The following advisories/alerts from Novacoast are intended to brief users and administrators on newly discovered threats, vulnerabilities, and critical software updates.
Weekly Top 10: 10.06.2025: Hackers Launch Extortion Campaign Targeting Oracle E-Business Suite Customers; GreyNoise Detects 500% Surge in Scans Targeting Palo Alto Networks Portals; Ransomware Gang Sought BBC Reporter’s Help, and More.
Hackers Launch Extortion Campaign Targeting Oracle E-Business Suite Customers; GreyNoise Detects 500% Surge in Scans…
Weekly Top 10: 09.29.2025: Emergency Directive on Cisco ASA/FTD Zero-Days; Cloudflare Mitigates 22.2 Tbps DDoS; Workforce PII Stolen in Supplier Ransomware Breach, and More.
Emergency Directive on Cisco ASA/FTD Zero-Days; Cloudflare Mitigates 22.2 Tbps DDoS; Workforce PII Stolen in Supplier…
Weekly Top 10: 09.22.2025: Microsoft’s September Updates Break SMBv1 Shares; CISA MAR: Malicious Listener Malware on Ivanti EPMM; Critical Azure Entra ID Flaw Highlights IAM Blast Radius and More.
Microsoft’s September Updates Break SMBv1 Shares; CISA MAR: Malicious Listener Malware on Ivanti EPMM; Critical Azure…
Weekly Top 10: 09.15.2025: CISA Adds a Newly Exploited CVE to the KEV Catalog; Microsoft Patch Tuesday: 81 Flaws, 2 Zero-Days; Google Chrome: Stable Channel Security Update and More.
CISA Adds a Newly Exploited CVE to the KEV Catalog; Microsoft Patch Tuesday: 81 Flaws, 2 Zero-Days; Google Chrome:…
Weekly Top 10: 09.08.2025: ViewState Zero-Day in Sitecore (CVE-2025-53690); Debunking Microsoft 365 & Identity Myths; New AI-Powered HexStrike-AI Tool Exploits Citrix Flaws, and More.
ViewState Zero-Day in Sitecore (CVE-2025-53690); Debunking Microsoft 365 & Identity Myths; New AI-Powered…
Weekly Top 10: 09.01.2025: Attackers Abuse Velociraptor IR Tool; npm ‘Nx’ Supply-Chain Attack Leaks ~20K Sensitive Files; TransUnion Breach Hits 4.4M People, and More.
Attackers Abuse Velociraptor IR Tool; npm ‘Nx’ Supply-Chain Attack Leaks ~20K Sensitive Files; Transunion Breach Hits…
Weekly Top 10: 08.25.2025: ChatGPT Downgrade Attack Highlights GPT-5 Security Risks; 15,000 Jenkins Servers at Risk from RCE Vulnerability; Cybercriminals Abuse AI Website Creation App for Phishing, and More.
ChatGPT Downgrade Attack Highlights GPT-5 Security Risks; 15,000 Jenkins Servers at Risk from RCE Vulnerability;…
Weekly Top 10: 08.18.2025: The Rise of Native Phishing: Microsoft 365 Apps Abused in Attacks; WinRAR Vulnerability Exploited by Two Different Groups; Cisco Warns of CVSS 10.0 FMC RADIUS Flaw, and More.
The Rise of Native Phishing: Microsoft 365 Apps Abused in Attacks; WinRAR Vulnerability Exploited by Two Different…
Weekly Top 10: 08.04.2025: ShinyHunters Behind Major Salesforce Data Theft; SafePay Ransomware Threatens to Leak 35TB from Ingram Micro; Shade BIOS Attack Defeats Endpoint Security Measures, and More.
ShinyHunters Behind Major Salesforce Data Theft; SafePay Ransomware Threatens to Leak 35TB from Ingram Micro; Shade…
Weekly Top 10: 07.28.2025: CryptoJacking is Dead; Coyote in the Wild: First-Ever Malware That Abuses UI Automation; SharePoint Under Siege, and More.
CryptoJacking is Dead; Coyote in the Wild: First-Ever Malware That Abuses UI Automation; SharePoint Under Siege
Weekly Top 10: 07.21.2025: Hackers Use GitHub to Host Malware Payload; Critical Cisco Zero-Day Allows Root Access Without Password; Google Patches Chrome Zero-Day Used for Sandbox Escape, and More.
Hackers Use GitHub to Host Malware Payload; Critical Cisco Zero-Day Allows Root Access Without Password; Google…
Weekly Top 10: 07.14.2025: DoNot APT Group Targets European Government Entities; McDonald’s AI Hiring System Exposed 64 Million Applicants; Malicious Browser Extensions Infect 2.3 Million Users, and More.
DoNot APT Group Targets European Government Entities; McDonald's AI Hiring System Exposed 64 Million Applicants;…