Latest Posts
Major Supply Chain Attack Impacting React NativeZero-day in Windows Server 2025’s Active Directory enables full Domain TakeoverURGENT COMMVAULT ALERT CVE-2025-3928 Enables M365 Tenant CompromiseFive windows 0-days: The Lazarus Group Says Thanks for Not PatchingCPU Based Ransomware. Oof. How CPU Vulnerabilities Open the Door to Microcode Ransomware
  • Follow
  • Follow
  • Follow
  • Follow
  • Home
  • BULLETINS
  • ABOUT US
  • Free Security Resources
    • Training Workshops
  • CONTACT US
    • Subscribe to Free Newsletter!
    • Tell Your Story!
May 2025 Patch Tuesday: Five Zero-Days Unleashed and Critical Flaws Demand Action

May 2025 Patch Tuesday: Five Zero-Days Unleashed and Critical Flaws Demand Action

by Jonathan R. Brennan, CISSP | May 14, 2025 | Bulletins, Uncategorized

Stay Ahead of Cyber Threats Critical Security Updates. Time to Panic Less, Patch More. Microsoft’s May 2025 Patch Tuesday isn’t just another update cycle—it’s a five-alarm situation for IT and security teams. This month’s release includes fixes for 72 vulnerabilities,...
Blob URI Phishing: The Sneaky Threat Slipping Past Your Defenses

Blob URI Phishing: The Sneaky Threat Slipping Past Your Defenses

by Jonathan R. Brennan, CISSP | May 12, 2025 | Bulletins

Unmasking the Invisible Threat Understanding HTML Smuggling: A New Era of Phishing Yes,  The name is absurd.  We agree.  Let’s also agree to move past that because this is a serious threat.   Blob URI phishing is a stealthy, modern twist on HTML Smuggling that allows...
RATatouille Strikes: Remote Access Trojan Baked into Popular NPM Package rand-user-agent

RATatouille Strikes: Remote Access Trojan Baked into Popular NPM Package rand-user-agent

by Jonathan R. Brennan, CISSP | May 11, 2025 | Bulletins

Attackers spiked the deprecated but widely downloaded rand-user-agent npm package with a stealthy Remote Access Trojan (RAT). Now dubbed “RATatouille,” the malware gives adversaries remote access to systems via poisoned developer tools. Here’s how it happened—and how...
Cisco IOS XE Flaw Exposes Wireless Controllers to Full Takeover

Cisco IOS XE Flaw Exposes Wireless Controllers to Full Takeover

by Jonathan R. Brennan, CISSP | May 9, 2025 | Bulletins

Understanding the Risks Embedded Wireless Controller Vulnerabilities A Hard-Coded Catastrophe Cisco has dropped a patch for a nasty flaw in IOS XE Wireless LAN Controllers—CVE-2025-20188. The culprit? A hard-coded JSON Web Token (JWT) in the ‘Out-of-Band AP Image...
Bring Your Own Installer – SentinelOne Bypass Lets Ransomware Walk In

Bring Your Own Installer – SentinelOne Bypass Lets Ransomware Walk In

by Jonathan R. Brennan, CISSP | May 8, 2025 | Bulletins

The BYOI Vulnerability: A New Threat to EDR Security SentinelOne Hacked by Its Own Installer? The BYOI Technique That Lets Attackers Disable EDR Mid-Upgrade Critical Security Advisory Understanding the BYOI Vulnerability A newly discovered SentinelOne bypass known as...
Brace for Impact: Windows 11 24H2 Pushes Ahead—But IT Teams Should Hit Pause

Brace for Impact: Windows 11 24H2 Pushes Ahead—But IT Teams Should Hit Pause

by Jonathan R. Brennan, CISSP | May 6, 2025 | Bulletins, NEWS

Network Instability and Performance Issues Brace for Impact: Navigating the Windows 11 24H2 Update Windows 11 24H2 has moved into broad deployment, bringing system tweaks, new features—and a host of real-world problems. Early adopters of the Windows 11 24H2 update are...
« Older Entries
Next Entries »

Follow Us

  • Facebook
  • Twitter
  • Instagram
  • LinkedIn
  • YouTube

Search

Recent Posts

  • Major Supply Chain Attack Impacting React Native
  • Zero-day in Windows Server 2025’s Active Directory enables full Domain Takeover
  • URGENT COMMVAULT ALERT CVE-2025-3928 Enables M365 Tenant Compromise
  • Five windows 0-days: The Lazarus Group Says Thanks for Not Patching
  • CPU Based Ransomware. Oof. How CPU Vulnerabilities Open the Door to Microcode Ransomware

Categories

  • Bulletins
  • NEWS
  • Resources
  • Training
  • Uncategorized
  • User Stories

SecurityBlotter.com
Panic More. Patch Less.



Copyright 2025All rights reserved. Duplication or republication of any contents is prohibited without written permission from SecurityBlotter.

Recent News

  • Supply Chain CompromiseMajor Supply Chain Attack Impacting React Native
  • Zero-day in Windows Server 2025’s Active Directory…
  • URGENT COMMVAULT ALERT CVE-2025-3928 Enables M365…

Designed by Elegant Themes | Powered by WordPress