For CISOs responsible for cyber risk management, these three insights will help build a strong and reliable foundation for your proactive security strategy.
Trend™ Research analyzed a campaign distributing Atomic macOS Stealer (AMOS), a malware family targeting macOS users. Attackers disguise the malware as “cracked” versions of legitimate apps, luring users into installation.
GreyNoise observed two scanning surges against Cisco Adaptive Security Appliance (ASA) devices in late August including more than 25,000 unique IPs in a single burst. This activity represents a significant elevation above baseline, typically registering at less than 500 IPs per day.
A vulnerability was found in AOMEI Backupper Workstation and classified as critical. Affected by this issue is some unknown functionality. Executing manipulation can lead to link following.
This vulnerability appears as CVE-2025-8612. The attack requires local access. There is no available exploit.
A vulnerability was found in Craft CMS up to 4.16.5/5.8.6 and classified as problematic. This impacts an unknown function of the component Twig Handler. Such manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is traded as CVE-2025-57811. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Microsoft Windows. It has been classified as problematic. This impacts an unknown function of the component LNK File Handler. The manipulation leads to clickjacking.
This vulnerability is listed as CVE-2025-9491. The attack may be initiated remotely. There is no available exploit.
A vulnerability marked as critical has been reported in Citrix NetScaler ADC and NetScaler Gateway up to 37.240/47.47/55.329/59.21. Affected by this vulnerability is an unknown functionality of the component Gateway. This manipulation causes memory corruption.
The identification of this vulnerability is CVE-2025-7776. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.