Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A municipal utility company in Bavaria, Germany is recovering from a cyberattack that encrypted internal systems and disrupted operations. The attack affected the utility ability to provide services to customers.
Microsoft warned customers that Windows Server 2025 changes may cause application crashes for certain legacy software. The compatibility issues stem from changes in the Windows kernel and security defaults.
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts.
Chainguard has reached a milestone of 1 billion container builds, doubling its output from 500 million in just six months. The company attributes the growth to increased adoption of its secure software supply chain platform and growing enterprise demand for minimal vulnerability containers.
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.
Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.