The Week in Vulnerabilities: Cyble Warns of Rising Exploits Targeting ICS, Enterprise, and Web Systems

Between May 28 and June 3, 2025, multiple high-severity vulnerabilities were actively exploited by various threat actors, including a China-linked APT group targeting diverse industries. Cyble Research & Intelligence Labs observed increased exploit attempts, malware campaigns, and critical infrastructure risks, emphasizing the urgency of patching and enhanced cybersecurity measures. #CVE-2024-56145 #CVE-2025-5419 #ChinaAPT #MiraiBotnet

Read More
⚡ Weekly Recap: Chrome 0-Day, Data Wipers, Misused Tools and Zero-Click iPhone Attacks

This cybersecurity update highlights recent critical vulnerabilities, advanced malware campaigns, and nation-state hacking activities, emphasizing the importance of proactive defense. Key incidents include Google Chrome fixing an exploited 0-day, PathWiper targeting Ukraine, and sophisticated zero-click attacks on iPhones. #ChromeZeroDay #PathWiper #SaltTyphoon…

Read More
iMessage Zero-Click Attacks Suspected in Targeting of High-Value Individuals

Anomalous iPhone crashes linked to sophisticated zero-click exploits targeting a vulnerability called Nickname have been observed mainly in high-value individuals in the EU and US. These targeted attacks, associated with Chinese state-sponsored hackers, exploit iMessage vulnerabilities to potentially compromise devices without user interaction. #NickameVulnerability #ChineseHackers…

Read More
Controversial Firms Cellebrite and Corellium Announce 0 Million Acquisition Deal

Cellebrite’s acquisition of Corellium for $200 million aims to enhance mobile vulnerability detection and virtual device visualization solutions for various sectors. Both companies have faced legal and ethical controversies, including lawsuits from Apple and associations with spyware groups. #Cellebrite #Corellium #NSOGroup #Apple #cybersecurityM&A…

Read More
Cybersecurity News | Daily Recap [02 Jun 2025]

Recent cybersecurity updates highlight active exploitation of Adreno GPU vulnerabilities and the critical vBulletin flaw, underscoring the urgency for patching and improved security practices. The reports also reveal threats from TrickBot, GhostSpy, and NetBird spear-phishing campaigns, as well as geopolitical influence campaigns and regional cyber incidents. #AdrenoGPU #vBulletin #TrickBot #GhostSpy #NetBird

Read More
Exploit details for max severity Cisco IOS XE flaw now public

A critical vulnerability (CVE-2025-20188) in Cisco IOS XE Wireless LAN Controllers allows remote attackers to upload arbitrary files and execute commands with root privileges, especially when the ‘Out-of-Band AP Image Download’ feature is enabled. Immediate action is recommended, including software updates and disabling vulnerable features, to prevent exploitation. #CiscoIOSXEWLC #CVE2025-20188

Read More
Cisco Product Security Update Advisory

Cisco has released multiple security updates addressing numerous vulnerabilities across its IOS XE, IOS, Catalyst SD-WAN Manager, Webex Services, and other products. Users are strongly advised to update to the latest versions to mitigate risks including denial of service, command injection, privilege escalation, and cross-site scripting. #CiscoIOSXE #CatalystSDWAN #CiscoWebex

Read More
Microsoft Authenticator now warns to export passwords before July cutoff

Microsoft Authenticator is transitioning away from its password autofill feature, urging users to switch to Microsoft Edge to maintain seamless account access. The deprecation timeline spans from June 2025, with complete discontinuation by August 2025, prompting users to export passwords or enable autofill in Edge.
#MicrosoftAuthenticator #PasswordAutofill #MicrosoftEdge

Read More