Cox has confirmed a significant data breach involving Oracle EBS, with over 1.6 terabytes of data reportedly stolen and made public by cybercriminals. This incident highlights the severity of cybersecurity threats faced by organizations and the potential exposure of sensitive information for numerous alleged victims.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
The Hacker News
The ShadowPad malware is exploiting a recently patched vulnerability in Microsoft Windows Server Update Services (WSUS), identified as CVE-2025-59287, allowing attackers to gain full system access. This exploitation highlights the critical need for organizations to promptly apply security updates to vulnerable systems to prevent unauthorized access.
The Cybersecurity Outlook 2026 event highlights the evolving landscape of cybersecurity threats and the increasing severity of attacks. As organizations prepare for the future, it is crucial to understand the implications of these threats on security strategies and technologies.
darkreading
The article discusses the importance of online events in the context of cybersecurity awareness and education. It emphasizes the need for organizations to stay informed about current threats and to engage in continuous learning to mitigate risks. The core issue revolves around the evolving nature of cyber threats and the necessity for proactive measures.
APT31, a China-linked advanced persistent threat group, has been conducting stealthy cyberattacks on the Russian IT sector from 2024 to 2025, focusing on contractors and integrators for government agencies. These attacks have remained undetected for extended periods, raising concerns about the security of the targeted organizations.
The Hacker News
The article discusses a new command-and-control platform, Matrix Push C2, which utilizes browser notifications to execute phishing attacks by distributing malicious links. This fileless framework targets victims across different operating systems using push notifications, fake alerts, and link redirects.
The Hacker News
CISA has identified a critical security vulnerability in Oracle Identity Manager, classified as CVE-2025-61757, which is actively being exploited. This vulnerability involves missing authentication for a critical function, posing significant security risks.
Salesforce customers have been targeted again by threat actors from the ShinyHunters group, who exploited a third-party application to access sensitive Salesforce data. This repeated attack highlights the ongoing vulnerabilities associated with third-party integrations and the need for enhanced security measures.
Toto Wolff, the Team Principal of Mercedes F1, has sold a 15% stake in the team to George Kurtz, the CEO of CrowdStrike. This transaction highlights the ongoing partnership between CrowdStrike and the Mercedes F1 team, which began in 2019, indicating a strengthening of ties between cybersecurity and motorsport.
The LINE messaging app has significant security vulnerabilities due to its leaky custom protocol, which can lead to message replays, impersonation attacks, and exposure of sensitive information. These issues pose serious risks for users in Asia, potentially aiding geopolitical adversaries in cyber espionage activities.
The article highlights a recent outage experienced by Cloudflare, a leading service provider, which serves as a critical reminder of the vulnerabilities inherent in even the most advanced digital systems. Dr. David Utzke emphasizes that this incident could have significant implications for enterprises relying on such services, potentially disrupting the global digital economy.
The article discusses a new security framework designed to counteract evolving tactics used by attackers who can infiltrate enterprises quietly by exploiting their own policies. This shift in tactics highlights the need for organizations to adapt their security measures to prevent such silent breaches.
The Hacker News
Grafana has issued security updates to fix a critical vulnerability, CVE-2025-41115, with a CVSS score of 10.0. This flaw in the SCIM component can lead to privilege escalation and user impersonation under specific configurations.
The article highlights several significant cybersecurity incidents, including a data breach affecting 120,000 individuals and a surge in scanning activities by Palo Alto Networks. Additionally, it mentions ongoing legal battles involving WhatsApp and NSO, as well as the emergence of AI-related security threats such as second-order prompt injection attacks.
The article discusses how automation is transforming entry-level roles in cybersecurity, leading to concerns about the ability of upcoming security professionals to acquire essential hands-on experience. This shift could significantly impact the future of the cybersecurity workforce, raising questions about the effectiveness of training and skill development in a rapidly evolving field.