#Vulnerabilities
While recent coverage has focused on implications for U.S. defense, China expert Rush Doshi explains in the latest episode of Rethinking Trade why vulnerabilities extend far beyond the military and pose broader risks to U.S. sovereignty.

Listen now: youtu.be/a0KzzU1xN14
China’s Devastating Rare-Earths Squeeze: Rush Doshi on What It Means and What the U.S. Must Do Next
What happens when China cuts off the rare earths that power electric vehicles, missiles, and our defense industry? In this episode of Rethinking Trade, Lori Wallach sits down with Rush Doshi —…
youtu.be
November 12, 2025 at 3:51 PM
Outside of AI moderation and tools leading to massive security vulnerabilities... I think there will end up being a lot of false flags that end up getting people fucked over.
November 12, 2025 at 3:43 PM
2020 U.S. Senate Select Committee on Intelligence - Volume 5: Counterintelligence Threats and Vulnerabilities 👇
November 12, 2025 at 3:40 PM
GitHub Copilot and Visual Studio Vulnerabilities Allow Attacker to Bypass Security Feature
GitHub Copilot and Visual Studio Vulnerabilities Allow Attacker to Bypass Security Feature
cybersecuritynews.com
November 12, 2025 at 3:38 PM
Hitachi-owned GlobalLogic reported that personal data of over 10,000 current and former employees was compromised due to attacks by the Clop ransomware gang exploiting Oracle E-Business Suite vulnerabilities (CVE-2025-61882, CVE-2025-61884).
Hitachi-owned GlobalLogic admits data stolen on 10k current and former staff
go.theregister.com
November 12, 2025 at 3:35 PM
runZero Hour is one week away!

Join us on Nov 19: @todb.hugesuccess.org, Rob King, @hdm.io, and Jared Atkinson ( CTO @specterops.io ) break down attacker movement, graph analysis, runZeroHound, and this month’s top vulnerabilities.

👉 Register here: www.runzero.com/research/run...
November 12, 2025 at 3:27 PM
Thankfully our sequencing network is better isolated than most of our institute, and managed by me and not IT😅
They also missed a few vulnerabilities but that's perhaps besides the point.
November 12, 2025 at 3:23 PM
I think my favorite part of following security people online is how much they love to make fun of theoretical vulnerabilities found by researchers performing esoteric, highly improbable actions, that get fixed by vendors without anyone ever actually performing said attack.
November 12, 2025 at 3:23 PM
Amazon is the latest company to roll out AI bug bounty program, giving external researchers the ability to test their models for vulnerabilities. 👀 🪲

Full scoop from @cyberscoop.bsky.social 's @derekbjohnson.bsky.social 📰 ➡️ cyberscoop.com/amazon-bug-b...
November 12, 2025 at 3:22 PM
As experts work to understand detransitioners, their vulnerabilities and their highly individualized needs, their identities are being co-opted as part of a national campaign against transgender rights.
Detransition is key to politicians’ anti-trans agenda. But what is it really like?
The 19th spoke with two detransitioners who feel harmed and used by the Trump administration, which has positioned itself as a protector of those who detransition.
19thnews.org
November 12, 2025 at 3:21 PM
📌 Microsoft's November 2025 Patch Tuesday Addresses 63 Vulnerabilities, Including an Actively Exploited Zero-Day in Windows Kernel https://tinyurl.com/22aaqjd7
Microsoft's November 2025 Patch Tuesday Addresses 63 Vulnerabilities, Including an Actively Exploited Zero-Day in Windows Kernel
In November 2025, Microsoft released its monthly security updates, known as Patch Tuesday, addressing a total of 63 vulnerabilities. Among these, a zero-day vulnerability in the Windows kernel stands out due to its active exploitation in the wild. Zero-day vulnerabilities are particularly dangerous as they are unknown to the vendor until they are discovered, often after they have been exploited by attackers. The Windows kernel is a critical component of the operating system, and vulnerabilities in this area can lead to severe consequences, including privilege escalation, arbitrary code execution, and complete system compromise. The presence of an actively exploited zero-day vulnerability underscores the urgency for organizations to apply these patches promptly. Delaying the application of these updates can leave systems exposed to targeted attacks, which can result in data breaches, system compromises, and other security incidents. The fact that this vulnerability is already being exploited indicates that attackers are aware of it and are actively using it to compromise systems. From a cybersecurity perspective, this highlights the importance of robust patch management processes. Organizations must prioritize the timely application of security updates to mitigate the risk of exploitation. Additionally, this incident serves as a reminder of the ongoing cat-and-mouse game between cybersecurity professionals and attackers. As defenders patch vulnerabilities, attackers seek out new ones, making continuous vigilance and proactive security measures essential. The impact of this Patch Tuesday update on the cybersecurity landscape is significant. It underscores the need for organizations to stay current with their security updates and to have processes in place to quickly respond to new vulnerabilities. For cybersecurity professionals, this means staying informed about the latest threats and ensuring that their organizations are protected against known vulnerabilities. In conclusion, the November 2025 Patch Tuesday update from Microsoft is a critical reminder of the importance of timely patch management. The inclusion of an actively exploited zero-day vulnerability in the Windows kernel highlights the ongoing threat posed by such vulnerabilities and the need for organizations to remain vigilant and proactive in their cybersecurity efforts.
tinyurl.com
November 12, 2025 at 3:20 PM
Zoom users: Critical vulnerabilities detected! Update your apps now to protect against unauthorized access and data breaches. #PotatoSecurity #ZoomUpdate #DataProtection Link: thedailytechfeed.com/zoom-urges-i...
November 12, 2025 at 3:18 PM
Zoom users: Critical vulnerabilities detected! Update your apps now to protect against unauthorized access and data breaches. #CyberSecurity #ZoomUpdate #DataProtection Link: thedailytechfeed.com/zoom-urges-i...
November 12, 2025 at 3:18 PM
Microsoft Patches 66 Vulnerabilities in November Update

CVE-2025-60724 is the headline grabber this month: a critical severity, exploited-in-the-wild zero-day vulnerability that, according to Microsoft, affects nearly every... #Microsoft
Microsoft Patches 66 Vulnerabilities in November Update
The November Patch Tuesday from Microsoft has landed, bringing with it a mixed bag of security fixes. While the total number of vulnerabilities addressed – 66 – is lower than in recent months, one critical zero-day exploit already in the wild demands immediate attention from IT departments worldwide. This month’s update highlights the constant cat-and-mouse […]
hashlytics.io
November 12, 2025 at 3:14 PM
IEA forecasts oil, gas rise

The International Energy Agency said in its World Energy Outlook that global oil and gas demand could rise through 2050, reversing earlier forecasts and highlighting energy-system vulnerabilities.

With replies by 🎓Glen P. Peters, 🎓John Quiggin +39 more scholars.
IEA forecasts oil, gas rise
Replies by 🎓Glen P. Peters, 🎓John Quiggin, 🎓Brett Christophers, 🎓Hakan Yilmazkuday, 🎓Jonathan T. Overpeck +36 more scholars
www.lightnews.app
November 12, 2025 at 2:57 PM
New Microsoft Alert — Update Windows 10 And 11 Now, Attacks Underway www.forbes.com/sites... #cybersecurity #Windows #Chrome #vulnerabilities #updatenow
November 12, 2025 at 2:44 PM
November #PatchTuesday drops 66 new vulnerabilities, with 1 critical zero-day exploited in the wild (no public disclosure yet).

3 critical RCEs patched, all rated less likely to be exploited. Find Rapid7's analysis in a new blog: r-7.co/4nOaIre
November 12, 2025 at 2:41 PM
Excited to share another blog where Amazon Cyber Threat Intelligence (ACTI) discovered APT exploitation of zero-day vulnerabilities in Cisco and Citrix products. Proud of the team’s work! aws.amazon.com/blogs/securi...
Amazon discovers APT exploiting Cisco and Citrix zero-days | Amazon Web Services
The Amazon threat intelligence team has identified an advanced threat actor exploiting previously undisclosed zero-day vulnerabilities in Cisco Identity Service Engine (ISE) and Citrix systems. The ca...
aws.amazon.com
November 12, 2025 at 2:36 PM
We’re launching Semgrep AI-powered detection — a first-of-its-kind hybrid of deterministic scanning and AI that finds vulnerabilities like IDORs and business logic flaws that other tools miss. Our Private Beta opens today, and spots are limited.

👉 Learn more:
www.prnewswire.com/news-release...
November 12, 2025 at 2:30 PM
Notícia da SecurityWeek

"High-Severity Vulnerabilities Patched in VMware Aria Operations, NSX, vCenter " #bolhasec
High-Severity Vulnerabilities Patched in VMware Aria Operations, NSX, vCenter
Broadcom announced patches for six vulnerabilities affecting VMware Aria Operations, NSX, vCenter, and VMware Tools products.
www.securityweek.com
November 12, 2025 at 2:30 PM
"Amid these shifts, traditional energy risks affecting the security of oil and gas supply are now accompanied by vulnerabilities in other areas, most visibly in supply chains for critical minerals due to high levels of market concentration [i.e. China]."
November 12, 2025 at 2:11 PM
Ubuntu's Rust Transition Hits Another Bump as sudo-rs Security Vulnerabilities Show Up Password exposure and improper authentication validation issues caught early ahead of the LTS release. https:// itsfoss.com/news/sudo-rs-issue -ubuntu/ # Ubuntu

Interest | Match | Feed
Origin
infosec.exchange
November 12, 2025 at 2:07 PM