (CVE-2025-21418 and CVE-2025-21391).

OpenSSL Patched High-Severity Flaw Enabling Man-in-the-Middle Attacks

The vulnerability impacts TLS clients that explicitly enable RPKs and rely on SSL_VERIFY_PEER to detect authentication failures. Project maintainers pointed out that RPKs are disabled by default in both TLS clients and TLS servers.

Attackers Exploit a New Zero-Day to Hijack Fortinet Firewalls

Fortinet warned that threat actors are exploiting a new zero-day vulnerability, tracked as CVE-2025-24472 (CVSS score of 8.1), in FortiOS and FortiProxy to hijack Fortinet firewalls.

Police Dismantles 8Base Ransomware Gang Under Operation Phobos Aetor

The police arrested four European citizens in Phuket, Thailand, who are suspected of having stolen over $16 million through ransomware attacks affecting over 1,000 victims worldwide.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags