Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29804 bookmarks
Custom sorting
What's new in Burp Suite Professional: A year of innovation
What's new in Burp Suite Professional: A year of innovation
Over the past year, we’ve been hard at work making Burp Suite Professional faster, smarter, and more powerful than ever before. From the launch of Burp AI to major performance upgrades, there's never
·portswigger.net·
What's new in Burp Suite Professional: A year of innovation
Microsoft Patch Tuesday for May 2025 — Snort rules and prominent vulnerabilities
Microsoft Patch Tuesday for May 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for May of 2025 which includes 78 vulnerabilities affecting a range of products, including 11 that Microsoft marked as “critical”.   Microsoft noted five vulnerabilities that have been observed to be exploited in the wild. CVE-2025-30397 is a remote code execution vulnerability in the Microsoft Scripting Engine. There were also four elevation of privilege vulnerabilities being actively exploited, CVE-2025-32709, CVE-2025-30400, CVE-2025-32701 a
·blog.talosintelligence.com·
Microsoft Patch Tuesday for May 2025 — Snort rules and prominent vulnerabilities
News Alert: INE Security outlines top 5 training priorities emerging from RSAC 2025
News Alert: INE Security outlines top 5 training priorities emerging from RSAC 2025
Cary, NC, May 13, 2025, CyberNewswire --Fresh from a high-impact presence at RSAC 2025, where INE Security welcomed thousands of visitors to its interactive booth at San Francisco’s Moscone Center, the global cybersecurity training and certification provider is addressing some of the top cybersecurity priorities emerging from the industry-leading event. As an exhibitor that engaged
·lastwatchdog.com·
News Alert: INE Security outlines top 5 training priorities emerging from RSAC 2025
North Korea ramps up cyberspying in Ukraine to assess war risk
North Korea ramps up cyberspying in Ukraine to assess war risk
The state-backed North Korean threat group Konni (Opal Sleet, TA406) was observed targeting Ukrainian government entities in intelligence collection operations.
·bleepingcomputer.com·
North Korea ramps up cyberspying in Ukraine to assess war risk
Twilio denies breach following leak of alleged Steam 2FA codes
Twilio denies breach following leak of alleged Steam 2FA codes
Twilio has denied in a statement for BleepingComputer that it was breached after a threat actor claimed to be holding over 89 million Steam user records with one-time access codes.
·bleepingcomputer.com·
Twilio denies breach following leak of alleged Steam 2FA codes
Ivanti fixes EPMM zero-days chained in code execution attacks
Ivanti fixes EPMM zero-days chained in code execution attacks
Ivanti warned customers today to patch their Ivanti Endpoint Manager Mobile (EPMM) software against two security vulnerabilities chained in attacks to gain remote code execution.
·bleepingcomputer.com·
Ivanti fixes EPMM zero-days chained in code execution attacks
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
Today is Microsoft's May 2025 Patch Tuesday, which includes security updates for 72 flaws, including five actively exploited and two publicly disclosed zero-day vulnerabilities.
·bleepingcomputer.com·
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
Chinese-speaking hackers disrupt drone supply chains in Taiwan, researchers say
Chinese-speaking hackers disrupt drone supply chains in Taiwan, researchers say
Earth Ammit, as the group is known, launched two waves of campaigns from 2023 to 2024, affecting a range of industries including military, satellite, heavy industry, media, technology, software services and healthcare.
·therecord.media·
Chinese-speaking hackers disrupt drone supply chains in Taiwan, researchers say
Windows 11 KB5058411 and KB5058405 cumulative updates released
Windows 11 KB5058411 and KB5058405 cumulative updates released
Microsoft has released Windows 11 KB5058411 and KB5058405 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues.
·bleepingcomputer.com·
Windows 11 KB5058411 and KB5058405 cumulative updates released
Fortinet fixes critical zero-day exploited in FortiVoice attacks
Fortinet fixes critical zero-day exploited in FortiVoice attacks
Fortinet released security updates to patch a critical remote code execution vulnerability exploited as a zero-day in attacks targeting FortiVoice enterprise phone systems.
·bleepingcomputer.com·
Fortinet fixes critical zero-day exploited in FortiVoice attacks
Ivanti warns of critical Neurons for ITSM auth bypass flaw
Ivanti warns of critical Neurons for ITSM auth bypass flaw
​Ivanti has released security updates for its Neurons for ITSM IT service management solution that mitigate a critical authentication bypass vulnerability.
·bleepingcomputer.com·
Ivanti warns of critical Neurons for ITSM auth bypass flaw
New Intel CPU flaws leak sensitive data from privileged memory
New Intel CPU flaws leak sensitive data from privileged memory
A new "Branch Privilege Injection" flaw in all modern Intel CPUs allows attackers to leak sensitive data from memory regions allocated to privileged software like the operating system kernel.
·bleepingcomputer.com·
New Intel CPU flaws leak sensitive data from privileged memory