InfoSec
banner
infosec.skyfleet.blue
InfoSec
@infosec.skyfleet.blue
Relay Tracking News & Blogs about infosec, cybersec
- source removal/addition suggestions welcome !

CVE : check out @cve.skyfleet.blue

🆘 @skyfleet.blue
Critical Fortinet FortiWeb Vulnerability CVE-2025-64446
Critical Fortinet FortiWeb Vulnerability CVE-2025-64446
On November 14, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) officially added CVE-2025-64446 to its Known Exploited Vulnerabilities (KEV) catalog. This critical vulnerability a…
thecyberthrone.in
November 15, 2025 at 4:19 AM
Cisco Warns of High-Severity Privilege Escalation Flaw (CVE-2025-20341) in Catalyst Center Virtual Appliance
Cisco Warns of High-Severity Privilege Escalation Flaw (CVE-2025-20341) in Catalyst Center Virtual Appliance
Cisco patched a High-severity EoP flaw (CVE-2025-20341) in Catalyst Center Virtual Appliance. A low-privileged Observer user can remotely elevate privileges to Administrator via a crafted HTTP request.
securityonline.info
November 15, 2025 at 4:18 AM
Symfony Patches PATH_INFO Parsing Flaw Leading to Authorization Bypass (CVE-2025-64500)
Symfony Patches PATH_INFO Parsing Flaw Leading to Authorization Bypass (CVE-2025-64500)
Symfony patched a High-severity flaw (CVE-2025-64500) in its Request component. Improper PATH_INFO parsing allows attackers to bypass access control rules in vulnerable applications.
securityonline.info
November 15, 2025 at 4:13 AM
Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications
Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications
cybersecuritynews.com
November 15, 2025 at 4:03 AM
Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover
Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover
cybersecuritynews.com
November 15, 2025 at 3:23 AM
Washington Post Confirms Data Breach as CL0P Claims Over 40 Oracle Victims
Washington Post Data Breach One Of 40+ Claimed By CL0P
The Washington Post data breach is one of more than 40 claimed by CL0P in a threat campaign targeting Oracle E-Business Suite vulnerabilities.
thecyberexpress.com
November 14, 2025 at 11:44 PM
The Good, the Bad and the Ugly in Cybersecurity – Week 46
The Good, the Bad and the Ugly in Cybersecurity – Week 46
www.sentinelone.com
November 14, 2025 at 10:39 PM
Five plead guilty to helping North Koreans infiltrate US firms
Five plead guilty to helping North Koreans infiltrate US firms
The U.S. Department of Justice announced that five individuals pleaded guilty to aiding North Korea's illicit revenue generation schemes, including remote IT worker fraud and cryptocurrency theft.
www.bleepingcomputer.com
November 14, 2025 at 10:34 PM
Logitech confirms data breach after Clop extortion attack
Logitech confirms data breach after Clop extortion attack
Hardware accessory giant Logitech has confirmed it suffered a data breach in a cyberattack claimed by the Clop extortion gang, which conducted Oracle E-Business Suite data theft attacks in July.
www.bleepingcomputer.com
November 14, 2025 at 10:29 PM
Akira RaaS Targets Nutanix VMs, Threatens Critical Orgs
Akira RaaS Targets Nutanix VMs, Threatens Critical Orgs
The Akira ransomware group has been experimenting with new tools, bugs, and attack surfaces, with demonstrated success in significant sectors.
www.darkreading.com
November 14, 2025 at 10:09 PM
New Security Tools Target Growing macOS Threats
New Security Tools Target Growing macOS Threats
A public dataset and platform-agnostic analysis tool aim to help organizations in the fight against Apple-targeted malware, which researchers say has lacked proper attention.
www.darkreading.com
November 14, 2025 at 9:49 PM
Multiple US citizens plead guilty to helping North Korean IT workers earn $2 million
Multiple US citizens plead guilty to helping North Korean IT workers earn $2 million
Three U.S. nationals pleaded guilty to directly handing over their identities for use in North Korean IT worker scams, the Justice Department said, and two other people also admitted helping such schemes.
therecord.media
November 14, 2025 at 9:14 PM
Fortinet finally cops to critical make-me-admin bug under active exploitation
Fortinet finally cops to critical bug under active exploit
: More than a month after PoC made public
www.theregister.com
November 14, 2025 at 9:09 PM
DOJ lauds series of gains against North Korean IT worker scheme, crypto thefts
DOJ lauds series of gains against North Korean IT worker scheme, crypto thefts
Federal prosecutors secured five guilty pleas from people who supported overseas remote IT workers, and seized $15 million in stolen cryptocurrency tied to the North Korean regime.
cyberscoop.com
November 14, 2025 at 9:04 PM
Hardened Containers Look to Eliminate Common Source of Vulnerabilities
Hardened Containers Look to Eliminate Common Source of Vulnerabilities
A kitchen-sink approach to building containers has loaded many with vulnerabilities. A handful of companies are trying to slim them down to address the issue.
www.darkreading.com
November 14, 2025 at 8:59 PM
150,000 Packages Flood NPM Registry in Token Farming Campaign
150,000 Packages Flood NPM Registry in Token Farming Campaign
A self-replicating attack led to a tidal wave of malicious packages in the NPM registry, targeting tokens for the tea.xyz protocol.
www.darkreading.com
November 14, 2025 at 8:53 PM
Beware of Phishing Emails as Spam Filter Alerts Steal Your Email Logins in a Blink
Beware of Phishing Emails as Spam Filter Alerts Steal Your Email Logins in a Blink
cybersecuritynews.com
November 14, 2025 at 8:07 PM
North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
thehackernews.com
November 14, 2025 at 7:58 PM
China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work
China’s ‘autonomous’ AI-powered hacking campaign still required a ton of human work 
Anthropic and AI security experts told CyberScoop that behind the hype, effective AI-driven cyberattacks still require skilled humans, with the attack possibly done to send a message as what’s possible.
cyberscoop.com
November 14, 2025 at 7:53 PM
Shadow Program Gives AWS Exec New Security Lens
Shadow Program Gives AWS Exec New Security Lens
Sara Duffer highlights the top lessons she brought back to her security role following three years in Amazon's shadow program.
www.darkreading.com
November 14, 2025 at 7:48 PM
PostgreSQL releases fixes for CVE-2025-12817 & CVE-2025-12818
oss-sec: PostgreSQL releases fixes for CVE-2025-12817 & CVE-2025-12818
Posted by Alan Coopersmith on Nov 14 https://www.postgresql.org/about/news/postgresql-181-177-1611-1515-1420-and-1323-released-3171/ announces:
seclists.org
November 14, 2025 at 6:53 PM