GLOBAL SITUATIONMONITORING
482 published briefsUTCMon, Apr 6 08:15:39
Intelligence Domain

Cyber News & Updates

Breaking news, security alerts, and trending stories from across the cybersecurity landscape.

234 intelligence briefs← Intelligence Hub
  • OWASP Updates Top 10 Risks, Highlights Supply Chain and Systemic Flaws

    OWASP Updates Top 10 Risks, Highlights Supply Chain and Systemic Flaws

    OWASP has updated its Top 10 list of web application security risks, highlighting supply chain and systemic design weaknesses, marking its first major revision since 2021.

    1–2 minutes
  • Critical XSS Flaw Found in GitHub Enterprise Server: Immediate Update Recommended

    Critical XSS Flaw Found in GitHub Enterprise Server: Immediate Update Recommended

    A critical DOM-based Cross-Site Scripting (XSS) vulnerability, identified as CVE-2025-11892, has been uncovered in GitHub Enterprise Server, posing a significant risk of privilege escalation and unauthorized workflow triggers. Immediate update to affected systems is highly recommended to mitigate this high-severity flaw.

    1–2 minutes
  • Authenticated SQL Injection Exposes TorrentPier User Data

    Authenticated SQL Injection Exposes TorrentPier User Data

    An authenticated SQL injection vulnerability, tracked as CVE-2025-64519, has been discovered in TorrentPier, the popular open-source BitTorrent tracker engine. The flaw allows malicious actors with moderator privileges to execute arbitrary SQL queries, posing a significant risk to the integrity and confidentiality of database information.

    1–2 minutes
  • Critical Flaw in Soft Serve Git Server Exposes Internal Networks

    Critical Flaw in Soft Serve Git Server Exposes Internal Networks

    A critical Server-Side Request Forgery (SSRF) vulnerability, CVE-2025-64522, in Soft Serve Git server allows attackers to access internal networks. Organizations are urged to update to version 0.11.1 immediately to prevent data breaches and system compromise.

    1–2 minutes
  • Military Experts Raise Alarms Over AI Chatbot Vulnerabilities: A New Front in Cyberwarfare

    Military Experts Raise Alarms Over AI Chatbot Vulnerabilities: A New Front in Cyberwarfare

    Military experts warn about critical security flaws in AI chatbots, specifically prompt injection attacks, which can be exploited by hostile foreign powers to compromise sensitive information and unleash chaos. The article highlights real-world vulnerabilities in popular LLMs like Google Gemini, OpenAI’s ChatGPT, and Microsoft Copilot, and the potential for adversaries to pilfer critical files, warp…

    2–3 minutes
  • Critical Flaw in Combodo iTop Exposes Systems to Remote Code Execution

    Critical Flaw in Combodo iTop Exposes Systems to Remote Code Execution

    A critical security flaw in Combodo iTop, a widely adopted IT service management platform, could allow attackers to achieve remote code execution (RCE) and gain full control over affected systems.

    1–2 minutes
  • Mandiant Warns of Active Exploitation of Critical Triofox Flaw Allowing Remote Access

    Mandiant Warns of Active Exploitation of Critical Triofox Flaw Allowing Remote Access

    Mandiant warns of active exploitation of a critical Triofox flaw (CVE-2025-12480) allowing remote code execution, with threat actors UNC6485 bypassing authentication to compromise systems.

    1–2 minutes
  • EU Considers Banning Huawei Telecom Equipment for Member States

    EU Considers Banning Huawei Telecom Equipment for Member States

    The European Union is contemplating a ban on Huawei telecommunications equipment for member states, driven by escalating cybersecurity and national security concerns. This move reflects a growing international apprehension regarding the integration of specific foreign technologies into global telecom networks and aims to fortify critical infrastructure against potential vulnerabilities.

    2–3 minutes
  • Swiss NCSC Warns of iPhone Phishing Scams After Device Loss

    Swiss NCSC Warns of iPhone Phishing Scams After Device Loss

    The Swiss National Cyber Security Centre (NCSC) has warned iPhone users about a sophisticated phishing campaign that targets owners of lost devices. Scammers send convincing messages to steal Apple ID credentials, enabling them to bypass critical security features like Activation Lock. Users are advised against clicking unsolicited links and to activate Lost Mode immediately for…

    2–3 minutes
  • GlassWorm Malware Resurfaces, Infecting VS Code Extensions with Stealthy Unicode Attack

    GlassWorm Malware Resurfaces, Infecting VS Code Extensions with Stealthy Unicode Attack

    The GlassWorm malware campaign has re-emerged, targeting the Visual Studio Code (VS Code) ecosystem with a new set of malicious extensions, signaling a persistent threat to developers. This sophisticated, self-propagating worm aims to compromise credentials and cryptocurrency assets using invisible Unicode characters to embed malicious code.

    1–2 minutes