Infosec News

InfoSec News 20251030

  • Publicado: Qui, 30/10/2025 - 15:30

Top News


  • LinkedIn phishing targets finance execs with fake board invites

"Hackers are abusing LinkedIn to target finance executives with direct-message phishing attacks that impersonate executive board invitations, aiming to steal their Microsoft credentials."

Link

TLP1 : Green

InfoSec News 20251027

  • Publicado: Seg, 27/10/2025 - 15:41

Top News


  • Linux variant of Qilin Ransomware targets Windows via remote management tools and BYOVD

"Qilin ransomware group used Linux binaries on Windows to evade EDRs, steal backups, and disable defenses via BYOVD attacks."

Link

TLP1 : Green

InfoSec News 20251017

  • Publicado: Sex, 17/10/2025 - 17:44

Top News


  • Microsoft fixes highest-severity ASP.NET Core flaw ever

This HTTP request smuggling bug (CVE-2025-55315) was found in the Kestrel ASP.NET Core web server, and it enables authenticated attackers to smuggle another HTTP request to hijack other users' credentials or bypass front-end security controls.

Link

TLP1 : Green

InfoSec News 20251014

  • Publicado: Ter, 14/10/2025 - 18:12

Top News


  • Oracle issued an emergency security update to fix new E-Business Suite flaw CVE-2025-61884

Oracle issued an emergency security update to address a new E-Business Suite (EBS) vulnerability tracked as CVE-2025-61884

Link

TLP1 : Green

InfoSec News 20251009

  • Publicado: Qui, 09/10/2025 - 14:28

Top News


  • Azure outage blocks access to Microsoft 365 services, admin portals

"Microsoft is working to resolve an outage affecting its Azure Front Door content delivery network (CDN), which is preventing customers from accessing some Microsoft 365 services."

Link

TLP1 : Green

InfoSec News 20251003

  • Publicado: Sex, 03/10/2025 - 14:58

Top News


  • Confucius Hacker Group Weaponizes Documents to Infect Windows Systems with AnonDoor Malware

"The Confucius hacking group, a long-running cyber-espionage operation with suspected state-sponsored ties, has significantly evolved its attack methodologies over the past year, transitioning from document stealers like WooperStealer to sophisticated Python-based backdoors including AnonDoor malware."

Link

InfoSec News 20251001

  • Publicado: Qua, 01/10/2025 - 17:33

Top News


  • Smishing Campaigns Exploit Cellular Routers to Target Belgium

A newly identified wave of smishing attacks has been traced to exploited Milesight Industrial Cellular Routers. According to research by Sekoia.io’s Threat Detection & Research (TDR) team, the routers’ APIs were abused to send phishing text messages – a tactic that has repeatedly targeted Belgian users by impersonating official government services.

Páginas