Bipartisan Senators Renew Push for NIST Standards Among Federal Contractors

A bipartisan group of lawmakers is making a renewed effort to bolster cybersecurity requirements for federal government contractors. Senators Mark Warner (D-Va.) and James Lankford (R-Okla.) have reintroduced the Federal Contractor Cybersecurity Vulnerability Reduction Act, which would require contractors to adhere to guidelines set by the National Institute of Standards and Technology (NIST) for vulnerability … Continued

AI Models Are Learning to Defy Commands

Just last week, the fictional Ethan Hunt outwitted a rogue AI to save world in Mission: Impossible. But in real life, a new set of experiments from Palisade Research is raising serious concerns about how some AI systems are beginning to act in ways that directly defy human instructions. Palisade Research recently made waves with … Continued

High Severity DoS Vulnerability CVE-2025-47947 Identified in ModSecurity2

A newly disclosed vulnerability in ModSecurity2 firewall, tracked as CVE-2025-47947, has raised concerns over potential Denial of Service (DoS) attacks under specific, rare conditions. The issue was officially published on May 21, 2025, and is rated 7.5 (High) on the CVSS scale. The vulnerability was initially reported privately by a customer in March 2025. After … Continued

PoC Released for Fortinet Vulnerability CVE-2025-3275

FortinGuard Labs issued an advisory for CVE-2025-32756, a critical vulnerability affecting multiple Fortinet products. Just a day later, CVE-2025-32756 was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. Today researchers at Horizon3.ai released a proof-of-concept (PoC) demonstrating exploitation of the vulnerability. Their analysis focused on comparing the patched and unpatched versions of FortiMail. CVE-2025-32756 According to … Continued

Cisco Discloses Critical RADIUS Vulnerability CVE-2025-20152 in Identity Services Engine

Cisco has issued a high-severity security advisory for a vulnerability affecting its Identity Services Engine (ISE), warning that the flaw could allow unauthenticated remote attackers to trigger a denial of service (DoS) condition on affected devices. CVE-2025-20152 The vulnerability, tracked as CVE-2025-20152, stems from improper handling of certain RADIUS authentication requests within Cisco ISE, a widely … Continued

New backdoor malware exploits PyBitmessage P2P protocol

The AhnLab Security Intelligence Center (ASEC) has discovered a new backdoor malware strain bundled with a Monero cryptocurrency miner. Unlike other malware that uses HTTP or IP-based communication, this malware uses PyBitmessage library to communicate over a peer-to-peer (P2P) network, encrypting its traffic between endpoints. What is PyBitmessage? Bitmessage is a protocol designed for anonymity … Continued

Lexmark Issues Security Advisory for Critical Vulnerability

Lexmark, a global provider of printing and imaging products, has issued a critical security advisory warning of a severe vulnerability affecting the embedded web servers in multiple Lexmark devices.  The vulnerability is a combination of Path Traversal and Concurrent Execution flaws, which could allow attackers to execute arbitrary code remote execution. Vulnerability Details The vulnerability, … Continued

VanHelsing Ransomware Source Code Leaked

Yesterday morning, out of the blue, the notorious VanHelsing ransomware source code was suddenly listed for sale on the RAMP cybercrime forum. This unexpected leak has quickly caught the attention of cybersecurity researchers and threat intelligence analysts, raising concerns about the potential misuse of the code and what it could mean for the organizations. Initial … Continued

Critical CVE-2025-4322 vulnerability in Motors Theme Allows Admin Takeover

A severe security vulnerability has been identified in the premium WordPress theme Motors, potentially allowing unauthenticated attackers to hijack administrator accounts and seize full control of affected websites. CVE-2025-4322 The vulnerability, tracked as CVE-2025-4322, was publicly disclosed today by security firm Wordfence and has been assigned a CVSS severity rating of 9.8, classifying it as … Continued

Newsletter line