Chinese snoops spotted on end-of-life Juniper routers • The Register
https://www.theregister.com/2025/03/12/china_spy_juniper_routers/
Exploiting Reversing (ER) series: article 05 | Hyper-V (part 01) – Exploit Reversing
https://exploitreversing.com/2025/03/12/exploiting-reversing-er-series-article-05/
New SuperBlack ransomware exploits Fortinet auth bypass flaws
https://www.bleepingcomputer.com/news/security/new-superblack-ransomware-exploits-fortinet-auth-bypass-flaws/
Microsoft apologizes for removing VSCode extensions used by millions
https://www.bleepingcomputer.com/news/microsoft/microsoft-apologizes-for-removing-vscode-extensions-used-by-millions/
DeepSeek spits out malware code with a little persuasion • The Register
https://go.theregister.com/feed/www.theregister.com/2025/03/13/deepseek_malware_code/
GitHub - iSee857/CVE-2025-24813-PoC: Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)
https://github.com/iSee857/CVE-2025-24813-PoC
GitHub Uncovers New ruby-saml Vulnerabilities Allowing Account Takeover Attacks
https://thehackernews.com/2025/03/github-uncovers-new-ruby-saml.html
Disclosing YouTube Creator Emails for a $20k Bounty
https://brutecat.com/articles/youtube-creator-emails
libxml2:api: Stack-buffer-overflow in xmlValidateElementContent [392687022] - OSS Fuzz
https://issues.oss-fuzz.com/issues/392687022![libxml2:api: Stack-buffer-overflow in xmlValidateElementContent [392687022] - OSS Fuzz](/image/screenshot/614bee806e60d7e7fc6a2d0536ccdce9.png)
Microsoft says button to restore classic Outlook is broken
https://www.bleepingcomputer.com/news/microsoft/microsoft-says-button-to-restore-classic-outlook-is-broken/

Windows Notepad to get AI text summarization in Windows 11
https://www.bleepingcomputer.com/news/microsoft/windows-notepad-to-get-ai-text-summarization-in-windows-11/
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials - The GitHub Blog
https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/
GitLab patches critical authentication bypass vulnerabilities
https://www.bleepingcomputer.com/news/security/gitlab-patches-critical-authentication-bypass-vulnerabilities/
Medusa Ransomware Made 300 Critical Infrastructure Victims - SecurityWeek
https://www.securityweek.com/medusa-ransomware-made-300-critical-infrastructure-victims/
Lookout Discovers North Korean APT37 Mobile Spyware | Threat Intel
https://www.lookout.com/threat-intelligence/article/lookout-discovers-new-spyware-by-north-korean-apt37
ArechClient; Decoding IOCs and finding the onboard browser extension | by Jason Reaves | Walmart Global Tech Blog | Mar, 2025 | Medium
https://medium.com/walmartglobaltech/arechclient-decoding-iocs-and-finding-the-onboard-browser-extension-477f8796568d
[原创]Hyper-v虚拟磁盘驱动vhdmp.sys漏洞汇总分析-二进制漏洞-看雪-安全社区|安全招聘|kanxue.com
https://bbs.kanxue.com/thread-285976.htm?style=1![[原创]Hyper-v虚拟磁盘驱动vhdmp.sys漏洞汇总分析-二进制漏洞-看雪-安全社区|安全招聘|kanxue.com](/image/screenshot/c855569f7b2dc9ed29ea908c1b5ae772.png)
oss-security - CVE-2025-27363: out of bounds write in FreeType <= 2.13.0
https://www.openwall.com/lists/oss-security/2025/03/13/2
Juniper patches bug that let Chinese cyberspies backdoor routers
https://www.bleepingcomputer.com/news/security/juniper-patches-bug-that-let-chinese-cyberspies-backdoor-routers-since-mid-2024/
Saudi Arabia Buys Pokémon Go, and Probably All of Your Location Data
https://www.404media.co/saudi-arabia-buys-pokemon-go-and-probably-all-of-your-location-data/
CVE-2025-24048 - Security Update Guide - Microsoft - Windows Hyper-V Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/en-us/vulnerability/CVE-2025-24048
Volt Typhoon Strikes Massachusetts Power Utility
https://www.darkreading.com/cyberattacks-data-breaches/volt-typhoon-strikes-massachusetts-power-utility
Microsoft Warns of ClickFix Phishing Campaign Targeting Hospitality Sector via Fake Booking[.]com Emails
https://thehackernews.com/2025/03/microsoft-warns-of-clickfix-phishing.html![Microsoft Warns of ClickFix Phishing Campaign Targeting Hospitality Sector via Fake Booking[.]com Emails](/image/screenshot/1c81c765f8bc0885b124bb77ae3f8a13.png)
Support channel binding and ldap signing for ntlm and kerberos auth by zblurx · Pull Request #1919 · fortra/impacket · GitHub
https://github.com/fortra/impacket/pull/1919
oss-security - CVE-2025-27363: out of bounds write in FreeType <= 2.13.0
https://www.openwall.com/lists/oss-security/2025/03/13/1