08/13

Persistent Risk: XZ Utils Backdoor Still Lurking in Docker Images

https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images
Persistent Risk: XZ Utils Backdoor Still Lurking in Docker Images

LOLDrivers

http://LOLdrivers.io
LOLDrivers

Microsoft asks users to ignore certificate enrollment errors

https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-certificate-enrollment-errors/
Microsoft asks users to ignore certificate enrollment errors

Spike in Fortinet VPN brute-force attacks raises zero-day concerns

https://www.bleepingcomputer.com/news/security/spike-in-fortinet-vpn-brute-force-attacks-raises-zero-day-concerns/
Spike in Fortinet VPN brute-force attacks raises zero-day concerns

Microsoft removes PowerShell 2.0 from Windows 11, Windows Server

https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-powershell-20-from-windows-11-windows-server/
Microsoft removes PowerShell 2.0 from Windows 11, Windows Server

New downgrade attack can bypass FIDO auth in Microsoft Entra ID

https://www.bleepingcomputer.com/news/security/new-downgrade-attack-can-bypass-fido-auth-in-microsoft-entra-id/
New downgrade attack can bypass FIDO auth in Microsoft Entra ID

Conferences/BlackHat_USA_2025_Slides at main · onhexgroup/Conferences · GitHub

https://github.com/onhexgroup/Conferences/tree/main/BlackHat_USA_2025_Slides
Conferences/BlackHat_USA_2025_Slides at main · onhexgroup/Conferences · GitHub

Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws

https://thehackernews.com/2025/08/microsoft-august-2025-patch-tuesday.html
Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws

China Questions Security of AI Chips From NVIDIA, AMD

https://www.darkreading.com/cyber-risk/china-questions-security-ai-chips-nvidia-amd
China Questions Security of AI Chips From NVIDIA, AMD

Hackers leak Allianz Life data stolen in Salesforce attacks

https://www.bleepingcomputer.com/news/security/hackers-leak-allianz-life-data-stolen-in-salesforce-attacks/
Hackers leak Allianz Life data stolen in Salesforce attacks

Novel SSRF Technique Involving HTTP Redirect Loops › Searchlight Cyber

https://slcyber.io/assetnote-security-research-center/novel-ssrf-technique-involving-http-redirect-loops/
Novel SSRF Technique Involving HTTP Redirect Loops › Searchlight Cyber

Researchers cracked the encryption used by DarkBit ransomware

https://securityaffairs.com/181064/malware/researchers-cracked-the-encryption-used-by-darkbit-ransomware.html
Researchers cracked the encryption used by DarkBit ransomware

Curly COMrades: A New Threat Actor Targeting Geopolitical Hotbeds

https://businessinsights.bitdefender.com/curly-comrades-new-threat-actor-targeting-geopolitical-hotbeds
Curly COMrades: A New Threat Actor Targeting Geopolitical Hotbeds

CVE-2025-50154:Zero Click, One NTLM: Patch Bypass

https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/
CVE-2025-50154:Zero Click, One NTLM: Patch Bypass

Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code

https://thehackernews.com/2025/08/fortinet-warns-about-fortisiem.html
Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises | Trend Micro (US)

https://www.trendmicro.com/en_us/research/25/h/new-ransomware-charon.html
New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises | Trend Micro (US)

AIxCC Competition Archive | AIxCC Competition Archive

https://archive.aicyberchallenge.com/
AIxCC Competition Archive | AIxCC Competition Archive

From Support Ticket to Zero Day | Horizon3.ai

https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/
From Support Ticket to Zero Day | Horizon3.ai

CVE-2025-53769 - Security Update Guide - Microsoft - Windows Security App Spoofing Vulnerability

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53769
CVE-2025-53769 - Security Update Guide - Microsoft - Windows Security App Spoofing Vulnerability