Monthly Archive: September 2025

The Hidden Danger of Plain-Text Backup Codes

Huntress has published a detailed account of an incident in which attackers, having exploited a vulnerable SonicWall VPN, gained access to the management console and nearly stripped the organization of its defensive capabilities by...

Phoenix: A New Rowhammer Attack Bypasses DDR5 Protections

Researchers from COMSEC, in collaboration with Google engineers, have uncovered a novel Rowhammer variant capable of circumventing protections in contemporary SK Hynix DDR5 modules — the flaw has been assigned CVE-2025-6202. The team demonstrated...

A Simple Calendar Invite Can Make ChatGPT Leak Your Data

OpenAI has enabled support for the Model Context Protocol (MCP) in ChatGPT, permitting third-party services such as Gmail, calendars, SharePoint, Notion and other data sources to be integrated. The intent was to enrich the...

The Art of Digital Evasion: How Attackers Hide in Plain Sight

In the second quarter of 2025, experts at HP Wolf Security documented a wave of sophisticated attacks in which adversaries employed unconventional living-off-the-land (LOTL) tactics to evade detection. Multiple obscure system utilities were brought...

UN Warns of New Cyberfraud Hub in Timor-Leste

The United Nations has issued a warning about a new trend in the operations of international criminal networks. According to a report by the UNODC, evidence of fraudulent centers has been uncovered in the...