09/09

APT37: Rust Backdoor & Python Loader | ThreatLabz

https://www.zscaler.com/blogs/security-research/apt37-targets-windows-rust-backdoor-and-python-loader
APT37: Rust Backdoor & Python Loader | ThreatLabz

Plex tells users to reset passwords after new data breach

https://www.bleepingcomputer.com/news/security/plex-tells-users-to-reset-passwords-after-new-data-breach/
Plex tells users to reset passwords after new data breach

Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days

https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2025-patch-tuesday-fixes-81-flaws-two-zero-days/
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days

UEFI Petya PoC - YouTube

https://www.youtube.com/watch?v=dMOiypRXWkk
UEFI Petya PoC - YouTube

Microsoft: Anti-spam bug blocks links in Exchange Online, Teams

https://www.bleepingcomputer.com/news/microsoft/microsoft-anti-spam-bug-blocks-links-in-exchange-online-teams/
Microsoft: Anti-spam bug blocks links in Exchange Online, Teams

20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack

https://thehackernews.com/2025/09/20-popular-npm-packages-with-2-billion.html
20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack

Kosovo hacker pleads guilty to running BlackDB cybercrime marketplace

https://www.bleepingcomputer.com/news/security/kosovo-hacker-pleads-guilty-to-running-blackdb-cybercrime-marketplace/
Kosovo hacker pleads guilty to running BlackDB cybercrime marketplace

OSEE に合格したけど、もっと頑張ろうと思った話

https://io.cyberdefense.jp/entry/osee_niida/
OSEE に合格したけど、もっと頑張ろうと思った話

Surge in networks scans targeting Cisco ASA devices raise concerns

https://www.bleepingcomputer.com/news/security/surge-in-networks-scans-targeting-cisco-asa-devices-raise-concerns/
Surge in networks scans targeting Cisco ASA devices raise concerns

US charges admin of LockerGoga, MegaCortex, Nefilim ransomware

https://www.bleepingcomputer.com/news/security/us-charges-admin-of-lockergoga-megacortex-nefilim-ransomware/
US charges admin of LockerGoga, MegaCortex, Nefilim ransomware

SentinelOne to Acquire Observo AI in $225 Million Deal - SecurityWeek

https://www.securityweek.com/sentinelone-to-acquire-observo-ai-in-225-million-deal/
SentinelOne to Acquire Observo AI in $225 Million Deal - SecurityWeek

SAP fixes maximum severity NetWeaver command execution flaw

https://www.bleepingcomputer.com/news/security/sap-fixes-maximum-severity-netweaver-command-execution-flaw/
SAP fixes maximum severity NetWeaver command execution flaw

How I Hack Websites With Just HTML Injection | by Ibtissam hammadi | Sep, 2025 | InfoSec Write-ups

https://infosecwriteups.com/how-i-hack-websites-with-just-html-injection-9ccbc87faf47?source=rss------bug_bounty-5
How I Hack Websites With Just HTML Injection | by Ibtissam hammadi | Sep, 2025 | InfoSec Write-ups

Adobe patches critical SessionReaper flaw in Magento eCommerce platform

https://www.bleepingcomputer.com/news/security/adobe-patches-critical-sessionreaper-flaw-in-magento-ecommerce-platform/
Adobe patches critical SessionReaper flaw in Magento eCommerce platform

TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs

https://thehackernews.com/2025/09/tor-based-cryptojacking-attack-expands.html
TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs

18 Popular Code Packages Hacked, Rigged to Steal Crypto – Krebs on Security

https://krebsonsecurity.com/2025/09/18-popular-code-packages-hacked-rigged-to-steal-crypto/
18 Popular Code Packages Hacked, Rigged to Steal Crypto – Krebs on Security

SAP Patches Critical NetWeaver Vulnerabilities - SecurityWeek

https://www.securityweek.com/sap-patches-critical-netweaver-vulnerabilities/
SAP Patches Critical NetWeaver Vulnerabilities - SecurityWeek

MostereRAT Deployed AnyDesk/TightVNC for Covert Full Access | FortiGuard Labs

https://www.fortinet.com/blog/threat-research/mostererat-deployed-anydesk-tightvnc-for-covert-full-access
MostereRAT Deployed AnyDesk/TightVNC for Covert Full Access | FortiGuard Labs

Hackers hide behind Tor in exposed Docker API breaches

https://www.bleepingcomputer.com/news/security/hackers-hide-behind-tor-in-exposed-docker-api-breaches/
Hackers hide behind Tor in exposed Docker API breaches

Windows 11 KB5065426 & KB5065431 cumulative updates released

https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5065426-and-kb5065431-cumulative-updates-released/
Windows 11 KB5065426 & KB5065431 cumulative updates released

Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks

https://thehackernews.com/2025/09/axios-abuse-and-salty-2fa-kits-fuel.html
Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks