Latest

Cyber Daily 2/5: CISA's Edge Threat Guidance, XE Group's Supply Chain Threat, Retail Workforce Vulnerability, Russian Exploitation of 7-Zip Zero-Day, AMD and Microsoft Patch Updates

Cyber Daily 2/5: CISA's Edge Threat Guidance, XE Group's Supply Chain Threat, Retail Workforce Vulnerability, Russian Exploitation of 7-Zip Zero-Day, AMD and Microsoft Patch Updates

Welcome to today's issue of ONSEC Cyber Daily! In this edition, we delve into the latest cybersecurity threats and vulnerabilities that are making headlines. The Cybersecurity and Infrastructure Security Agency (CISA) has issued fresh guidance on edge threats, highlighting the need for robust network security. Meanwhile, the XE
ONSEC.io Research Team
Cyber Daily 2/4: Microsoft Bypass Vulnerability, ValleyRAT Malware Alert, WhatsApp Spyware by Israeli Firm, Record Security Vulnerabilities in 2024, Contec Patient Monitor Backdoor

Cyber Daily 2/4: Microsoft Bypass Vulnerability, ValleyRAT Malware Alert, WhatsApp Spyware by Israeli Firm, Record Security Vulnerabilities in 2024, Contec Patient Monitor Backdoor

Welcome to the ONSEC Cyber Daily! Today, we delve into the world of cybersecurity, where vulnerabilities and threats lurk in every corner. We kick off with a critical bypass vulnerability in Microsoft accounts that could allow attackers to gain remote access. This comes as researchers unveil a sophisticated malware campaign
ONSEC.io Research Team
Cyber Daily 2/1: Google's Urgent Cybersecurity Warning, SimpleHelp RMM Exploits, FDA Alerts on Contec Monitor Vulnerabilities, Oracle's Massive Security Update

Cyber Daily 2/1: Google's Urgent Cybersecurity Warning, SimpleHelp RMM Exploits, FDA Alerts on Contec Monitor Vulnerabilities, Oracle's Massive Security Update

Welcome to your daily dose of cybersecurity insights from ONSEC Cyber Daily. Today, we're diving into the realm of cybersecurity predictions for 2025, where hype battles reality. We'll explore how common practices like visual validation are becoming increasingly vulnerable, particularly in finance and cryptocurrency markets. We&
ONSEC.io Research Team
Cyber Daily 1/31: FDA Alerts on Contec, Epsimed Monitor Vulnerabilities, NCSC's New Classification System, Broadcom Patches VMware Aria Flaws, Mirai Botnet Targets Zyxel Routers, SonicWall Firewalls Vulnerable

Cyber Daily 1/31: FDA Alerts on Contec, Epsimed Monitor Vulnerabilities, NCSC's New Classification System, Broadcom Patches VMware Aria Flaws, Mirai Botnet Targets Zyxel Routers, SonicWall Firewalls Vulnerable

Welcome to the latest issue of ONSEC Cyber Daily. Today, we're diving into a series of cybersecurity vulnerabilities that are making waves in the health sector. The FDA has issued a warning about potential vulnerabilities in patient monitors manufactured by Contec and Epsimed. Meanwhile, the UK's
ONSEC.io Research Team
Cyber Daily 1/29: Zyxel CPE Exploitation, UK's Advancing Cyber Threat, iOS 18.3 Security Update, Google Chrome Alert, Nvidia GPU Vulnerabilities, Apple's Zero-Day Patch, Cybersecurity Podcasts

Cyber Daily 1/29: Zyxel CPE Exploitation, UK's Advancing Cyber Threat, iOS 18.3 Security Update, Google Chrome Alert, Nvidia GPU Vulnerabilities, Apple's Zero-Day Patch, Cybersecurity Podcasts

Welcome to the ONSEC Cyber Daily for January 29th. Today's issue is packed with critical updates and warnings that you need to know. We start with a warning about Zyxel CPE devices facing active exploitation due to an unpatched vulnerability. This is a serious issue that needs immediate
ONSEC.io Research Team
Cyber Daily 1/28: Google Chrome Users at Risk, Indian Govt. Issues Warning, Chinese AI App DeepSeek Cyberattacked, Fenix24 Acquires vArmour, Brave Browser Vulnerability, SonicWall SMA 1000 Series Under Threat

Cyber Daily 1/28: Google Chrome Users at Risk, Indian Govt. Issues Warning, Chinese AI App DeepSeek Cyberattacked, Fenix24 Acquires vArmour, Brave Browser Vulnerability, SonicWall SMA 1000 Series Under Threat

Welcome to the latest issue of ONSEC Cyber Daily, where we bring you the most pressing cybersecurity news from around the globe. Today, we're diving into a wave of vulnerabilities and cyber threats that are putting tech users and companies on high alert. Google Chrome users, take note
ONSEC.io Research Team
Cyber Daily 1/24: Microsoft Outlook Zero-Click RCE Vulnerability, Aviat Networks Boosts Cybersecurity, Ivanti Cloud Service Vulnerabilities Exploited, Google Chrome Security Warning for 3 Billion Users

Cyber Daily 1/24: Microsoft Outlook Zero-Click RCE Vulnerability, Aviat Networks Boosts Cybersecurity, Ivanti Cloud Service Vulnerabilities Exploited, Google Chrome Security Warning for 3 Billion Users

Good morning, ONSEC Cyber Daily readers! Today, we're diving deep into the world of cybersecurity, where vulnerabilities and exploits are the name of the game. We start with a critical zero-click RCE vulnerability in Microsoft Outlook (CVE-2025-21298), a proof of concept exploit that's been released, making
ONSEC.io Research Team
Cyber Daily 1/23: 7-Zip and Ivanti Vulnerabilities Exploited, IBM Client Solutions Breached, CISA Alerts on Aircraft and Siemens Flaws, Oracle's Massive Patch Release

Cyber Daily 1/23: 7-Zip and Ivanti Vulnerabilities Exploited, IBM Client Solutions Breached, CISA Alerts on Aircraft and Siemens Flaws, Oracle's Massive Patch Release

Welcome to your daily dose of ONSEC Cyber Daily. Today, we're diving into the world of vulnerabilities and patches. A Proof-of-Concept exploit has been released for a high-severity vulnerability in 7-Zip, a popular file archiver. Meanwhile, HEAL Security is discussing Cisco vulnerabilities and automotive threats. In other news,
ONSEC.io Research Team
Cyber Daily 1/22: Mercedes-Benz and PayPal Under Cyberattack, DeFi Exchange and Squarespace Vulnerabilities, Patch Delays for Fortinet and Windows 11, AI in Cybersecurity Podcasts

Cyber Daily 1/22: Mercedes-Benz and PayPal Under Cyberattack, DeFi Exchange and Squarespace Vulnerabilities, Patch Delays for Fortinet and Windows 11, AI in Cybersecurity Podcasts

Welcome to your ONSEC Cyber Daily newsletter for January 22, 2025. Today, we're diving into a whirlwind of cybersecurity threats and solutions that have been making headlines. First up, Mercedes-Benz owners are on high alert as 13 security issues have been discovered, putting their vehicles at risk of
ONSEC.io Research Team
Cyber Daily 1/21: NCERT Alerts Palo Alto Networks on DNS Vulnerability, FBI and CISA Advise Secure Cryptography, Guardia Civil Data Breach, Vietnam's 23 New Vulnerabilities, Chrome and Edge Security Flaws

Cyber Daily 1/21: NCERT Alerts Palo Alto Networks on DNS Vulnerability, FBI and CISA Advise Secure Cryptography, Guardia Civil Data Breach, Vietnam's 23 New Vulnerabilities, Chrome and Edge Security Flaws

Welcome to today's issue of ONSEC Cyber Daily! We're diving into a whirlwind of cybersecurity alerts, vulnerabilities, and patches. The National Computer Emergency Response Team (NCERT) has issued a hack alert against vulnerabilities in cybersecurity software, while the FBI and CISA urge software vendors to stop
ONSEC.io Research Team
Cyber Daily 1/17: Veeam Azure Backup Vulnerability, Microsoft's Massive Patch Tuesday, Fortinet's Zero-Day Exploit, Samsung's Galaxy S20 FE 5G Security Patch

Cyber Daily 1/17: Veeam Azure Backup Vulnerability, Microsoft's Massive Patch Tuesday, Fortinet's Zero-Day Exploit, Samsung's Galaxy S20 FE 5G Security Patch

Welcome to your daily dose of ONSEC Cyber Daily. Today's issue is packed with critical updates and insights on the latest cybersecurity threats and patches. We kick off with a vulnerability in Veeam Azure Backup Solution that allows attackers to enumerate networks, a serious threat that requires immediate
ONSEC.io Research Team
Cyber Daily 1/16: Fortinet, FortiOS Vulnerabilities Alert, AI's Double-Edged Sword, Google Chrome's Urgent Update, BeyondTrust Exploits, Microsoft's Record Patch Tuesday, macOS SIP Exploit, Rsync Flaws

Cyber Daily 1/16: Fortinet, FortiOS Vulnerabilities Alert, AI's Double-Edged Sword, Google Chrome's Urgent Update, BeyondTrust Exploits, Microsoft's Record Patch Tuesday, macOS SIP Exploit, Rsync Flaws

Welcome to the ONSEC Cyber Daily, your one-stop source for the latest in cybersecurity news. Today, we're diving into a whirlwind of vulnerabilities, patches, and cyber threats that are keeping the digital world on its toes. We start with an alert issued by FortiOS and FortiProxy, warning of
ONSEC.io Research Team
Cyber Daily 1/15: Quantum Tech Threatens Encryption, Beyond Trust and Olik Bugs on CISA's KEV List, Aviatrix Controller Flaw Exploited, Record 159 CVEs Patched in Microsoft's January Update

Cyber Daily 1/15: Quantum Tech Threatens Encryption, Beyond Trust and Olik Bugs on CISA's KEV List, Aviatrix Controller Flaw Exploited, Record 159 CVEs Patched in Microsoft's January Update

Welcome to the latest issue of ONSEC Cyber Daily, your go-to source for the most impactful cybersecurity news. Today, we delve into the top 5 cybersecurity trends of 2025, highlighting the increasing vulnerability of traditional encryption methods in the face of rapidly developing quantum technologies. We also report on the
ONSEC.io Research Team
Cyber Daily 1/13: CISA's 4-Year Review, Sex Toy Cyber Threat, Samsung's S24, S23 Attacks, Malicious Browser Extensions, macOS and Ivanti Vulnerabilities, Google's Android Alert

Cyber Daily 1/13: CISA's 4-Year Review, Sex Toy Cyber Threat, Samsung's S24, S23 Attacks, Malicious Browser Extensions, macOS and Ivanti Vulnerabilities, Google's Android Alert

Welcome to your daily dose of ONSEC Cyber Daily, where we bring you the latest and most impactful cybersecurity news. Today, we delve into a comprehensive review of the Cybersecurity and Infrastructure Security Agency's (CISA) four-year policy, shedding light on the state of cybersecurity in the US. In
ONSEC.io Research Team
Cyber Daily 1/10: Ivanti VPN Vulnerability Exploited, ACSC Issues Alert, Quorum Cyber Acquires Kivu, Critical Mitel and Oracle Flaws, Ivanti and SonicWall Patches Urged

Cyber Daily 1/10: Ivanti VPN Vulnerability Exploited, ACSC Issues Alert, Quorum Cyber Acquires Kivu, Critical Mitel and Oracle Flaws, Ivanti and SonicWall Patches Urged

Welcome to the latest issue of ONSEC Cyber Daily, your one-stop source for all the major cybersecurity updates. Today, we delve into the alarming details of Ivanti VPN's major vulnerability, as revealed by Mandiant. This critical zero-day vulnerability has been exploited since December 2024, prompting an urgent alert
ONSEC.io Research Team
Cyber Daily 1/6: Chinese APT Breaches U.S. Treasury, Assam Police Crack Cybercrime Racket, Windows and Nuclei Patch High-Risk Vulnerabilities, PoC Exploits Released for OpenSSH and Windows Registry, Wordpress Plugin Risk, Cybersecurity Podcast Insights

Cyber Daily 1/6: Chinese APT Breaches U.S. Treasury, Assam Police Crack Cybercrime Racket, Windows and Nuclei Patch High-Risk Vulnerabilities, PoC Exploits Released for OpenSSH and Windows Registry, Wordpress Plugin Risk, Cybersecurity Podcast Insights

Welcome to the latest issue of ONSEC Cyber Daily. Today, we delve into the world of cyber vulnerabilities and the critical need for robust security measures. We kick off with a warning from a minister about the potential risks that cyber vulnerabilities pose to our people and critical infrastructure. In
ONSEC.io Research Team
Cyber Daily 1/3: SC3 Alert Protocol, Canadian Software Vulnerability, Google Chrome Red Alert, Sophos Firewall Risk, LDAPNightmare Exploit, Windows 11 Encryption Bypass, China & Russia Cyber Attacks, Exploding Cybertruck, AI Risks in 2025

Cyber Daily 1/3: SC3 Alert Protocol, Canadian Software Vulnerability, Google Chrome Red Alert, Sophos Firewall Risk, LDAPNightmare Exploit, Windows 11 Encryption Bypass, China & Russia Cyber Attacks, Exploding Cybertruck, AI Risks in 2025

Welcome to today's issue of ONSEC Cyber Daily, where we bring you the most impactful cybersecurity news from around the globe. Today, we delve into the Scottish Cyber Coordination Centre's new vulnerability coordination policy and procedure, designed to alert and coordinate responses to cyber threats. In
ONSEC.io Research Team
Cyber Daily 1/2: CISA Warns of PAN-OS Vulnerability, Google Chrome Users Alerted, Critical Flaws in WhatsUp Gold and PRTG Monitor, Windows LDAP RCE Exploit Released

Cyber Daily 1/2: CISA Warns of PAN-OS Vulnerability, Google Chrome Users Alerted, Critical Flaws in WhatsUp Gold and PRTG Monitor, Windows LDAP RCE Exploit Released

Welcome back from the holidays, everyone! We hope you had a fantastic break and are ready to dive into the latest cybersecurity developments. In today’s issue of ONSEC Cyber Daily, we’re starting off with a critical warning from CISA regarding an exploited vulnerability in PAN-OS versions—expertly covered
ONSEC.io Research Team
Cyber Daily 12/31: High Risk Warning for Google Chrome, Patches for CVEs in Microsoft, Four-Faith Routers, TrueNAS CORE, Samsung, Oracle, Palo Alto Networks, Podcasts on Belarus' Authoritarianism

Cyber Daily 12/31: High Risk Warning for Google Chrome, Patches for CVEs in Microsoft, Four-Faith Routers, TrueNAS CORE, Samsung, Oracle, Palo Alto Networks, Podcasts on Belarus' Authoritarianism

Good Morning ONSEC Cyber Daily Subscribers, As we bid farewell to 2024, we're here to keep you updated on the latest cybersecurity developments. Today's newsletter is packed with critical information that you need to know. First up, Google Chrome users, be on high alert. The government
ONSEC.io Research Team
Cyber Daily 12/30: Apache Vulnerabilities Alert, American Addiction Centers Breach, Oracle and Palo Alto Patches, Singapore's Security Advisory, Podcast Insights

Cyber Daily 12/30: Apache Vulnerabilities Alert, American Addiction Centers Breach, Oracle and Palo Alto Patches, Singapore's Security Advisory, Podcast Insights

Welcome to the last ONSEC Cyber Daily of 2024! Today, we're diving into a series of critical vulnerabilities and patches that have been making waves in the cybersecurity world. First up, we're looking at the critical Apache vulnerabilities, including CVE-2024-43441, which has been flagged by Singapore&
ONSEC.io Research Team
Cyber Daily 12/26: Amazon Cloud Faces 3 High-Rated Vulnerabilities, Japan Airlines Cyberattack Delays Flights, US Targets Chinese Tech Firms, Critical Bugs Hit IBM, Apache, Adobe

Cyber Daily 12/26: Amazon Cloud Faces 3 High-Rated Vulnerabilities, Japan Airlines Cyberattack Delays Flights, US Targets Chinese Tech Firms, Critical Bugs Hit IBM, Apache, Adobe

Good morning ONSEC Cyber Daily readers, Today's issue is packed with critical updates from the cybersecurity world. We start with a warning from Amazon about three high-rated vulnerabilities that have hit their cloud, as reported by veteran cybersecurity writer, Davey Winder. In airline news, Japan Airlines has been
ONSEC.io Research Team
Cyber Daily 12/23: PKCERT Warns of Windows Vulnerability, Sophos Firewall Flaws Unveiled, Microsoft Fixes Cloud Platform Issue, Cybersecurity Podcasts Trending

Cyber Daily 12/23: PKCERT Warns of Windows Vulnerability, Sophos Firewall Flaws Unveiled, Microsoft Fixes Cloud Platform Issue, Cybersecurity Podcasts Trending

Season’s Greetings, ONSEC Cyber Daily readers! As we gear up for the upcoming Christmas festivities, we hope you’re staying merry and vigilant in the ever-evolving world of cybersecurity. Today, we’re diving into a flurry of updates that have been making headlines: The National Cyber Emergency Response Team
ONSEC.io Research Team
Cyber Daily 12/20: FBI Warns of HiatusRAT Threat to Webcams, DVRs; BeyondTrust Vulnerability Exploited; AI-Driven Cyber Threats Predicted by 2025; Critical FortiWLM Vulnerability Patched by Fortinet

Cyber Daily 12/20: FBI Warns of HiatusRAT Threat to Webcams, DVRs; BeyondTrust Vulnerability Exploited; AI-Driven Cyber Threats Predicted by 2025; Critical FortiWLM Vulnerability Patched by Fortinet

Welcome to your ONSEC Cyber Daily for December 20th. Today, we're diving into a series of critical cybersecurity issues that have been making headlines. The FBI has issued a stark warning about HiatusRAT malware, a threat that's been targeting webcams and DVRs, leaving them vulnerable to
ONSEC.io Research Team
Cyber Daily 12/19: US-China Mobile Security Alert, Google Chrome Vulnerabilities in India, SHARP Routers and Fortinet Flaws, Rhode Island Cybersecurity Warning, Podcast Insights on Cybersecurity Future

Cyber Daily 12/19: US-China Mobile Security Alert, Google Chrome Vulnerabilities in India, SHARP Routers and Fortinet Flaws, Rhode Island Cybersecurity Warning, Podcast Insights on Cybersecurity Future

Good morning, ONSEC Cyber Daily readers! Today's newsletter is packed with critical updates and insights you won't want to miss. We kick off with an urgent mobile security alert issued by the US over Chinese cyber threats. CISA is advising iPhone users to enable Lockdown Mode
ONSEC.io Research Team
Cyber Daily 12/18: Rhode Island's Unaddressed Cybersecurity Warning, Apache Struts and Cleo Software Exploited, Hitachi Energy and BeyondTrust Patch Critical Vulnerabilities

Cyber Daily 12/18: Rhode Island's Unaddressed Cybersecurity Warning, Apache Struts and Cleo Software Exploited, Hitachi Energy and BeyondTrust Patch Critical Vulnerabilities

Good morning, ONSEC Cyber Daily readers! Today's issue is packed with critical updates and alerts you need to know. We start off in Rhode Island, where the state's social service and healthcare technology infrastructure is under attack by cybercriminals. Despite the Auditor General's repeated
ONSEC.io Research Team
Cyber Daily 12/17: Rising Tech Outages, CISA's 2024 Review, Windows Kernel Vulnerability, Adobe & Windows Exploits, HiatusRAT Attacks, Cleo & DrayTek Vulnerabilities, CISA & EPA Guidelines, Cross Apple-Android Texting Warning

Cyber Daily 12/17: Rising Tech Outages, CISA's 2024 Review, Windows Kernel Vulnerability, Adobe & Windows Exploits, HiatusRAT Attacks, Cleo & DrayTek Vulnerabilities, CISA & EPA Guidelines, Cross Apple-Android Texting Warning

Welcome to the ONSEC Cyber Daily newsletter for December 17th. Today, we're diving into the escalating wave of tech outages and cybercrime losses, as reported by Macleans and Cybersecurity Ventures. We'll also explore North Korea's cyberattack strategies, Iran's advancing cyber capabilities, and
ONSEC.io Research Team
Cyber Daily 12/16: DrayTek Vulnerabilities Impact Hundreds, CISA and EPA Shield Water Systems, Cross-Platform Texting Warning, Medical Imaging RCE Alert, Android Chrome Security Alert, Clop Ransomware Hits Cleo, NoviSpy Exploits Qualcomm Bugs

Cyber Daily 12/16: DrayTek Vulnerabilities Impact Hundreds, CISA and EPA Shield Water Systems, Cross-Platform Texting Warning, Medical Imaging RCE Alert, Android Chrome Security Alert, Clop Ransomware Hits Cleo, NoviSpy Exploits Qualcomm Bugs

Welcome to today's issue of ONSEC Cyber Daily, where we bring you the most impactful cybersecurity news in a digestible format. In today's headlines, hundreds of organizations have fallen victim to cyberattacks exploiting undocumented vulnerabilities in DrayTek. The cybersecurity vendor Forescout has issued a warning about
ONSEC.io Research Team
Cyber Daily 12/14: CISA Warns of Cleo, CyberPanel Exploits; Samsung, Apple Patch Critical CVEs; Ransomware Gangs Target RDP Services; Podcasts Discuss Cybersecurity Trends

Cyber Daily 12/14: CISA Warns of Cleo, CyberPanel Exploits; Samsung, Apple Patch Critical CVEs; Ransomware Gangs Target RDP Services; Podcasts Discuss Cybersecurity Trends

Welcome to today's issue of ONSEC Cyber Daily! We're diving into a whirlwind of cyber threats and security patches. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about ransomware gangs exploiting the Cleo 0-Day vulnerability, a situation reminiscent of the MOVEit hack campaign.
ONSEC.io Research Team
Cyber Daily 12/10: Android, Windows Security "Downdates", CISA's 271 Warnings, iOS 18 Update Risk, HealthAlliance's $550K Settlement, Mitel MiCollab Vulnerabilities

Cyber Daily 12/10: Android, Windows Security "Downdates", CISA's 271 Warnings, iOS 18 Update Risk, HealthAlliance's $550K Settlement, Mitel MiCollab Vulnerabilities

Welcome to today's issue of ONSEC Cyber Daily. 🔴 ONSEC is now on X (Twitter)!!! Follow us for timely updates on critical security news, vulnerabilities, exploits, expert articles, and more! Follow ONSEC Team on X Moreover, today we starting with a new Android and Windows attack that "downdates&
ONSEC.io Research Team
Cyber Daily 12/9: FBI Warns of AI-Driven Cyberattacks, Chinese Threats, Tinxy App Vulnerability, Termite Ransomware Hits Blue Yonder, Patches for QNAP, Google's Vanir, and Windows Zero-Day

Cyber Daily 12/9: FBI Warns of AI-Driven Cyberattacks, Chinese Threats, Tinxy App Vulnerability, Termite Ransomware Hits Blue Yonder, Patches for QNAP, Google's Vanir, and Windows Zero-Day

Welcome to today's issue of ONSEC Cyber Daily, where we bring you the most pressing cybersecurity news from around the globe. Today, we delve into the FBI's recent warning about AI-driven cyberattacks, sparking serious concerns about the rise of advanced persistent threats, particularly those backed by
ONSEC.io Research Team
Cyber Daily 12/7: Windows Zero-Day Warning, China's Cyber Spying Denial, FBI Alerts on iPhone, Android Attacks, Atrium Health Data Breach, Cybersecurity Podcast Insights

Cyber Daily 12/7: Windows Zero-Day Warning, China's Cyber Spying Denial, FBI Alerts on iPhone, Android Attacks, Atrium Health Data Breach, Cybersecurity Podcast Insights

Welcome to your daily dose of ONSEC Cyber Daily. Today, we're diving into a whirlwind of cybersecurity warnings, vulnerabilities, and cyberattacks that are making headlines worldwide. First up, we have a critical warning for all Windows users. A zero-day vulnerability with no official fix has been confirmed, leaving
ONSEC.io Research Team
Cyber Daily 12/4: Cisco's Decade-Old WebVPN Vulnerability Fuels Botnet, LastPass Dodges Deepfake CEO Scam, Google Chrome's Emergency Update, PRC Cyber Threats Tackled by CISA & FBI, EU's Cybersecurity Shield, Palo Alto Firewalls Breached

Cyber Daily 12/4: Cisco's Decade-Old WebVPN Vulnerability Fuels Botnet, LastPass Dodges Deepfake CEO Scam, Google Chrome's Emergency Update, PRC Cyber Threats Tackled by CISA & FBI, EU's Cybersecurity Shield, Palo Alto Firewalls Breached

Welcome to today's issue of ONSEC Cyber Daily, where we bring you the most impactful cybersecurity news in one place. Today, we're focusing on the urgent call from Cisco to patch a decade-old WebVPN vulnerability that's fueling the Androxgh0st botnet activity. This comes as
ONSEC.io Research Team
Cyber Daily 12/3: Log4Shell Exploits in VMware, Cisco's Decade-Old ASA WebVPN Vulnerability, Australia's CISC Guidance, Samsung's Security Patch, Windows Driver Vulnerability

Cyber Daily 12/3: Log4Shell Exploits in VMware, Cisco's Decade-Old ASA WebVPN Vulnerability, Australia's CISC Guidance, Samsung's Security Patch, Windows Driver Vulnerability

Welcome to the ONSEC Cyber Daily newsletter for December 3rd, 2024. Today, we delve into the most exploited vulnerabilities of 2023 and how they are shaping the cybersecurity landscape for 2025. We'll discuss how nation-state actors and cybercriminals have leveraged Log4Shell in various campaigns, including its notable use
ONSEC.io Research Team
Cyber Daily 11/30: Russian 0-Click Backdoor Attack on Windows, Bank of England's Cyber Threat Warning, Chinese Cyberespionage Impact on Gov Agencies, Microsoft and Oracle's Critical Patches

Cyber Daily 11/30: Russian 0-Click Backdoor Attack on Windows, Bank of England's Cyber Threat Warning, Chinese Cyberespionage Impact on Gov Agencies, Microsoft and Oracle's Critical Patches

Welcome to ONSEC Cyber Daily Newsletter! Stay ahead of the curve with today’s critical updates in cybersecurity. From alarming 0-click backdoor attacks targeting Windows systems to high-risk vulnerabilities in industry-critical software, the landscape of threats continues to evolve. This edition highlights the latest exploits and patches, emphasizing the urgency
ONSEC.io Research Team
Cyber Daily 11/29: Russian 0-Click Attack on Windows, Zyxel Firewalls Targeted by Helldown, India's Firefox Warning, Raspberry Pi Security, Advantech Wi-Fi Flaws, AI Cyber Warfare

Cyber Daily 11/29: Russian 0-Click Attack on Windows, Zyxel Firewalls Targeted by Helldown, India's Firefox Warning, Raspberry Pi Security, Advantech Wi-Fi Flaws, AI Cyber Warfare

Welcome to another edition of ONSEC Cyber Daily. Today, we're diving into a series of critical cybersecurity updates that have been making headlines. First up, we're looking at a confirmed Russian cyber attack that exploited a severe vulnerability in Windows, leading to a 0-click backdoor attack.
ONSEC.io Research Team
Cyber Daily 11/28: Oracle Agile PLM Flaw, Africa's Cybercrime Crackdown, Google Chrome Security Risks, ProjectSend Exploitation, Australia's Cyber Security Act, Windows 11 Vulnerability, Firefox Zero-Day Flaws

Cyber Daily 11/28: Oracle Agile PLM Flaw, Africa's Cybercrime Crackdown, Google Chrome Security Risks, ProjectSend Exploitation, Australia's Cyber Security Act, Windows 11 Vulnerability, Firefox Zero-Day Flaws

Happy Thanksgiving! 🦃🍁 We hope you’re enjoying this season of gratitude and celebration. Welcome to the latest issue of ONSEC Cyber Daily, your one-stop source for the most impactful cybersecurity news. Today, we're diving into a series of critical vulnerabilities and the urgent actions needed to mitigate them.
ONSEC.io Research Team
Cyber Daily 11/27: PTA Warns of WordPress Plugin Flaw, England's Weather Vulnerability Mapped, Android and iPhone Users Alerted, Grafana and ProjectSend Exploits, Microsoft and QNAP Patch Critical Gaps

Cyber Daily 11/27: PTA Warns of WordPress Plugin Flaw, England's Weather Vulnerability Mapped, Android and iPhone Users Alerted, Grafana and ProjectSend Exploits, Microsoft and QNAP Patch Critical Gaps

Welcome to your daily dose of ONSEC Cyber Daily. Today, we're diving into a plethora of critical security alerts and vulnerabilities that are making waves in the cyber world. First up, we have a critical security alert issued by PTA against a significant flaw in a WordPress plugin.
ONSEC.io Research Team
Cyber Daily 11/26: Palo Alto and Android Vulnerabilities, CISA's New Exploited Catalog, Apple Users Warned, Zyxel Firewall and 7-Zip Breaches, Android & Google Pixel Flaws, Array Networks and QNAP Patches

Cyber Daily 11/26: Palo Alto and Android Vulnerabilities, CISA's New Exploited Catalog, Apple Users Warned, Zyxel Firewall and 7-Zip Breaches, Android & Google Pixel Flaws, Array Networks and QNAP Patches

Welcome to your ONSEC Cyber Daily dose for November 26th. Today, we're diving into a sea of vulnerabilities and warnings that are making waves in the cybersecurity world. First up, Palo Alto's certification validation flaw is causing a stir, allowing attackers to escalate privileges. Meanwhile, Android
ONSEC.io Research Team
Cyber Daily 11/23: Google AI Uncovers 26 Open-Source Vulnerabilities, Indian Govt. Warns Apple Users, EPA Issues Water System Cyberattack Alert, Palo Alto Firewalls Compromised, CISO Insights, Podcasts on Cybersecurity

Cyber Daily 11/23: Google AI Uncovers 26 Open-Source Vulnerabilities, Indian Govt. Warns Apple Users, EPA Issues Water System Cyberattack Alert, Palo Alto Firewalls Compromised, CISO Insights, Podcasts on Cybersecurity

Welcome to your ONSEC Cyber Daily dose for November 23rd. Today, we delve into the world of vulnerabilities and patches. Google's AI has identified 26 new vulnerabilities in open-source projects, highlighting the importance of staying updated. Small businesses are facing heightened vulnerability, with cyber insurance becoming a necessity.
ONSEC.io Research Team
Cyber Daily 11/21: EPA Warns of Water Utility Cyber Vulnerabilities, Indian Govt. Alerts Chrome Bug, VMware VCenter Under Attack, Ubuntu Server Flaws Exposed, Apple and Android Users Urged to Update

Cyber Daily 11/21: EPA Warns of Water Utility Cyber Vulnerabilities, Indian Govt. Alerts Chrome Bug, VMware VCenter Under Attack, Ubuntu Server Flaws Exposed, Apple and Android Users Urged to Update

Welcome to the ONSEC Cyber Daily for November 21st. Today's issue is packed with critical updates and warnings from across the globe. We kick off with a warning from the EPA about cybersecurity vulnerabilities in water utilities, affecting millions of customers. Meanwhile, the Indian government's cybersecurity
ONSEC.io Research Team
Cyber Daily 11/18: Palo Alto's Zero-Day Firewall Bug, Hong Kong's Cybersecurity Drill, Arkansas' Cyber Insurance Need, Five Eyes Alliance's Top Vulnerabilities, MSSP Market Update, NCSC's Black Friday Warning

Cyber Daily 11/18: Palo Alto's Zero-Day Firewall Bug, Hong Kong's Cybersecurity Drill, Arkansas' Cyber Insurance Need, Five Eyes Alliance's Top Vulnerabilities, MSSP Market Update, NCSC's Black Friday Warning

Welcome to your ONSEC Cyber Daily dose for November 18th. Today, we're diving into the world of cybersecurity, where the stakes are high and the threats are ever-evolving. Palo Alto Networks is in the spotlight, patching a critical zero-day firewall bug and dealing with two more bugs in
ONSEC.io Research Team
Cyber Daily 11/15: US EPA Flags Cybersecurity Risks in Water Systems, CISA Reports Rising Zero-Days, Vietnam Strengthens Cybersecurity with CISA, Palo Alto and Cisco Face Critical Vulnerabilities

Cyber Daily 11/15: US EPA Flags Cybersecurity Risks in Water Systems, CISA Reports Rising Zero-Days, Vietnam Strengthens Cybersecurity with CISA, Palo Alto and Cisco Face Critical Vulnerabilities

Welcome to the ONSEC Cyber Daily, your one-stop source for the latest in cybersecurity news. Today, we're diving into a recent US EPA report that highlights significant cybersecurity flaws in our drinking water systems, raising concerns about potential disruptions and public health risks. We'll also be
ONSEC.io Research Team
Cyber Daily 11/14: UK, Five Eyes Warn of Rising Zero-Day Exploits, CyberFirst at Kunoichi Games, Microsoft Patches CVE-2024-43451, D-Link Refuses to Patch Older Modems

Cyber Daily 11/14: UK, Five Eyes Warn of Rising Zero-Day Exploits, CyberFirst at Kunoichi Games, Microsoft Patches CVE-2024-43451, D-Link Refuses to Patch Older Modems

Welcome to today's issue of ONSEC Cyber Daily! As we navigate the ever-evolving cyber landscape, we're seeing a significant shift in cyber attackers exploiting zero-day vulnerabilities. The UK and its allies have issued a stark warning, with the Five Eyes cybersecurity agencies reporting a notable increase
ONSEC.io Research Team
Cyber Daily 11/12: CISA, FBI, NSA Warn of Top 2023 Exploits, Germany on High Alert, Mazda's Vulnerability, Apple and Google Chrome Users at Risk, Critical WordPress and PAN-OS Vulnerabilities, Patch Updates for SAP, HPE, Dell, and Veeam

Cyber Daily 11/12: CISA, FBI, NSA Warn of Top 2023 Exploits, Germany on High Alert, Mazda's Vulnerability, Apple and Google Chrome Users at Risk, Critical WordPress and PAN-OS Vulnerabilities, Patch Updates for SAP, HPE, Dell, and Veeam

Good morning, ONSEC Cyber Daily readers! Today, we're diving into a whirlwind of cybersecurity alerts and vulnerabilities that have been making headlines. The CISA, FBI, NSA, and International Partners have released a joint advisory on the top routinely exploited vulnerabilities of 2023. This comes as Germany's
ONSEC.io Research Team
Cyber Daily 11/9: Critical Google Chrome Alert, Indian Govt Warning, HPE and Palo Alto Vulnerabilities, CISA Warnings, Cisco and Android Flaws, Oracle and Dell Patches

Cyber Daily 11/9: Critical Google Chrome Alert, Indian Govt Warning, HPE and Palo Alto Vulnerabilities, CISA Warnings, Cisco and Android Flaws, Oracle and Dell Patches

Good morning, ONSEC Cyber Daily readers! Today, we're diving into a flurry of critical alerts and warnings that have been issued by various cybersecurity agencies worldwide. First up, Google Chrome users, you're on high alert! The government has issued a severe warning about vulnerabilities that could
ONSEC.io Research Team
Cyber Daily 11/7: Google and Cisco Patch Critical Vulnerabilities, Open Redirect Attacks Exploited, Sports Sector Cyber Vulnerability, Cybersecurity in Healthcare and Elections

Cyber Daily 11/7: Google and Cisco Patch Critical Vulnerabilities, Open Redirect Attacks Exploited, Sports Sector Cyber Vulnerability, Cybersecurity in Healthcare and Elections

Welcome to the November 7th issue of ONSEC Cyber Daily. Today, we're diving into the murky waters of open redirect attacks, a versatile tool that cybercriminals are using to scale their attacks. We'll also explore the potential cyber vulnerabilities in the sports sector, particularly among volunteers.
ONSEC.io Research Team
Cyber Daily 11/6: Google Patches Android Zero-Days, FBI Warns of Email Takeovers, AI Revolutionizes Cybersecurity, Unpatched Synology Devices at Risk

Cyber Daily 11/6: Google Patches Android Zero-Days, FBI Warns of Email Takeovers, AI Revolutionizes Cybersecurity, Unpatched Synology Devices at Risk

Welcome to the ONSEC Cyber Daily! Today, we're diving into the world of Android vulnerabilities, with Google patching two zero-day vulnerabilities that have been exploited in targeted attacks. The FBI has issued a warning about cybercriminals taking over email accounts via stolen session cookies, highlighting the importance of
ONSEC.io Research Team
Cyber Daily 11/5: Google's AI Discovers Vulnerability, CISA Alerts on PTZOptics Cameras & Rockwell Systems, Samsung & Google Patch Android Flaws, Nigerian Phishing Scam, Russian Disinformation Campaign

Cyber Daily 11/5: Google's AI Discovers Vulnerability, CISA Alerts on PTZOptics Cameras & Rockwell Systems, Samsung & Google Patch Android Flaws, Nigerian Phishing Scam, Russian Disinformation Campaign

Welcome to the latest issue of ONSEC Cyber Daily, your one-stop source for the most impactful cybersecurity news. Today, we're diving into a groundbreaking discovery by Google's Project Zero and DeepMind, who have uncovered their first real-world vulnerability using a large language model. This marks a
ONSEC.io Research Team
Cyber Daily 11/4: American Water Cyberattack, SharePoint Flaw Threatens Networks, Nigerian Phishing Scam Conviction, Synology NAS Vulnerability, Russian Disinformation Campaign

Cyber Daily 11/4: American Water Cyberattack, SharePoint Flaw Threatens Networks, Nigerian Phishing Scam Conviction, Synology NAS Vulnerability, Russian Disinformation Campaign

Welcome to the ONSEC Cyber Daily, your one-stop source for the latest cybersecurity news. Today, we're diving into the recent cyberattack on American Water, highlighting the vulnerabilities that continue to plague critical infrastructure sectors. We're also discussing the SharePoint flaw that's putting entire corporate
ONSEC.io Research Team
Cyber Daily 10/31: Fortinet Discloses More Malicious IPs, CISA Updates Manufacturing Software Guidance, AVTECH and Room Alert Support Cybersecurity, Microsoft SharePoint Vulnerability Exploited

Cyber Daily 10/31: Fortinet Discloses More Malicious IPs, CISA Updates Manufacturing Software Guidance, AVTECH and Room Alert Support Cybersecurity, Microsoft SharePoint Vulnerability Exploited

Welcome to your ONSEC Cyber Daily newsletter for October 31st. Today, we're diving into a web of cyber threats and vulnerabilities that are keeping the cybersecurity world on its toes. Fortinet has discovered more malicious IPs linked to a widely exploited zero-day vulnerability, a serious threat that could
ONSEC.io Research Team
Cyber Daily 10/30: Quantum Computing Threat Looms, U.S. Water Sector at Risk, Instagram Vulnerability, Apple and Google Patch Major Flaws, AI Cyberattacks on the Rise

Cyber Daily 10/30: Quantum Computing Threat Looms, U.S. Water Sector at Risk, Instagram Vulnerability, Apple and Google Patch Major Flaws, AI Cyberattacks on the Rise

Welcome to ONSEC Cyber Daily! We're thrilled to introduce our new section: "Wisdom from the ONSEC Founders' Vault." Tap into the expertise of our founders with exclusive insights and strategies to stay ahead in cybersecurity. In today’s issue: * Quantum computing threatens encryption as criminals
ONSEC.io Research Team
Cyber Daily 10/28: Belgium's Leonidas Project, Critical Infrastructure Cybersecurity, CISA and FBI Alert on XSS, Philips Smart Bulbs' IoT Vulnerabilities, Microsoft Windows High Risk Warning

Cyber Daily 10/28: Belgium's Leonidas Project, Critical Infrastructure Cybersecurity, CISA and FBI Alert on XSS, Philips Smart Bulbs' IoT Vulnerabilities, Microsoft Windows High Risk Warning

Welcome to the ONSEC Cyber Daily, your one-stop source for the latest in cybersecurity news. In today's issue, we delve into Belgium's Leonidas Project and its efforts to boost national cyber resilience, a critical initiative in a world where cyber threats are a constant buzz. We
ONSEC.io Research Team
Cyber Daily 10/25: Nvidia Security Alert for Gamers, Water Utilities Vulnerable Post-Pennsylvania Attack, FortiManager Devices Compromised, Virgin Media's Public Wi-Fi Warning

Cyber Daily 10/25: Nvidia Security Alert for Gamers, Water Utilities Vulnerable Post-Pennsylvania Attack, FortiManager Devices Compromised, Virgin Media's Public Wi-Fi Warning

Welcome to the latest issue of ONSEC Cyber Daily, your one-stop source for the most impactful cybersecurity news. Today, we're diving into a critical security warning for 200 million Nvidia users, both Linux and Windows gamers alike. Veteran cybersecurity writer, Davey Winder, has highlighted an improper input validation
ONSEC.io Research Team
Cyber Daily 10/24: Russian Cyber Campaign Intensifies, Fortinet FortiManager Vulnerability Exploited, Cyberattacks on Spring Java Framework, Critical Alerts for Windows and Cisco Updates

Cyber Daily 10/24: Russian Cyber Campaign Intensifies, Fortinet FortiManager Vulnerability Exploited, Cyberattacks on Spring Java Framework, Critical Alerts for Windows and Cisco Updates

Welcome to the ONSEC Cyber Daily for October 24th. Today, we're diving into the escalating cyber campaign by Russian Intelligence, as reported by the Kyiv Post. Western intelligence agencies are urging organizations worldwide to stay vigilant. In the UK, the National Cyber Security Centre (NCSC) is offering a
ONSEC.io Research Team
Cyber Daily 10/23: Zimbra, Stormshield Vulnerability Alert, Veeam Ransomware Exploits, VMware's Patching Crisis, Bitdefender's Critical Flaws, and Cybersecurity Podcast Insights

Cyber Daily 10/23: Zimbra, Stormshield Vulnerability Alert, Veeam Ransomware Exploits, VMware's Patching Crisis, Bitdefender's Critical Flaws, and Cybersecurity Podcast Insights

Welcome to the ONSEC Cyber Daily for October 23rd. Today, we're diving into a whirlwind of vulnerabilities, patches, and cyber threats that have been making waves in the cybersecurity world. We start with a critical vulnerability in the Postjournal Zimbra software suite, which has prompted a security alert
ONSEC.io Research Team
Cyber Daily 10/18: GitHub and Mozilla Firefox Vulnerabilities, US Indicts Russia's GRU Unit, Critical Patches for Kubernetes and VMware, Podcast Insights from CISO Rubrik

Cyber Daily 10/18: GitHub and Mozilla Firefox Vulnerabilities, US Indicts Russia's GRU Unit, Critical Patches for Kubernetes and VMware, Podcast Insights from CISO Rubrik

Welcome to your ONSEC Cyber Daily dose for October 18th. Today, we're diving deep into the world of cybersecurity, exploring the critical role of VAPT in fortifying our digital defenses. With over 72% of organizations worldwide falling victim to at least one ransomware attack, the need for robust
ONSEC.io Research Team
Cyber Daily 10/16: GitHub Patches Critical Flaw, Muah.ai Faces Extortion Threats, Russian Cyber Campaign Threatens UK

Cyber Daily 10/16: GitHub Patches Critical Flaw, Muah.ai Faces Extortion Threats, Russian Cyber Campaign Threatens UK

Good morning, ONSEC Cyber Daily readers! Today’s highlights include GitHub patching a critical Enterprise Server flaw to prevent unauthorized access and the Muah.ai breach exposing cyber vulnerabilities and leading to extortion threats. Organizations must also address exploited SolarWinds Web Help Desk vulnerabilities and stay alert to a new
ONSEC.io Research Team
Cyber Daily 10/15: High-Risk Android, Chrome Warnings, Veeam Exploits, muah.ai Breach, CERT-In Alerts, NSA on Russian Threats, GitLab Patches, AI Cybersecurity Podcasts

Cyber Daily 10/15: High-Risk Android, Chrome Warnings, Veeam Exploits, muah.ai Breach, CERT-In Alerts, NSA on Russian Threats, GitLab Patches, AI Cybersecurity Podcasts

Hello ONSEC Cyber Daily readers! Today’s edition covers critical cybersecurity updates. CERT-In has issued a high-risk warning for Android devices and Google Chrome, highlighting vulnerabilities that could be exploited through malicious apps or websites. The National Cyber Security Centre also reports a rise in denial-of-service (DoS) attacks disrupting organizations.
ONSEC.io Research Team
ONSEC Cyber Daily 10/14: Critical Cyber Alerts: Android and Chrome Risks in India and Vietnam, Jamaica’s Vulnerability, Fortinet and Firefox Patches

ONSEC Cyber Daily 10/14: Critical Cyber Alerts: Android and Chrome Risks in India and Vietnam, Jamaica’s Vulnerability, Fortinet and Firefox Patches

Welcome to your daily briefing from ONSEC Cyber Daily. Today, we spotlight a surge of global cyber threats raising alarms across nations. In India, Android and Google Chrome users face critical risks, prompting the government to issue an urgent advisory. CERT-In has flagged severe vulnerabilities that could pave the way
ONSEC.io Research Team