Vulnerabilities
10 storiesRisky Business #771 -- Palo Alto's firewall 0days are very, very stupid
Critical zero-day vulnerabilities in Palo Alto firewall management interfaces expose enterprise perimeters to immediate compromise through basic web application flaws.
Risky Business9/10Firewall Bug Under Active Attack Triggers CISA Warning
CISA's emergency warning for Palo Alto Networks PAN-OS reflects European perimeter security crisis requiring immediate enterprise firewall audit protocols.
Threatpost9/10Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088
Critical WinRAR vulnerability CVE-2025-8088 sees widespread exploitation by diverse threat actors months after July 2025 patch availability, indicating persistent patching gaps in enterprise environments.
Mandiant BlogCVE-2025-80888.89/10Version 1.0: SonicWall SonicOS - Kritische Schwachstelle erlaubt unauthentifizierten Zugriff auf sensible Ressourcen
Critical SonicWall unauthenticated access vulnerability exposes network perimeter controls protecting German SME infrastructure from unauthorized resource compromise.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Version 1.1: Check Point Security Gateways - Abfluss von Zugangsdaten möglich
Check Point credential exposure vulnerability threatens network segmentation integrity across German enterprise perimeter defenses, requiring urgent security gateway assessment.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Version 1.0: Cisco ASA: Aktiv ausgenutzte Schwachstellen geschlossen
Active exploitation of Cisco ASA vulnerabilities requires immediate patching priority for German organizations using these perimeter security appliances in critical network positions.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Dirty Frag: Linux kernel hit by second major security flaw in two weeks
Second critical Linux kernel flaw within two weeks enables unprivileged users to gain root access, amplifying enterprise server compromise risks across European data centers.
The Record9/10[UPDATE] [hoch] Red Hat OpenShift: Mehrere Schwachstellen
Red Hat OpenShift container orchestration platform faces multiple high-severity vulnerabilities enabling privilege escalation and arbitrary code execution in Kubernetes environments.
CERT-Bund (BSI)9/10Finding and Exploiting Citrix NetScaler Buffer Overflow (CVE-2023-3519) (Part 3)
Detailed exploitation methodology for Citrix buffer overflow enables proactive threat hunting and incident response preparation for affected infrastructure.
AssetnoteCVE-2023-35199.89/10Copy.Fail Linux Vulnerability
Copy.Fail's kernel-level privilege escalation bypasses container isolation, requiring emergency patching across European cloud and edge computing infrastructure.
Schneier on Security9/10
Research
7 storiesTop 10 web hacking techniques of 2024
Annual compilation highlights most impactful web security research trends, providing strategic intelligence for enterprise security teams planning 2025 defensive priorities.
PortSwigger Research10/10A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
Zero-click Pixel 9 exploit chain exploits AI-powered message features, expanding mobile attack surface through media processing.
Project Zero9/10[tl;dr sec] #312 - The Industrialization of Exploit Generation, macOS EDR Evasion, Hacking the AWS Console
AI-driven exploit generation reaches industrial scale, fundamentally shifting enterprise vulnerability management from reactive patching to predictive threat modeling.
tl;dr sec9/10From Controlled to the Wild: Evaluation of Pentesting Agents for the Real-World
Academic benchmarks for AI pentesting poorly predict real-world effectiveness, suggesting enterprises may misjudge automated attack tool capabilities.
arXiv Crypto & Security9/10You Have Been LaTeXpOsEd: A Systematic Analysis of Information Leakage in Preprint Archives Using Large Language Models
LLM analysis of arXiv LaTeX source reveals systematic information leakage patterns beyond published PDFs, exposing unintended data disclosure in academic publishing.
arXiv Crypto & Security9/10A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
Pixel 9 sandbox escape demonstrates kernel driver exploitation from constrained mediacodec contexts in Android.
Project Zero9/10What's on Your Mind? Exploring Privacy of Mental Health Apps
Mental health app privacy analysis exposes sensitive data handling gaps, highlighting GDPR special category obligations for European healthcare technology providers.
arXiv Crypto & Security8/10
DevSecOps
6 storiesTrust Me, Import This: Dependency Steering Attacks via Malicious Agent Skills
Supply chain attacks exploit LLM coding agents by steering dependency choices toward attacker-controlled packages through malicious skill libraries.
arXiv Crypto & Security9/10Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
TeamPCP's worm-like propagation across major package repositories signals need for immediate dependency scanning updates in European enterprise environments.
THN (Feedburner)9/10TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
TeamPCP's sequential compromise of Checkmarx tools demonstrates systematic targeting of security vendor infrastructure to poison enterprise CI/CD pipelines.
THN (Feedburner)9/10Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
Cross-ecosystem supply chain attack exploits package signing mechanisms to distribute credential-stealing malware through legitimate development workflows targeting both npm and PyPI.
BleepingComputer9/10Official CheckMarx Jenkins package compromised with infostealer
Official marketplace compromise demonstrates supply chain risks even for established security vendors, potentially exposing CI/CD pipelines to credential theft during security scans.
BleepingComputer9/10Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain
TanStack ecosystem compromised by self-propagating malware targeting npm maintainer credentials, threatening JavaScript dependency chains across European enterprises.
Dark Reading9/10
Regulatory
3 storiesEurope's GDPR privacy law is headed for red tape bonfire within 'weeks'
Hacker News (EU Regulatory)10/10Europe is scaling back GDPR and relaxing AI laws
Hacker News (EU Regulatory)10/10Position: AI Security Policy Should Target Systems, Not Models
Policy position argues EU AI Act should regulate AI systems architecture rather than individual model capabilities for effective security governance.
arXiv Crypto & Security9/10
Threat Intel
3 storiesRisky Business #793 -- Scattered Spider is hijacking MX records
Scattered Spider's DNS MX record hijacking enables rapid enterprise compromise within minutes, demanding immediate email security architecture reviews across European organizations.
Risky Business9/10Risky Business #772 -- Salt Typhoon is truly a national security disaster
Salt Typhoon's telecommunications infrastructure compromise represents the most significant national security breach since SolarWinds, affecting critical infrastructure monitoring capabilities.
Risky Business9/10When LLMs Team Up: A Coordinated Attack Framework for Automated Cyber Intrusions
Coordinated LLM agent teams can automate sophisticated cyber intrusions by distributing reconnaissance, exploitation, and persistence tasks across specialized AI models with enhanced success rates.
arXiv Crypto & Security9/10
Compliance
3 storiesUK water company allowed hackers to lurk undetected for nearly two years, regulator finds
Nearly £1M fine demonstrates how prolonged attacker dwell time amplifies regulatory penalties under UK data protection law, with 630K+ records exposed after two-year compromise window.
The Record9/10Aqua Security Achieves FedRAMP® High Authorization
FedRAMP High authorization validates cloud security platform for sensitive government workloads, setting compliance benchmark for CNAPP providers.
Aqua Security8/10GM agrees to $12.75M California settlement over sale of drivers’ data
California's enforcement action against automotive data selling sets precedent for GDPR-like penalties in sectors beyond traditional tech, signaling broader privacy enforcement expansion.
BleepingComputer8/10
AI Security
2 stories[tl;dr sec] #323 - Anthropic Mythos, Security Program Politics, Vulnerability Research is Cooked
Anthropic's new AI model demonstrates autonomous zero-day discovery and exploit development capabilities, fundamentally altering vulnerability research economics for European enterprises.
tl;dr sec9/10Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
Google's discovery of AI-generated zero-day exploits marks a paradigm shift requiring immediate reassessment of enterprise vulnerability management timelines.
THN (Feedburner)9/10