10/10

7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code Remotely

https://cybersecuritynews.com/7-zip-vulnerabilities/
7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code Remotely

Velociraptor leveraged in ransomware attacks

https://blog.talosintelligence.com/velociraptor-leveraged-in-ransomware-attacks/
Velociraptor leveraged in ransomware attacks

FBI takes down BreachForums portal used for Salesforce extortion

https://www.bleepingcomputer.com/news/security/fbi-takes-down-breachforums-portal-used-for-salesforce-extortion/
FBI takes down BreachForums portal used for Salesforce extortion

セミナー | MNCTF - マクニカ

https://go.macnica.co.jp/Entry-MNC-PE-Sec-20251211-MNCTF2025.html
セミナー | MNCTF - マクニカ

MalwareBazaar | SHA256 f9040a4e04ed7681ad1fbcd20d52f0b4393652ad64ba0006cb1b3968f0d5e851 (RemcosRAT)

https://bazaar.abuse.ch/sample/f9040a4e04ed7681ad1fbcd20d52f0b4393652ad64ba0006cb1b3968f0d5e851/
MalwareBazaar | SHA256 f9040a4e04ed7681ad1fbcd20d52f0b4393652ad64ba0006cb1b3968f0d5e851 (RemcosRAT)

From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability

https://thehackernews.com/2025/10/from-lfi-to-rce-active-exploitation.html
From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox Vulnerability

Log in to X / X

https://x.com/iok
Log in to X / X

[HackerNotes Ep. 143]: New Cohost + Client-Side Gadgets, LHE Meta — Instant Global Admin in Entra!

https://blog.criticalthinkingpodcast.io/p/hackernotes-ep-143-new-cohost-client-side-gadgets-lhe-meta-instant-global-admin-in-entra
[HackerNotes Ep. 143]: New Cohost + Client-Side Gadgets, LHE Meta — Instant Global Admin in Entra!

Copilot on Windows can now connect to email, create Office docs

https://www.bleepingcomputer.com/news/microsoft/copilot-on-windows-can-now-connect-to-email-create-office-docs/
Copilot on Windows can now connect to email, create Office docs

Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers

https://thehackernews.com/2025/10/stealit-malware-abuses-nodejs-single.html
Stealit Malware Abuses Node.js Single Executable Feature via Game and VPN Installers

Juniper Networks Patches Critical Junos Space Vulnerabilities - SecurityWeek

https://www.securityweek.com/juniper-networks-patches-critical-junos-space-vulnerabilities/
Juniper Networks Patches Critical Junos Space Vulnerabilities - SecurityWeek