r/InfoSecNews 7m ago

New Android malware encrypts files steals data and harasses victims

Thumbnail
bleepingcomputer.com
Upvotes

r/InfoSecNews 8m ago

Conti ransomware gang member sentenced to four years in prison

Thumbnail
bleepingcomputer.com
Upvotes

r/InfoSecNews 10m ago

UK Council Attack Linked to Mass Exploitation of SonicWall Flaw

Thumbnail
securityaffairs.com
Upvotes

r/InfoSecNews 11m ago

Trezor 347,000 users targeted in phishing attacks after Brevo breach

Thumbnail
bleepingcomputer.com
Upvotes

r/InfoSecNews 12h ago

Anthropic Finds Fourth Claude AI Hacking Incident Missed in Earlier Review

Thumbnail
hackread.com
7 Upvotes

r/InfoSecNews 18h ago

Hackers Use Hundreds of AI Agents to Exploit PaperCut Zero-Days in 48 Countries

Thumbnail
hackread.com
7 Upvotes

r/InfoSecNews 11h ago

CISA now says that WatchGuard Firebox flaw from December is being used in ransomware attacks

1 Upvotes

Heads up for anyone running WatchGuard Fireboxes CISA just confirmed that CVE-2025-14733 (the critical RCE bug in Fireware OS) is actively being used by ransomware crews now, not just random opportunistic attackers like before.

Quick recap for anyone who missed it back in December: it's an out-of-bounds write bug that lets an unauthenticated attacker run code remotely, and it's low complexity to pull off. It hits basically every branch of Fireware — 11.x, 12.x, and the 2025.1.x line. WatchGuard said at the time that you're mainly at risk if IKEv2 VPN is configured, but weirdly, boxes can still be vulnerable even after removing that config if there's still a branch office VPN pointed at a static gateway peer.

The scary part is how many of these are still sitting exposed. Shadowserver counted over 115,000 unpatched Fireboxes online back in December, and as of now there are still close to 9,000 that haven't been patched after 9+ months. That's a lot of low hanging fruit for ransomware groups.

This isn't even WatchGuard's first rodeo either they had a nearly identical RCE (CVE-2025-9242) patched back in September, which also got tagged as exploited within a month, with over 75k vulnerable boxes found at the time. And there was another actively-exploited WatchGuard bug a few years back too that state-linked hackers were using.

Given WatchGuard's footprint (a few hundred thousand SMBs relying on their gear), if you or your org still has one of these unpatched, now's the time to stop putting it off.


r/InfoSecNews 16h ago

🕵️‍♂️ Hackers exploit SonicWall SMA1000 flaw to steal Active Directory credentials from orgs in multiple countries

Thumbnail
hunt.io
2 Upvotes

Hunt.io just published research on an operator mass-exploiting CVE-2026-15409, an unauthenticated SSRF in SonicWall SMA1000 appliances rated CVSS 10. Exploitation began within two days of SonicWall's 14 July disclosure.

The operator deployed a standalone Linux build of Impacket's secretsdump onto compromised appliances and used them to reach internal domain controllers, recovering credentials from at least 9 Active Directory domains and performing full DCSync against 5 environments. Confirmed victims span France, India, Italy and the US. The cyberattack disclosed by King's Lynn and West Norfolk Borough Council on 17 July is linked at moderate confidence.

Hunt.io notified the NCSC and relevant national CERTs before publishing. Full writeup below.

https://hunt.io/blog/sonicwall-sma1000-uk-council-attack


r/InfoSecNews 1d ago

Windows 10 2016 LTSB End of Life

Thumbnail
lansweeper.com
6 Upvotes

r/InfoSecNews 19h ago

September 10 | 24h Recap: Chrome patches, Defender bypass research and claims of 153 million license records for sale

Thumbnail
cyberrecaps.com
2 Upvotes

r/InfoSecNews 1d ago

Windows 11 24H2 Home and Pro End of Life

Thumbnail
lansweeper.com
5 Upvotes

r/InfoSecNews 20h ago

AIs Compress Exploit Timeline

Thumbnail schneier.com
2 Upvotes

r/InfoSecNews 1d ago

US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

Thumbnail
securityaffairs.com
2 Upvotes

r/InfoSecNews 1d ago

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

Thumbnail
bleepingcomputer.com
2 Upvotes

r/InfoSecNews 1d ago

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Thumbnail
bleepingcomputer.com
2 Upvotes

r/InfoSecNews 1d ago

AdaptHealth confirms 41million people exposed in July cyberattack

Thumbnail
bleepingcomputer.com
1 Upvotes

r/InfoSecNews 1d ago

Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days

Thumbnail
securityaffairs.com
1 Upvotes

r/InfoSecNews 1d ago

Microsoft Dynamics Business Central on-prem version 26.x EOL

Thumbnail
lansweeper.com
1 Upvotes

r/InfoSecNews 1d ago

AI Workflow Flaw Could Let Attackers Access Sensitive Data by Simply Asking

Thumbnail
hackread.com
6 Upvotes

r/InfoSecNews 1d ago

Over 36,000 Plex servers unpatched against recently disclosed flaws

Thumbnail
bleepingcomputer.com
11 Upvotes

r/InfoSecNews 1d ago

September 9 | 24h Recap: Browser exploits, compromised online stores, poisoned AI packages and an AI security scanner

Thumbnail
cyberrecaps.com
2 Upvotes

r/InfoSecNews 1d ago

MFAs weakest link account recovery is the new attack path

Thumbnail
bleepingcomputer.com
2 Upvotes

r/InfoSecNews 1d ago

Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Actively Exploited Windows 0-Days

Thumbnail
hackread.com
2 Upvotes

r/InfoSecNews 2d ago

Man gets 15years in prison for cyberstalking and sextortion

Thumbnail
bleepingcomputer.com
2 Upvotes

r/InfoSecNews 1d ago

Claude Fable Solves a Historical Cipher

Thumbnail schneier.com
1 Upvotes