LogoVulnerable U
Read
Watch
Jobs
Membership
Login
Subscribe

Archive

News

Russian-Linked Actors Target Accounts With Device Code Phishing Tactic

Feb 14, 2025

•

3 min read

Russian-Linked Actors Target Accounts With Device Code Phishing Tactic

Microsoft categorizes the emerging threat group behind an ongoing campaign as Storm-2372, which is a suspected nation-state actor “working toward Russian state interests.”

Newsroom
Newsroom

News

Exploits Hit Palo Alto CVE-2025-0108

Feb 14, 2025

•

2 min read

Exploits Hit Palo Alto CVE-2025-0108

Palo Alto disclosed the bug on Feb. 12 and released updated software to address it

Newsroom
Newsroom
🎓️ Vulnerable U | #103

Feb 14, 2025

•

14 min read

🎓️ Vulnerable U | #103

What really happened with DOGE at the Treasury, Apple patches vuln likely used by spyware, Old Microsoft bugs spiking in exploit activity, some great bug bounty write-ups, and much more!

Matt Johansen
Matt Johansen

News

+1

Russian Hackers Expand Global Cyber Espionage Campaign with "BadPilot" Operation

Feb 13, 2025

•

6 min read

Russian Hackers Expand Global Cyber Espionage Campaign with "BadPilot" Operation

Microsoft revealed a multiyear cyber espionage campaign by Russian state-sponsored hackers. The operation has exploited critical infrastructure worldwide.

Matt Johansen
Matt Johansen

News

New PostgreSQL Zero Day Found as Part of BeyondTrust Investigation

Feb 13, 2025

•

3 min read

New PostgreSQL Zero Day Found as Part of BeyondTrust Investigation

Newsroom
Newsroom

cybercrime

+1

Massive Carding Marketplace "Savastan0" Selling Over 15 Million Stolen Credit Cards

Feb 13, 2025

•

5 min read

Massive Carding Marketplace "Savastan0" Selling Over 15 Million Stolen Credit Cards

An underground carding marketplace sells over 15 million stolen credit and debit cards. Researchers reveal its operations and the growing scale of card fraud.

Matt Johansen
Matt Johansen

News

Ivanti Patches Critical Bugs in Multiple Products

Feb 12, 2025

•

3 min read

Ivanti Patches Critical Bugs in Multiple Products

The flaws affect Connect Secure, Policy Secure, Secure Access Client, and Cloud Services Application

Newsroom
Newsroom

News

Hackers Use Google Tag Manager to Inject Credit Card Skimmers in E-Commerce Stores

Feb 11, 2025

•

6 min read

Hackers Use Google Tag Manager to Inject Credit Card Skimmers in E-Commerce Stores

Malware campaign abusing GTM to inject credit card skimmers into e-commerce sites. Obfuscated JavaScript stealing payment data, along with a hidden PHP backdoor for persistent access.

Matt Johansen
Matt Johansen

News

Alabama Man Pleads Guilty to SEC Twitter Account Hack

Feb 10, 2025

•

3 min read

Alabama Man Pleads Guilty to SEC Twitter Account Hack

Eric Council Jr., 25, who was arrested in October 2024, pleaded guilty to conspiracy to commit aggravated identity theft and access device fraud

Newsroom
Newsroom

News

Global Law Enforcement Operation Targets 8Base Ransomware Leak Site

Feb 10, 2025

•

4 min read

Global Law Enforcement Operation Targets 8Base Ransomware Leak Site

The dark web leak site of the 8base, a ransomware group that deploys a variant of the Phobos ransomware, has been seized.

Newsroom
Newsroom

Microsoft

+1

Exploits Target Office CVE-2024-21413 Flaw Microsoft Patched a Year Ago

Feb 7, 2025

•

4 min read

Exploits Target Office CVE-2024-21413 Flaw Microsoft Patched a Year Ago

The flaw can lead to remote code execution

Newsroom
Newsroom

Newsletter

🎓️ Vulnerable U | #102

Feb 7, 2025

•

13 min read

🎓️ Vulnerable U | #102

Musk's DOGE agents accessing sensitive info, Medical device backdoors, North Korean MacOS malware, Cisco and Zyxel vulnerabilities, and much more!

Matt Johansen
Matt Johansen
Load more
Vulnerable U

Vulnerable U

Infosec's favorite weekly newsletter for news, tools, and tips with 38,000+ CISOs, founders, change-makers, and straight up hackers.


Home

Posts

Authors

Account

Upgrade

Sponsors

Sponsors