Latest Cybersecurity News and Articles

Misconfigured APIs Expose Sensitive Medical Data in Major Diagnostic Chain

A recent investigation by CloudSEK’s BeVigil platform has revealed critical vulnerabilities in the API infrastructure of a prominent diagnostic chain, exposing sensitive personal and medical data of potentially millions of users.

Over 12,000 KerioControl Firewalls Exposed to Exploited RCE Flaw

GFI Software released a security update for the problem with version 9.4.5 Patch 1 on December 19, 2024, yet three weeks later, according to Censys, over 23,800 instances remained vulnerable.

OpenSSL Patched High-Severity Flaw Enabling Man-in-the-Middle Attacks

The vulnerability impacts TLS clients that explicitly enable RPKs and rely on SSL_VERIFY_PEER to detect authentication failures. Project maintainers pointed out that RPKs are disabled by default in both TLS clients and TLS servers.

Attackers Exploit a New Zero-Day to Hijack Fortinet Firewalls

Fortinet warned that threat actors are exploiting a new zero-day vulnerability, tracked as CVE-2025-24472 (CVSS score of 8.1), in FortiOS and FortiProxy to hijack Fortinet firewalls.
February 12, 2025

Triplestrength Hits Victims With Ransomware, Cloud Hijacks, Cryptomining

A previously unknown gang dubbed Triplestrength poses a triple threat to organizations: It infects victims' computers with ransomware, then hijacks their cloud accounts to illegally mine for cryptocurrency.

SonicWall Firewall Exploit Lets Hackers Hijack VPN Sessions, Patch Now

Security researchers at Bishop Fox have published complete exploitation details for the CVE-2024-53704 vulnerability that bypasses the authentication mechanism in certain SonicOS SSL VPN application versions.

Microsoft February 2025 Patch Tuesday Fixes 4 Zero-Days, 55 Flaws

This month's Patch Tuesday fixes two actively exploited and two publicly exposed zero-day vulnerabilities. Microsoft classifies a zero-day flaw as one that is publicly disclosed or actively exploited while no official fix is available.

Ivanti Patches Critical Flaws in Connect Secure and Policy Secure

Ivanti has released security updates to address multiple security flaws impacting Connect Secure (ICS), Policy Secure (IPS), and Cloud Services Application (CSA) that could be exploited to achieve arbitrary code execution.
February 12, 2025

Semgrep Bags $100M in Series D to Elevate AI-Driven Code Security

The round was spearheaded by Menlo Ventures, with significant contributions from existing stakeholders including Felicis Ventures, Harpoon Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital.

University Site Cloned to Evade Ad Detection and Distribute Fake Cisco AnyConnect Installer

The attackers are using a clever technique to evade detection by security systems. They have cloned the website of a German university that uses Cisco AnyConnect and are using it as a “white page” to fool ad detection systems.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags