CISA Flags Two Actively Exploited N-central Vulnerabilities: CVE-2025-8875 and CVE-2025-8876

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in N-able’s N-central software to its Known Exploited Vulnerabilities (KEV) Catalog. This listing confirms that the flaws are being actively targeted by attackers and require urgent attention from organizations using the platform. N-able N-central is a popular remote monitoring and management (RMM) tool … Continued

Charon Ransomware Targets Middle East with Nation-State Level Tactics

A new ransomware strain called Charon has been making headlines after targeting organizations in the Middle East. The main victims are from the public sector and aviation industry. What makes this attack more dangerous than usual is that the hackers are using techniques normally seen in nation-state cyber espionage groups. This makes the ransomware much … Continued

Manpower Data Breach Exposes Nearly 145,000 Individuals’ Personal Information

Manpower, the international staffing and workforce solutions company, has announced a data breach that may have affected 144,189 people. The company sent formal notifications after completing its investigation, confirming that sensitive personal information might have been accessed by unauthorized parties. The breach involved Manpower and associated staffing operations. It started when staff in Lansing, Michigan, … Continued

Connex Credit Union Data Breach Exposes 172,000 Members’ Personal Information

Connex Credit Union has confirmed that a major cyberattack exposed the personal information of approximately 172,000 individuals. The affected group includes current and former members, along with others connected to the credit union. The organization has called this one of the most serious security incidents in its history. The breach occurred in early June 2025 … Continued

Win-DDoS Flaws Let Attackers Weaponize Public Domain Controllers

Security researchers from SafeBreach Labs have discovered a new set of denial-of-service (DoS) vulnerabilities in Windows, known as Win-DoS and Win-DDoS. These flaws allow attackers to abuse publicly accessible Windows domain controllers to generate massive amounts of traffic, turning them into a large-scale distributed denial-of-service (DDoS) botnet without the need for malware. The team identified … Continued

Columbia University Data Breach Exposes 870,000 Records

Columbia University has confirmed a major data breach that impacted nearly 870,000 people. Those affected include current and former students, job applicants, staff members, and even some of their family members. The incident is one of the largest security breaches reported by a U.S. university in recent years. The first signs of trouble appeared on … Continued

Inside the Minds of Hackers Who Defend, Not Destroy

In a world where cyber threats evolve by the second, heroes wear hoodies not capes. At Black Hat USA 2025, ethical hackers proved they’re the digital world’s frontline defenders.From AI-powered red teams to real breach simulations, they’re rewriting how we stay safe.This isn’t hacking for chaos, it’s hacking for a cause.    What Is Ethical … Continued

Deep Dive into Ransomware Evolution: What 2025 Has Uncovered So Far

Introduction Ransomware has undergone a dramatic transformation from early rudimentary encryption attacks to today’s high-stakes, multi-vector extortions. As Black Hat USA 2025 unfolds, it’s more vital than ever to understand where ransomware stands heading into 2025 and what defenders must prepare for. 1. The Rise and Collapse of RaaS The Ransomware-as-a-Service (RaaS) model enabled prolific groups … Continued

Top 5 Demos from Black Hat USA 2025 That Could Actually Make a Difference

Black Hat USA 2025 delivered big this year  but only a handful of demos stood out as real game-changers for the cybersecurity world. Here are five standout demos that left us thinking, “this could shift cybersecurity as we know it”  Intel CPU Data Leak via Microarchitectural Race Condition  Researchers demonstrated how attackers can bypass Spectre-era … Continued

Newsletter line