Skip to content
Threat Note Threat Note

Aggregating Cyber Insights

  • Articles
  • Breaches
  • Learning
  • News
  • Podcast
  • Research
  • Toolkit
  • Vulnerabilities
  • Webinars
  • About Us

Vulnerabilities

  • Home
  • Vulnerabilities
From Cybersecurity Help – Suspected Chinese cyber spies target US tech and legal sectors with Brickstorm backdoor
Posted inVulnerabilities

From Cybersecurity Help – Suspected Chinese cyber spies target US tech and legal sectors with Brickstorm backdoor

The attacks remained undetected for an average of 393 days, allowing the attackers to siphon off sensitive data for over a year in some cases.  ​ Read More  ​ 
Posted by Samir K September 25, 2025
From Cybersecurity Help – Russia-linked Coldriver hackers add ClickFix technique to their arsenal
Posted inVulnerabilities

From Cybersecurity Help – Russia-linked Coldriver hackers add ClickFix technique to their arsenal

The multi-stage approach represents an evolution in Coldrivers's tactics, which previously relied mostly on credential phishing.  ​ Read More  ​ 
Posted by Samir K September 25, 2025
From Cybersecurity Help – SonicWall rolls out firmware update to remove rootkit malware from SMA 100 devices
Posted inVulnerabilities

From Cybersecurity Help – SonicWall rolls out firmware update to remove rootkit malware from SMA 100 devices

The company urges all users of the SMA 100 series, including SMA 210, 410, and 500v models, to upgrade as soon as possible.  ​ Read More  ​ 
Posted by Samir K September 24, 2025
From Cybersecurity Help – Hackers exploited critical GeoServer RCE flaw to breach US federal agency
Posted inVulnerabilities

From Cybersecurity Help – Hackers exploited critical GeoServer RCE flaw to breach US federal agency

The intruders moved laterally across the agency's network, targeting and infiltrating a web server and an SQL server.  ​ Read More  ​ 
Posted by Samir K September 24, 2025
From Cybersecurity Help – Nation state hackers exploit Libraesva ESG command injection bug
Posted inVulnerabilities

From Cybersecurity Help – Nation state hackers exploit Libraesva ESG command injection bug

The flaw, tracked as CVE-2025-59689, impacts ESG versions 4.5 through 5.5.x, up to but not including 5.5.7.  ​ Read More  ​ 
Posted by Samir K September 24, 2025
From Cybersecurity Help – US Secret Service dismantles bot farm used for swatting American officials
Posted inVulnerabilities

From Cybersecurity Help – US Secret Service dismantles bot farm used for swatting American officials

The network included over 300 SIM servers and 100,000 SIM cards.  ​ Read More  ​ 
Posted by Samir K September 24, 2025
From Cybersecurity Help – New EDR-Freeze technique uses Windows error reporting to disable security tools
Posted inVulnerabilities

From Cybersecurity Help – New EDR-Freeze technique uses Windows error reporting to disable security tools

The technique exploits legitimate Windows components to force EDR and antivirus processes into a suspended or ‘coma’ state.  ​ Read More  ​ 
Posted by Samir K September 23, 2025
From Cybersecurity Help – Moldovan authorities raid media company linked to Russian propaganda
Posted inVulnerabilities

From Cybersecurity Help – Moldovan authorities raid media company linked to Russian propaganda

The media company in question was part of a wider disinformation network financed through a complex money-laundering scheme.  ​ Read More  ​ 
Posted by Samir K September 23, 2025
From Cybersecurity Help – GitHub to update npm publishing after major supply chain attack
Posted inVulnerabilities

From Cybersecurity Help – GitHub to update npm publishing after major supply chain attack

The company plans to introduce new security measures aimed at reducing the risks posed by token abuse, credential theft, and malware propagation.  ​ Read More  ​ 
Posted by Samir K September 23, 2025
From Cybersecurity Help – Iran-linked Nimbus Manticore hackers deploy malware targeting Europe
Posted inVulnerabilities

From Cybersecurity Help – Iran-linked Nimbus Manticore hackers deploy malware targeting Europe

The threat actor sends highly targeted phishing emails that look like job offers from HR recruiters.  ​ Read More  ​ 
Posted by Samir K September 23, 2025
From Cybersecurity Help – Large-scale campaign uses fake GitHub repositories to spread Atomic Stealer malware
Posted inVulnerabilities

From Cybersecurity Help – Large-scale campaign uses fake GitHub repositories to spread Atomic Stealer malware

The attackers are using SEO poisoning to manipulate Google and Bing search results.  ​ Read More  ​ 
Posted by Samir K September 22, 2025
From Cybersecurity Help – Ukraine’s Security Service detains two Russian agents who smuggled Ukrainian SIM cards to Russia
Posted inVulnerabilities

From Cybersecurity Help – Ukraine’s Security Service detains two Russian agents who smuggled Ukrainian SIM cards to Russia

The SIM cards were used to enhance the communication and navigation systems of combat UAVs.  ​ Read More  ​ 
Posted by Samir K September 22, 2025
From Cybersecurity Help – Ransomware attack disrupts airports worldwide
Posted inVulnerabilities

From Cybersecurity Help – Ransomware attack disrupts airports worldwide

The cyberattack targeted software systems provided by US defense and aviation firm Collins Aerospace.  ​ Read More  ​ 
Posted by Samir K September 22, 2025
From Cybersecurity Help – Fortra patches GoAnywhere MFT command injection flaw
Posted inVulnerabilities

From Cybersecurity Help – Fortra patches GoAnywhere MFT command injection flaw

The flaw stems from a deserialization of untrusted data issue, which can be exploited without user interaction in low-complexity attacks.  ​ Read More  ​ 
Posted by Samir K September 22, 2025
From Cybersecurity Help – Cyber Security Week in Review: September 19, 2025
Posted inVulnerabilities

From Cybersecurity Help – Cyber Security Week in Review: September 19, 2025

In brief: Google patches a Chrome zero-day flaw, Gamaredon and Turla join efforts in attacks on Ukraine, and more.  ​ Read More  ​ 
Posted by Samir K September 19, 2025

Posts pagination

1 2 3 … 83 Next page

Latest Posts

  • From Dark Reading – How Cloud Service Disruptions Are Making Resilience Critical for DevelopersSeptember 25, 2025
  • From The Hacker News – North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto DevelopersSeptember 25, 2025
  • From Security Week – Chinese Cyberspies Hacked US Defense ContractorsSeptember 25, 2025
  • From Cyber Security News – New LockBit 5.0 Ransomware Variant Attacking Windows, Linux, and ESXi SystemsSeptember 25, 2025
  • From Security Week – RTX Confirms Airport Services Hit by RansomwareSeptember 25, 2025
Total Visitors
0575564

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • December 2022
  • November 2022
  • May 2022
Copyright 2025 — Threat Note. All rights reserved. Bloghash WordPress Theme
Scroll to Top