Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits
“These weren’t obscure, corner-case vulnerabilities,” security vendor Eclypsium said in a report shared with The Hacker News.
“Instead these were very well-known issues that we wouldn’t expect to see
Beware: Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks
“The campaign is global, with Netskope Threat Labs tracking victims targeted in Argentina, Colombia, the United States, the Philippines, and other countries around the world,” Leandro Fróes, senior threat research engineer at
Experts Find Shared Codebase Linking Morpheus and HellCat Ransomware Payloads
The findings come from SentinelOne, which analyzed artifacts uploaded to the VirusTotal malware scanning platform by the same submitter towards the end of December 2024.
“These two payload samples are
Axoflow Raises $7 Million for Security Data Curation Platform
Security data pipeline management startup Axoflow has raised $7 million in a seed funding round led by EBRD Venture Capital.
The post Axoflow Raises $7 Million for Security Data Curation Platform appeared first on SecurityWeek.
Homebrew macOS Users Targeted With Information Stealer Malware
A malicious campaign has been redirecting macOS users to a fake Homebrew website, infecting them with information stealer malware.
The post Homebrew macOS Users Targeted With Information Stealer Malware appeared first on SecurityWeek.
Tesla Charger Exploits Earn Hackers $129,000 at Pwn2Own
Hackers earned more than $700,000 on the first two days of Pwn2Own Automotive 2025 for EV charger and infotainment exploits.
The post Tesla Charger Exploits Earn Hackers $129,000 at Pwn2Own appeared first on SecurityWeek.
Cisco Patches Critical Vulnerability in Meeting Management
Cisco has released patches for three vulnerabilities, including a critical privilege escalation bug and a DoS flaw for which exploit code exists.
The post Cisco Patches Critical Vulnerability in Meeting Management appeared first on SecurityWeek.
SonicWall Learns From Microsoft About Potentially Exploited Zero-Day
SonicWall has credited Microsoft for reporting CVE-2025-23006, a critical remote command execution vulnerability possibly exploited in the wild.
The post SonicWall Learns From Microsoft About Potentially Exploited Zero-Day appeared first on SecurityWeek.
