Aggregator
FTC alleges messaging app violated child privacy law, duped users into subscriptions
CISA says it will fill the gap as federal funding for MS-ISAC dries up
The cooperative agreement between the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the not-for-profit Center for Internet Security is ending today, the agency has announced on Monday, and CISA will take it upon itself to offer support to US state, local, tribal, and territorial (SLTT) governments by way of grants, tools, and cybersecurity expertise. MS-ISAC funding cut leaves core services intact but trims key support The Center for Internet Security (CIS) runs the Multi-State … More →
The post CISA says it will fill the gap as federal funding for MS-ISAC dries up appeared first on Help Net Security.
Chinese hackers exploiting VMware zero-day since October 2024
Docker APIs Targeted – FireTail Blog
Sep 30, 2025 - Lina Romero - In 2025’s fast-moving cyber landscape, attacks are everywhere and AI and APIs are the biggest targets. We’ve spoken before about hackers exploiting Docker Swarm to launch cryptomining attacks, but now attackers are using Docker APIs for other malicious purposes. It started this June. Trend Micro noticed abnormal activity in Docker’s APIs- attacks that started as requests to exposed APIs to retrieve a list of containers. The bad actors would then create a novel container to connect to the host root and carry out their attack on the host system. However, an encoded payload hidden in the initial request executes a shell script that sets up the Tor browser in the container and fetches a payload over the Tor network (Security Week). The attackers can then deploy a malicious shell script and modify the SSH configuration of the host system. At this point, the attackers deploy a binary acting as a dropper for an XMRig cryptocurrency miner and “all necessary execution stops internally, allowing it to deploy the miner without requiring the download of any external components” in order to avoid detection (Trend Micro). However, this was only the beginning- on September 8th of this year, hackers launched similar attacks, but with a twist: after carrying out the same initial steps, they proceeded to block external access to the Docker API by writing a command to the cron tab file to create a cron job that blocks its access every minute. From there, threat actors can perform mass scans for other open ports, and propagate malware in new containers using the exposed APIs. Researchers from Trend Micro determined that the attackers used AI in the creation of these tools. What is especially troubling is that these attacks are growing more advanced and may only continue to increase in volume and complexity. As AI and API attacks surge, Docker APIs are a popular target for attackers. Maintaining strong API security is the corner store of cybersecurity as a whole- after all, API security IS AI security. To learn more about securing AI and APIs, check out FireTail’s all-in-one approach. Set up a demo or start a free trial today.
The post Docker APIs Targeted – FireTail Blog appeared first on Security Boulevard.
CVE-2022-34266 | LibTIFF 4.0.3-35.amzn2.0.1 on Amazon Linux TIFF File tif_dirread.c TIFFFetchStripThing uninitialized resource (ALAS-2022-1814)
CVE-2024-32964 | lobehub lobe-chat up to 0.150.5 /api/proxy server-side request forgery
CVE-2025-8276 | Patika Global HumanSuite up to 53.20.x injection
CVE-2025-10217 | Hitachi Energy Asset Suite up to 9.7 neutralization for logs (EUVD-2025-31726)
CVE-2025-10585 | Google Chrome up to 140.0.7339.127 V8 type confusion (EUVD-2025-31006 / Nessus ID 265355)
CISA Warns of Linux Sudo Vulnerability Actively Exploited in Attacks
CISA has issued an urgent advisory regarding a critical vulnerability in the Linux and Unix sudo utility CVE-2025-32463 that is currently being exploited in the wild. This flaw allows local adversaries to bypass access controls and execute arbitrary commands as the root user, even without explicit sudoers privileges. Sudo Chroot Bypass (CVE-2025-32463) Identified as “Inclusion […]
The post CISA Warns of Linux Sudo Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.
Cyber Incident Impacts DeKalb County Government Computer System
CVE-2025-10859 | Mozilla Firefox up to 143.0 on iOS Cookie information disclosure (EUVD-2025-31731)
CVE-2025-8532 | Bimser Solution Software Trade eBA Document and Workflow Management System 6.7.164/6.7.165 authorization (EUVD-2025-30288)
Google Gemini Vulnerabilities Let Attackers Exfiltrate User’s Saved Data and Location
Three new vulnerabilities in Google’s Gemini AI assistant suite could have allowed attackers to exfiltrate users’ saved information and location data. The vulnerabilities uncovered by Tenable, dubbed the “Gemini Trifecta,” highlight how AI systems can be turned into attack vehicles, not just targets. The research exposed significant privacy risks across different components of the Gemini […]
The post Google Gemini Vulnerabilities Let Attackers Exfiltrate User’s Saved Data and Location appeared first on Cyber Security News.