November 28, 2025 at 12:10AM

■□□□□ CVE-2025-5318 A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing.…

November 28, 2025 at 12:01AM

■□□□ 💥 Cyber-War on Israel: Transport display outages; new details on cyber intrusion into “Urban Digital” company. 🎤Following a widespread disruption in transport information displays in the occupied territories, Hebrew sources confirmed that the incident originated from a cyber intrusion into the infrastructure of the “Urban Digital” company. This attack disabled parts of the smart…

November 27, 2025 at 03:46PM

■■□□□ The Central Bank of India (RBI) 🇮🇳 has made a good decision from cyber security perspective. They have forced all bank websites to be subdomains of bank.in This will effectively cause most phishing campaigns to go astray. 🚫

November 27, 2025 at 03:19PM

■■■■□ SectorA01 (Lazarus) employed a highly sophisticated, multi-stage attack chain beginning with social engineering via a fake official Deriv trading platform installer (NSIS-based). The infection progresses through a polyglot payload sequence (NSIS → Electron/JavaScript → Python → .NET), using dynamic code execution via eval() on remotely fetched JavaScript, Pastebin as a dead-drop mechanism with 1,000…