- The Hidden Threat in Your Stack: Why Non-Human Identity Management is the Next Cybersecurity Frontierby info@thehackernews.com (The Hacker News) on 10/06/2025 at 11:00
Modern enterprise networks are highly complex environments that rely on hundreds of apps and infrastructure services. These systems need to interact securely and efficiently without constant human oversight, which is where non-human identities (NHIs) come in. NHIs — including application secrets, API keys, service accounts, and OAuth tokens — have exploded in recent years, thanks to an
- Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Accountby info@thehackernews.com (The Hacker News) on 10/06/2025 at 10:11
Google has stepped in to address a security flaw that could have made it possible to brute-force an account's recovery phone number, potentially exposing them to privacy and security risks. The issue, according to Singaporean security researcher "brutecat," leverages an issue in the company's account recovery feature. That said, exploiting the vulnerability hinges on several moving parts,
- Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprisesby info@thehackernews.com (The Hacker News) on 10/06/2025 at 07:48
The threat actor known as Rare Werewolf (formerly Rare Wolf) has been linked to a series of cyber attacks targeting Russia and the Commonwealth of Independent States (CIS) countries. "A distinctive feature of this threat is that the attackers favor using legitimate third-party software over developing their own malicious binaries," Kaspersky said. "The malicious functionality of the campaign
- CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities Catalogby info@thehackernews.com (The Hacker News) on 10/06/2025 at 05:37
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added two critical security flaws impacting Erlang/Open Telecom Platform (OTP) SSH and Roundcube to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities in question are listed below - CVE-2025-32433 (CVSS score: 10.0) - A missing authentication for a critical
- Over 70 Organizations Across Multiple Sectors Targeted by China-Linked Cyber Espionage Groupby info@thehackernews.com (The Hacker News) on 09/06/2025 at 15:23
The reconnaissance activity targeting American cybersecurity company SentinelOne was part of a broader set of partially-related intrusions into several targets between July 2024 and March 2025. "The victimology includes a South Asian government entity, a European media organization, and more than 70 organizations across a wide range of sectors," SentinelOne security researchers Aleksandar