Blog - Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
https://security.apple.com/blog/memory-integrity-enforcement/
APT37: Rust Backdoor & Python Loader | ThreatLabz
https://www.zscaler.com/blogs/security-research/apt37-targets-windows-rust-backdoor-and-python-loader
Plex tells users to reset passwords after new data breach
https://www.bleepingcomputer.com/news/security/plex-tells-users-to-reset-passwords-after-new-data-breach/
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2025-patch-tuesday-fixes-81-flaws-two-zero-days/
UEFI Petya PoC - YouTube
https://www.youtube.com/watch?v=dMOiypRXWkk
Microsoft: Anti-spam bug blocks links in Exchange Online, Teams
https://www.bleepingcomputer.com/news/microsoft/microsoft-anti-spam-bug-blocks-links-in-exchange-online-teams/
20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack
https://thehackernews.com/2025/09/20-popular-npm-packages-with-2-billion.html
SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025-54236)
https://sansec.io/research/sessionreaper
Kosovo hacker pleads guilty to running BlackDB cybercrime marketplace
https://www.bleepingcomputer.com/news/security/kosovo-hacker-pleads-guilty-to-running-blackdb-cybercrime-marketplace/
OSEE に合格したけど、もっと頑張ろうと思った話
https://io.cyberdefense.jp/entry/osee_niida/
Surge in networks scans targeting Cisco ASA devices raise concerns
https://www.bleepingcomputer.com/news/security/surge-in-networks-scans-targeting-cisco-asa-devices-raise-concerns/
US charges admin of LockerGoga, MegaCortex, Nefilim ransomware
https://www.bleepingcomputer.com/news/security/us-charges-admin-of-lockergoga-megacortex-nefilim-ransomware/
SentinelOne to Acquire Observo AI in $225 Million Deal - SecurityWeek
https://www.securityweek.com/sentinelone-to-acquire-observo-ai-in-225-million-deal/
SAP fixes maximum severity NetWeaver command execution flaw
https://www.bleepingcomputer.com/news/security/sap-fixes-maximum-severity-netweaver-command-execution-flaw/
How I Hack Websites With Just HTML Injection | by Ibtissam hammadi | Sep, 2025 | InfoSec Write-ups
https://infosecwriteups.com/how-i-hack-websites-with-just-html-injection-9ccbc87faf47?source=rss------bug_bounty-5
Adobe patches critical SessionReaper flaw in Magento eCommerce platform
https://www.bleepingcomputer.com/news/security/adobe-patches-critical-sessionreaper-flaw-in-magento-ecommerce-platform/
TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs
https://thehackernews.com/2025/09/tor-based-cryptojacking-attack-expands.html
18 Popular Code Packages Hacked, Rigged to Steal Crypto – Krebs on Security
https://krebsonsecurity.com/2025/09/18-popular-code-packages-hacked-rigged-to-steal-crypto/
SAP Patches Critical NetWeaver Vulnerabilities - SecurityWeek
https://www.securityweek.com/sap-patches-critical-netweaver-vulnerabilities/
Sean Metcalf on X: "Last week, I focused on Active Directory Admins (ADAs). https://t.co/vAXiC7q7IC This week, let's look at built-in privileged groups: * Account Operators - should be empty per Microsoft due to highly privileged access in AD. * Backup operators - should only contain backup https://t.co/WltLXFUcgt" / X
https://x.com/PyroTek3/status/1960029810669006946
MostereRAT Deployed AnyDesk/TightVNC for Covert Full Access | FortiGuard Labs
https://www.fortinet.com/blog/threat-research/mostererat-deployed-anydesk-tightvnc-for-covert-full-access
Hackers hide behind Tor in exposed Docker API breaches
https://www.bleepingcomputer.com/news/security/hackers-hide-behind-tor-in-exposed-docker-api-breaches/
Windows 11 KB5065426 & KB5065431 cumulative updates released
https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5065426-and-kb5065431-cumulative-updates-released/
Salt Typhoon and UNC4841: Silent Push Discovers New Domains; Urges Defenders to Check Telemetry and Log Data - Silent Push
https://www.silentpush.com/blog/salt-typhoon-2025/
Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks
https://thehackernews.com/2025/09/axios-abuse-and-salty-2fa-kits-fuel.html