Amazon’s threat intelligence team discovered that attacker exploiting previously undisclosed zero-day vulnerabilities in Cisco Identity Service Engine (ISE) and Citrix systems. This campaign utilized custom malware and showed access to various hidden vulnerabilities, indicating a trend where attackers target essential identity and network access controls. Amazon’s MadPot honeypot service identified …
Read More »QNAP Patched 7 Zero-Days Exploited at Pwn2Own 2025
QNAP has urgently advised users and released patches for seven zero-day vulnerabilities exploited during the Pwn2Own Ireland 2025 competition, affecting their NAS devices. These patches address critical flaws in the core operating systems and key applications, such as backup and malware removal tools. Top security research teams, including Summoning Team, …
Read More »Samsung Galaxy Hijacked via 0-Day Exploit Using Single WhatsApp Image
Security researchers found Android spyware that targeted Samsung Galaxy phones for almost a year. Researchers at Palo Alto Networks’ Unit 42 said the spyware, which they call “Landfall,” was first detected in July 2024 and relied on exploiting a security flaw in the Galaxy phone software that was unknown to …
Read More »Critical Cisco UCCX flaw allows attackers to execute commands as root
Cisco has issued security updates to fix a critical vulnerability in the Unified Contact Center Express (UCCX) software that could allow attackers to gain root access. The Cisco UCCX platform, described by the company as a “contact center in a box,” is a software solution for managing customer interactions in …
Read More »HackedGPT: 7 New Vulns in GPT-4o and GPT-5 Enables 0-Click Attacks
Tenable researchers found 7 new vulnerabilities in OpenAI’s ChatGPT, putting users at risk of data theft and safety breaches through new attacks on AI systems dubbed HackedGPT. Flaws known as HackedGPT were found during testing of OpenAI’s ChatGPT-4o and some persist in ChatGPT-5. OpenAI has fixed some issues, but others …
Read More »BIND9 DNA Cache poisoning impact 267 IPs in Bangladesh
BIND9 DNA Cache poisoning impact 267 IPs in Bangladesh via CVE: 2025-40778. The high severity flaw can allow remote attackers to inject forged DNS records into resolver caches. BGD e-GOV CIRT published an advisory stating all organizations operating BIND 9 resolvers in Bangladesh (ISPs, data centers, government, enterprises) must upgrade …
Read More »Windows,VMware zero day and Linux flaw exploited: Australia warn unpatched Cisco IOS XE devices
In recent time, Hacker exploited Windows, VMware and Linux flaw. On another side, Australia warn about of BadCandy infections on unpatched Cisco devices. VMware: CISA added a serious security flaw affecting Broadcom VMware Tools and VMware Aria Operations to its Known Exploited Vulnerabilities list after reports of ongoing exploitation. The …
Read More »92% of Exchange servers in Germany unprotected
92% of Microsoft Exchange servers in Germany are outdated and won’t get any more security updates, as warned by the German Federal Office for Information Security (BSI). The BSI in Germany reports about 33,000 on-premise Exchange servers with publicly accessible Outlook Web Access. About 30,360 servers are running Exchange 2019 …
Read More »DomeWatch leak exposed Capitol Hill applicants’ personal data
Thousands of Americans’ personal job-seeking details were publicly exposed because of an unsecured database linked to the House Democrats’ Official Online Resume Bank, DomeWatch.us. The security lapse was brought to light by the research firm Safety Detectives, after an anonymous cybersecurity researcher reported to them about an “unencrypted and non-password-protected …
Read More »New CoPhish attack steals OAuth tokens Exploitng Copilot Studio agents
A phishing technique named CoPhish misuses Microsoft Copilot Studio to deceive users into giving hackers access to their Microsoft Entra ID accounts. Datadog Security Labs identified a method that uses customizable AI agents on legitimate Microsoft domains to disguise OAuth consent attacks, making them seem trustworthy and avoiding user suspicion. …
Read More »
InfoSecBulletin Cybersecurity for mankind