Security Leftovers
-
Security Week ☛ ICS/OT Security Budgets Increasing, but Critical Areas Underfunded: Report
The SANS Institute and OPSWAT have published their 2025 ICS/OT Cybersecurity Budget Report.
-
Pen Test Partners ☛ DNSSEC NSEC. The accidental treasure map to your subdomains
TL;DR: DNSSEC secures DNS but may unintentionally expose domain structures via NSEC/NSEC3 records, enabling zone walking to enumerate subdomains. NSEC openly lists domain names, making enumeration easy.
-
Security Week ☛ Broadcom Patches 3 VMware Zero-Days Exploited in the Wild
Broadcom patched VMware zero-days CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226 after Abusive Monopolist Microsoft warned it of exploitation.
-
The Strategist ☛ In case we forgot, Typhoon attacks remind us of China’s cyber capability—and intent [Ed: China just took advantage of CALEA]
Australians need to understand the cyber threat from China. US President The Insurrectionist described the launch of Chinese artificial intelligence chatbot, DeepSeek, as a wake-up call for the US tech industry.
-
Security Week ☛ Vulnerabilities Patched in Qualcomm, Mediatek Chipsets
Chip makers Qualcomm and Mediatek have released patches for many vulnerabilities across their products.
-
Scoop News Group ☛ Congress eyes bigger cyber role for NTIA amid telecom attacks
A pair of cyber-focused bills tied to the National Telecommunications and Information Administration advanced out of a House committee Tuesday.
-
Security Week ☛ Exploitation Long Known for Most of CISA’s Latest KEV Additions
Exploitation has been known for months or years for most of the latest vulnerabilities added by CISA to its KEV catalog.
-
Security Week ☛ Google Patches Pair of Exploited Vulnerabilities in Android
Android’s March 2025 security update addresses over 40 vulnerabilities, including two actively exploited in the wild.
-
Troy Hunt ☛ We're Backfilling and Cleaning Stealer Logs in Have I Been Pwned
I think I've finally caught my breath after dealing with those 23 billion rows of stealer logs last week.
-
SANS ☛ Tool update: mac-robber.py, (Tue, Mar 4th)
Just a quick update. I fixed a big bug in my mac-robber.py script about 2 weeks ago [...]
-
Bruce Schneier ☛ Trojaned Hey Hi (AI) Tool Leads to Disney Hack [Ed: Misleading title as it's about someone running malware, nothing to do with the buzzwords used herein]
This is a sad story of someone who downloaded a Trojaned Hey Hi (AI) tool that resulted in hackers taking over his computer and, ultimately, costing him his job.
-
SANS ☛ Romanian Distillery Scanning for SMTP Credentials, (Tue, Mar 4th)
Lately, attackers have gotten more creative and aggressive in trying to find various credential files on exposed web servers. Our "First Seen" page each day shows many new versions of scans for secrets files like ".env".
-
Windows TCO / Windows Bot Nets
-
Security Week ☛ Polish Space Agency Hit by Cyberattack
The Polish space agency POLSA says it has disconnected its network from the internet to contain a cyberattack.
-