Category: Security

Cybersecurity Awareness Month: Simple steps for cyber safety in 2025

Cybersecurity Awareness Month: Simple steps for cyber safety in 2025

October 1 marked the beginning of Cybersecurity Awareness Month (CAM), an annual initiative dedicated to raising awareness about cybersecurity and promoting safe online practices. Each October, governments, public sector agencies and private sector partners join forces, organizing events and media...

/ October 6, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Linux sudo vulnerability

Cybersecurity Threat Advisory: Critical Linux sudo vulnerability

Security researchers have uncovered a serious vulnerability in sudo, the tool that runs commands with elevated privileges on Linux systems. It is tracked as CVE-2025-32463 and carries a CVSS score of 9.3. This flaw poses a serious risk to Linux...

/ October 2, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: VMware zero-day vulnerability exploited

Cybersecurity Threat Advisory: VMware zero-day vulnerability exploited

Threat actors have actively exploited a zero-day vulnerability in Broadcom VMware Tools and VMware Aria Operations (CVE-2025-41244) in the wild. The China-linked group UNC5174 (aka Uteus/Uetus) has exploited the flaw for privilege escalation in VMware-targeted attacks. Continue reading this edition...

/ October 1, 2025 / 1 Comment
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Cisco IOS and IOS XE SNMP vulnerability

Cybersecurity Threat Advisory: Cisco IOS and IOS XE SNMP vulnerability

Several vulnerability advisories were issued that impact devices using Cisco IOS and Cisco IOS XE firmware. Most notably, CVE-2025-20352 has already been observed in active exploitation. Continue reading this Cybersecurity Threat Advisory to mitigate your risks from this vulnerability. What...

/ October 1, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall VPNs targeted by Akira ransomware

Cybersecurity Threat Advisory: SonicWall VPNs targeted by Akira ransomware

Akira ransomware operators have launched an aggressive campaign targeting SonicWall VPN appliances. Attackers have already breached accounts protected by multi-factor authentication (MFA) successfully, leveraging vulnerabilities in SonicWall Secure Mobile Access (SMA) and SSL-VPN portals. The campaign is characterized by rapid...

/ September 30, 2025
MSPs
MSPs are redefining supply chain defense

MSPs are redefining supply chain defense

As a journalist covering the cybersecurity business landscape, I’ve closely followed the growing impact of supply chain attacks throughout 2025. These incidents continue to escalate in frequency and complexity, affecting organizations of all sizes across industries. This two-part series brings...

/ September 30, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Cisco ASA zero-day vulnerability

Cybersecurity Threat Advisory: Cisco ASA zero-day vulnerability

Threat actors are actively exploiting two critical zero-day vulnerabilities in Cisco Secure Firewall ASA and FTD software. CVE-2025-20333 (CVSS 9.9) and CVE-2025-20362 (CVSS 6.5) allow attackers to chain exploits that bypass authentication and execute malicious code. In response, the U.S....

/ September 26, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: RCE vulnerability in SolarWinds WHD

Cybersecurity Threat Advisory: RCE vulnerability in SolarWinds WHD

A critical remote code execution (RCE) vulnerability, CVE-2025-26399, has been identified in SolarWinds Web Help Desk (WHD) and remains exploitable despite previous fixes. The flaw allows unauthenticated attackers to execute arbitrary code on vulnerable servers, leading to a full system...

/ September 24, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Severe GoAnywhere MFT vulnerability

Cybersecurity Threat Advisory: Severe GoAnywhere MFT vulnerability

Fortra disclosed a critical vulnerability in GoAnywhere Managed File Transfer (MFT), tracked as CVE-2025-10035, with a CVSS score of 10.0. The flaw allows attackers to execute remote code without authentication. Review this Cybersecurity Threat Advisory to keep your systems safe....

/ September 24, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Fake password managers

Cybersecurity Threat Advisory: Fake password managers

LastPass has issued a warning about a widespread cyber campaign targeting macOS users. Malicious software is being disguised as legitimate applications and distributed through fake GitHub repositories. Read this Cybersecurity Threat Advisory to stay informed and protect your data. What...

/ September 23, 2025