Chinese hackers attack via Ivanti & Fortinet VPNs
Targeted attacks on Japanese organizations were carried out via already known vulnerabilities in Ivanti and Fortinet VPN systems. The campaigns show once again how critical unpatched systems can be in production environments.
Microsoft closes 137 security gaps - including one zero-day
A total of 137 vulnerabilities were fixed as part of the July Patch Tuesday, including an actively exploited remote code execution vulnerability in SQL Server. Security managers should apply the updates immediately.
Diskstation ransomware group dismantled
An international law enforcement operation has stopped a criminal group that was infecting Synology NAS systems worldwide with ransomware. The gang targeted poorly secured network storage solutions in companies.
Google Chrome affected by zero-day (CVE-2025-6558)
A critical vulnerability in the GPU component of Chrome is being actively exploited. Under certain circumstances, it allows users to break out of the sandbox. Google has reacted quickly - users should update to version 138.0.7204.157 or .158 immediately.
Wing FTP Server: Remote code execution via CVE-2025-47812
A zero-byte vulnerability in the Wing FTP Server allows attackers to inject code - in the worst case, the entire server can be compromised. This vulnerability is already being actively exploited.
What happened in the hacking world this week?
Related news
How to Spot Phishing Emails and Protect Yourself
Never click on links in emails! Never open an email that seems strange to you! Never reply to an…
Why automated pentests reach their limits
Cyber risks in the financial sector
The digitization of the industry is advancing rapidly and…
What happened in the hacking world this week? (Week 33/2025)
Attack on the Canadian House of Commons
Threat Actor exploited a recently discovered Microsoft…


