03/13

Chinese snoops spotted on end-of-life Juniper routers • The Register

https://www.theregister.com/2025/03/12/china_spy_juniper_routers/
Chinese snoops spotted on end-of-life Juniper routers • The Register

Exploiting Reversing (ER) series: article 05 | Hyper-V (part 01) – Exploit Reversing

https://exploitreversing.com/2025/03/12/exploiting-reversing-er-series-article-05/
Exploiting Reversing (ER) series: article 05 | Hyper-V (part 01) – Exploit Reversing

New SuperBlack ransomware exploits Fortinet auth bypass flaws

https://www.bleepingcomputer.com/news/security/new-superblack-ransomware-exploits-fortinet-auth-bypass-flaws/
New SuperBlack ransomware exploits Fortinet auth bypass flaws

Microsoft apologizes for removing VSCode extensions used by millions

https://www.bleepingcomputer.com/news/microsoft/microsoft-apologizes-for-removing-vscode-extensions-used-by-millions/
Microsoft apologizes for removing VSCode extensions used by millions

DeepSeek spits out malware code with a little persuasion • The Register

https://go.theregister.com/feed/www.theregister.com/2025/03/13/deepseek_malware_code/
DeepSeek spits out malware code with a little persuasion • The Register

GitHub Uncovers New ruby-saml Vulnerabilities Allowing Account Takeover Attacks

https://thehackernews.com/2025/03/github-uncovers-new-ruby-saml.html
GitHub Uncovers New ruby-saml Vulnerabilities Allowing Account Takeover Attacks

Disclosing YouTube Creator Emails for a $20k Bounty

https://brutecat.com/articles/youtube-creator-emails
Disclosing YouTube Creator Emails for a $20k Bounty

Microsoft says button to restore classic Outlook is broken

https://www.bleepingcomputer.com/news/microsoft/microsoft-says-button-to-restore-classic-outlook-is-broken/
Microsoft says button to restore classic Outlook is broken

Windows Notepad to get AI text summarization in Windows 11

https://www.bleepingcomputer.com/news/microsoft/windows-notepad-to-get-ai-text-summarization-in-windows-11/
Windows Notepad to get AI text summarization in Windows 11

Sign in as anyone: Bypassing SAML SSO authentication with parser differentials - The GitHub Blog

https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials - The GitHub Blog

GitLab patches critical authentication bypass vulnerabilities

https://www.bleepingcomputer.com/news/security/gitlab-patches-critical-authentication-bypass-vulnerabilities/
GitLab patches critical authentication bypass vulnerabilities

Medusa Ransomware Made 300 Critical Infrastructure Victims - SecurityWeek

https://www.securityweek.com/medusa-ransomware-made-300-critical-infrastructure-victims/
Medusa Ransomware Made 300 Critical Infrastructure Victims - SecurityWeek

Lookout Discovers North Korean APT37 Mobile Spyware | Threat Intel

https://www.lookout.com/threat-intelligence/article/lookout-discovers-new-spyware-by-north-korean-apt37
Lookout Discovers North Korean APT37 Mobile Spyware | Threat Intel

ArechClient; Decoding IOCs and finding the onboard browser extension | by Jason Reaves | Walmart Global Tech Blog | Mar, 2025 | Medium

https://medium.com/walmartglobaltech/arechclient-decoding-iocs-and-finding-the-onboard-browser-extension-477f8796568d
ArechClient; Decoding IOCs and finding the onboard browser extension | by Jason Reaves | Walmart Global Tech Blog | Mar, 2025 | Medium

oss-security - CVE-2025-27363: out of bounds write in FreeType <= 2.13.0

https://www.openwall.com/lists/oss-security/2025/03/13/2
oss-security - CVE-2025-27363: out of bounds write in FreeType <= 2.13.0

Juniper patches bug that let Chinese cyberspies backdoor routers

https://www.bleepingcomputer.com/news/security/juniper-patches-bug-that-let-chinese-cyberspies-backdoor-routers-since-mid-2024/
Juniper patches bug that let Chinese cyberspies backdoor routers

Saudi Arabia Buys Pokémon Go, and Probably All of Your Location Data

https://www.404media.co/saudi-arabia-buys-pokemon-go-and-probably-all-of-your-location-data/
Saudi Arabia Buys Pokémon Go, and Probably All of Your Location Data

CVE-2025-24048 - Security Update Guide - Microsoft - Windows Hyper-V Elevation of Privilege Vulnerability

https://msrc.microsoft.com/update-guide/en-us/vulnerability/CVE-2025-24048
CVE-2025-24048 - Security Update Guide - Microsoft - Windows Hyper-V Elevation of Privilege Vulnerability

Volt Typhoon Strikes Massachusetts Power Utility

https://www.darkreading.com/cyberattacks-data-breaches/volt-typhoon-strikes-massachusetts-power-utility
Volt Typhoon Strikes Massachusetts Power Utility

Microsoft Warns of ClickFix Phishing Campaign Targeting Hospitality Sector via Fake Booking[.]com Emails

https://thehackernews.com/2025/03/microsoft-warns-of-clickfix-phishing.html
Microsoft Warns of ClickFix Phishing Campaign Targeting Hospitality Sector via Fake Booking[.]com Emails

oss-security - CVE-2025-27363: out of bounds write in FreeType <= 2.13.0

https://www.openwall.com/lists/oss-security/2025/03/13/1
oss-security - CVE-2025-27363: out of bounds write in FreeType <= 2.13.0