Cybersecurity
General cybersecurity news and analysis

KernelSU v057 Critical Flaw — Must-Have Patch
A critical authentication bug in KernelSU v0.5.7 lets a malicious app impersonate the manager and gain full root control, putting millions of rooted Android devices at risk. If you use KernelSU or custom-root tools, update immediately, verify manager signatures, and avoid untrusted sideloads.

malvertising campaign: Exclusive Dangerous PS1Bot Threat
What if the ads you trust were actually a backdoor? A new malvertising campaign is quietly using compromised ad networks to deploy PS1Bot — a modular PowerShell malware that runs in memory, evades traditional defenses, and can turn ordinary browsers into footholds for wider attacks.

Russian-linked cyber actors: Stunning Critical Threat
Allegations tying Moscow-linked hackers to a months-long breach of U.S. federal court files and a hacking attempt that manipulated a Norwegian dam’s controls have exposed just how fragile our courts and critical infrastructure can be. The incidents raise urgent questions about who’s really protecting the systems we rely on—and what must be fixed now.

law enforcement email accounts: Shocking Risk Exposed
For as little as $40, criminals can buy real law-enforcement and government email accounts on the dark web — and that cheap access lets them impersonate officials, steal data, and trick people into payments. Strengthening authentication, email protections, and simple verification habits is essential to protect trust and public safety.

website after cyberattack: Risky Stunning Supply Outage
What do you do when the system that tells retailers what’s on the shelf goes dark? Stock in the Channel pulled its site after a cyberattack — saying customer data appear safe but providing no forensic report or timeline — leaving partners scrambling with manual checks, delayed orders and shaken trust.

FortiSIEM vulnerability: Critical, Risky Exploit Emerges
A critical FortiSIEM flaw with exploit code now circulating turns your SIEM into a prime target. Patch, tighten access, and hunt for signs of compromise immediately to protect visibility and contain risk.

live facial recognition Stunning but Risky Expansion
The UK’s decision to add 10 live facial‑recognition police vans has reignited a heated debate. Supporters say they’ll help catch suspects and protect public spaces, while campaigners warn they risk widening surveillance, entrenching bias and eroding public trust without stronger legal safeguards.

N‑able N‑central Critical Risk: Urgent Must-Fix Flaws
Heads-up: CISA has added two N‑able N‑central flaws to its KEV catalog after evidence of active exploitation, so MSPs and customers should urgently locate, patch or isolate affected RMM instances and tighten admin controls. Because a compromised RMM can give attackers broad access, demand proof of remediation and enforce strong segmentation, MFA, and monitoring now.

FortiSIEM vulnerability: Critical, Urgent Must-Fix
A critical FortiSIEM vulnerability now has working exploit code circulating, and defenders are seeing a sharp spike in automated scanning and brute‑force attacks against exposed devices. If you manage FortiSIEM, patch or apply Fortinet’s mitigations immediately, isolate internet‑facing appliances, and rotate credentials to stay ahead of opportunistic attackers.

Artificial intelligence: Stunning Defense, Risky Threat
AI is turning cybersecurity into a high-speed arms race—defenders use machine learning to triage alerts and automate responses while attackers leverage generative models to scale convincing attacks. Check out Prompt||GTFO’s demos to see how practitioners are testing AI’s promise and peril in real-world defenses and offensives.

Equation Editor: Must-Have Fix for Risky Exploit
Eight years after Microsoft patched the Equation Editor, attackers are still exploiting CVE-2017-11882 to drop keyloggers and steal credentials from unpatched Office installs. If you haven’t audited Office versions or enforced updates and controls like EDR and MFA, now’s the time—old vulnerabilities keep paying off for attackers.

Erlang/OTP SSH daemon Critical: Urgent Must-Have Fix
A critical unauthenticated RCE in the Erlang/OTP SSH daemon lets attackers run commands on vulnerable systems, putting telecom, messaging and network appliances at immediate risk. Apply vendor patches, isolate exposed SSH services, and scan for signs of compromise right away.

helmet-mounted displays: Exclusive, Best Tactical Edge
Helmet‑mounted displays are no longer niche pilot toys but powerful force multipliers that merge sensors, targeting, and comms into a pilot’s line of sight—while also creating new vulnerabilities to jamming, spoofing, and human error. Keeping the tactical edge means hardening systems, training for degraded conditions, and designing HMDs pilots can trust.

FortiSIEM CVE-2025-25256 Exclusive Critical Alert
Heads up: FortiSIEM CVE-2025-25256 is a critical 9.8-rated OS command injection with exploit code already in the wild, meaning exposed or unpatched instances can let attackers run commands, pivot, and erase evidence. Patch immediately, isolate affected systems, and hunt for indicators of compromise to avoid a catastrophic breach.

police facial recognition: Must-Have or Risky Deployment
Ten mobile facial‑recognition vans promise quicker suspect ID and faster missing‑person responses, but accuracy gaps, bias concerns and fuzzy legal safeguards mean we must insist on independent audits, clear transparency and enforceable limits before these systems become routine.

high severity protocol vulnerabilities: Must-Have Patch
Matrix.org disclosed two high-severity protocol flaws that require breaking changes across servers and clients. Federated homeserver operators must urgently coordinate upgrades to avoid exploitation, while single-instance users can roll updates more deliberately.

Kerberos zero-day: Critical Emergency Fix You Must Apply
Microsoft’s August 2025 Patch Tuesday includes a publicly known Kerberos zero‑day—apply the update and prioritize domain controllers now to stop attackers from forging tickets or escalating privileges. Also tighten MFA and monitoring while patches roll out to reduce your exposure.

August Patch Tuesday: Risky 107-CVE Alert — Must-Act
Microsoft’s August Patch Tuesday fixes 107 vulnerabilities — including an actively exploited zero-day — so IT teams and everyday users should prioritize updates and mitigations now to avoid leaving easy openings for attackers. Take a breath, then triage: inventory affected systems, test critical patches, and deploy promptly to stay ahead of opportunistic and persistent threats.

Charon ransomware: Stunningly Devastating Threat
A new ransomware called Charon is using APT-style stealth—DLL side‑loading and process injection—to strike Middle East public-sector and aviation systems, forcing a rethink of how we protect critical services. Assume attackers are getting smarter: prioritize EDR, MFA, network segmentation and practiced response plans to keep cities and flights safe.

Patch Tuesday: Must-Have Critical Guide
Don’t wait—August’s Patch Tuesday shipped 100+ fixes, including over a dozen critical remote-code-execution bugs. Prioritize internet-facing and mission-critical systems now, apply mitigations where you can’t patch, and sharpen detection to avoid turning routine updates into an incident.

cyber incident: Exclusive Risky Outage Exposes PA Flaws
A cyber incident knocked Pennsylvania’s Attorney General office offline for a second day, leaving residents, victims and partner agencies scrambling for answers as websites, phones and email went dark. With external cybersecurity teams on the case but few details released, the outage raises urgent questions about preparedness, potential data exposure, and how quickly critical services can be restored.

data extortion: Stunning, Dangerous Cloud Threat
ShinyHunters and Scattered Spider have shifted from stealing and selling data to brazenly extorting Salesforce customers, combining mass-data access with hands-on intrusion to squeeze ransoms out of enterprises. If this hybrid tactic spreads to financial and tech-service providers, it could seriously amplify risk across industries—time to lock down identities, APIs, and incident playbooks.

storytelling jailbreak: Stunning Risky Threat Exposed
A new storytelling jailbreak shows how crafty prompts can hide dangerous requests inside fiction to coax GPT-5 past its safeguards. That loophole exposes real risks for safety, trust, and policy — and pushes developers to build smarter, context-aware defenses.

BlackSuit ransomware Stunning Win: $1M Recovered
U.S. authorities seized servers, domains and about $1M in crypto tied to the Russia-linked BlackSuit gang, delivering a major disruption to its ransomware-as-a-service scheme. Still, experts caution this is a tactical win—not a knockout—as criminals quickly regroup and adapt.