The Kimwolf Botnet is Stalking Your Local Network – Krebs on Security

Autre question : quels sont vos sources d'informations préférées pour la #cybersécurité ? Que je pourrais donc rajouter à mon futur flux

#cybersecurity #CybersecurityNews #Veille

En adición a esto por ejemplo

🚨 87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw - PoC Exploit Released

Source: cybersecuritynews.com/mongobleed/

A high-severity vulnerability in MongoDB Server that allows unauthenticated remote attackers to siphon sensitive data from database memory.

Dubbed "MongoBleed" due to its automated similarities to the infamous Heartbleed bug, the flaw tracks as CVE-2025-14847 and carries a CVSS score of 7.5.

The vulnerability resides in the MongoDB Server’s zlib message decompression implementation. According to the disclosure released on December 19, 2025, the flaw is an uninitialized memory disclosure issue.

#cybersecuritynews #vulnerabilitynews https://cybersecuritynews.com/mongobleed/
(https://t.me/experienciainterdimensional/9916)

Parrot 7 Beta Images are here 💥

Parrot is now based on Debian 13 (Trixie), with KDE as the new default desktop. Please test drive it and let us know what breaks (nicely). 🦜

👉 Click the link down below and read the full Release Notes on our website, then grab the beta and have fun ⤵️

http://parrotsec.org/blog/2025-12-09-parrot-7.0-beta-release-notes

#ParrotSec #ParrotOS #linux #linuxdistro #cybersec #cybersecurity #cybersecuritynews #hacker #hackers #PenTest #pentesting #debian

Officials argue the policy is necessary to protect citizens due to a sharp increase in online fraud and cybercrime.

#cybersecurity #cybersecuritynews

CISA has added CVE-2021-26829
(OpenPLC/ScadaBR XSS) to the Known Exploited Vulnerabilities Catalog.

XSS vulnerabilities in ICS/SCADA environments remain a dependable avenue for attackers, and CISA is urging organizations - not just federal - to prioritize remediation.

How does your team track and respond to KEV updates?

Source: https://www.cisa.gov/news-events/alerts/2025/11/28/cisa-adds-one-known-exploited-vulnerability-catalog

🔔 Follow TechNadu for balanced, non-sensational cybersecurity coverage.

#infosec #CISA #KEV #ICS #SCADA #OpenPLC #OTSecurity #XSS #vulnerabilitymanagement #riskmanagement #cybersecuritynews #threatintel

A threat actor claims to have leaked 2.3TB of data from Almaviva, the IT services provider for FS Italiane Group.

Experts say the structure and recency of the files look consistent with modern ransomware/data broker operations.

Almaviva confirmed a cyber incident, isolated affected systems, and notified authorities. Core services remain operational.

💬 Thoughts on the broader supply-chain implications?
👍 Follow TechNadu for more threat intelligence coverage.

#Infosec #ThreatIntel #DataBreach #Italy #FSItaliane #Almaviva #RansomwareOps #CriticalInfrastructure #CyberSecurityNews

OFAC + U.K. + Australia sanction Media Land LLC for providing bulletproof hosting to LockBit, BlackSuit, Play, Evil Corp & Black Basta.
Volosovik (Yalishanda), Zatolokin & Pankova named, along with ML Cloud, MLT & DC Kirishi.

Full report: https://www.technadu.com/russian-hosting-provider-media-land-sanctioned-for-supporting-lockbit-blacksuit-and-play-ransomware/613982/

Follow @technadu for continuous threat intel.
#CybersecurityNews #Ransomware #LockBit #ThreatIntel

CISA has issued a 7-day patch directive for actively exploited Fortinet FortiWeb vulnerability CVE-2025-64446 (rated 9.1 critical).
Researchers have confirmed exploitation, and reports indicate a zero-day version was being sold on underground forums. Hundreds of vulnerable appliances are visible online.
Is this an example of a necessary emergency directive - or a sign that vendors need more transparent patch timelines?

💬 Share your thoughts.
👍 Follow us for more detailed, unbiased cybersecurity coverage.

#Infosec #CISA #Fortinet #CVE202564446 #ThreatHunting #VulnerabilityManagement #CybersecurityNews

Drilling Down on Uncle Sam’s Proposed TP-Link Ban – Krebs on Security