⚡ Weekly Recap: Zero-Day Exploits, Insider Threats, APT Targeting, Botnets and More

This cybersecurity update covers recent threats, vulnerabilities, and incidents targeting organizations worldwide, emphasizing the importance of resilience and swift action. It highlights developments involving tech giants, nation-state actors, and supply chain attacks affecting multiple systems and entities. #Microsoft #Coinbase #EarthAmmit #Konni #APT28…

Read More
i³ Threat Advisory: Inside the DPRK: Spotting Malicious Remote IT Applicants – DTEX Systems

DTEX has updated its Insider Threat Advisory highlighting evolved tactics used by DPRK IT workers to infiltrate organizations globally and evade detection, particularly through behavioral and technological indicators. These activities impact corporate insider threat detection, remote access infrastructure, and recruitment systems worldwide. #DPRK #InsiderThreat #RemoteAccess

Read More
OperationToyBoxStory

APT37 conducted a spear phishing campaign disguised as invitations to South Korean national security events, delivering malicious LNK files via Dropbox to execute fileless RoKRAT malware. This campaign exploited trusted cloud services for command and control (C2), challenging detection efforts and impacting endpoint security defenses. #APT37 #RoKRAT #Dropbox #EndpointSecurity

Read More
Fortinet Patches Zero-Day Exploited Against FortiVoice Appliances

Fortinet has released security patches addressing a dozen vulnerabilities across its product range, including a critical zero-day actively exploited against FortiVoice devices. The vulnerabilities could allow remote code execution and authentication bypass, posing significant risks to affected systems. Affected: FortiVoice, Fortinet products (FortiMail, FortiNDR, FortiRecorder, FortiCamera), FortiOS, FortiProxy, FortiSwitchManager, FortiClient, FortiManager,…

Read More
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws

Microsoft’s May 2025 Patch Tuesday addresses security updates for 72 vulnerabilities, including five actively exploited zero-days and two publicly disclosed flaws. The updates fix critical flaws across various Windows components, affecting systems and services globally, with a focus on elevation of privilege, remote code execution, and information disclosure vulnerabilities.Affected: Microsoft Windows, Microsoft Defender, Microsoft Edge, Microsoft Office, Azure, Visual Studio, Remote Desktop, and other Microsoft services.

Read More
New VMware Tools Vulnerability Allows Attackers to Tamper with Virtual Machines, Broadcom Issues Urgent Patch

A newly disclosed VMware Tools vulnerability (CVE-2025-22247) allows attackers with limited access to compromise virtual machines by tampering with local files. Broadcom has issued patches for affected versions on Windows and Linux to address this moderate-severity flaw.Affected: VMware, Virtual Machines, VMware Tools, open-vm-tools…

Read More
Part 1: How to Become a Pentester in 2025: Free & Affordable Online Labs

This web content introduces various free and affordable online platforms for learning penetration testing and cybersecurity skills in 2025. It highlights resources like Hack The Box Academy, PortSwigger Web Security Academy, and TryHackMe to help aspiring pentesters accelerate their journey. Affected: cybersecurity training platforms, learners, and aspiring penetration testers

Read More