Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Executive summary People’s Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging, and military infrastructure networks. While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers, they also leverage compromised devices and trusted connections to pivot into other networks.
CISA received six files related to Microsoft SharePoint vulnerabilities, including an exploit chain known as ToolShell that uses CVE-2025-49706 and CVE-2025-49704. The analysis includes Base64 encoded .NET DLL binaries that retrieve machine key settings from ASP.NET applications.
Notification This report is provided "as is" for informational purposes only.
CISA released a malware analysis report on exploitation of SharePoint vulnerabilities allowing attackers to execute remote code and access sensitive data. The report details how multiple CVEs are chained for maximum impact.
This DFIR Report analysis covers ransomware threats including attack chains, indicators of compromise, and recommended defensive measures. Ransomware continues to be a primary cyber risk for organizations across all sectors.
Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism.