[MEDIUM] – InjectEave Research Demonstrates RF-Induced Device Eavesdropping
Researchers demonstrated RF-induced side channels recovering audio and appliance states on 11 commercial devices.
Cybersecurity, AI, etc.
Red teaming (offensive research, new TTPs, exploitation techniques, PoC releases, adversary simulation findings)
Researchers demonstrated RF-induced side channels recovering audio and appliance states on 11 commercial devices.
CISA added a ConnectWise ScreenConnect authorization flaw enabling file transfer and execution in active sessions to its KEV catalog.
Attackers are exploiting an unauthenticated arbitrary-file-upload flaw in the WordPress Super Forms plugin.
The U.S. Justice Department says a Conti ransomware conspirator received a four-year prison sentence.
Mantax Otax targets Android users with ransomware, data theft, credential harvesting, and device-control capabilities.
Proofpoint identified four espionage-focused groups using BlueMoon to chain Chrome and Windows vulnerabilities.
Wiz reports active exploitation of three Artifactory vulnerabilities, including chains that yield administrative control.
Attackers are exploiting Fortinet CVE-2025-25249 to deploy PivotC2; update affected FortiOS and FortiSwitchManager releases.
CISA added an actively exploited NetScaler authentication bypass to KEV; exposed gateway and AAA deployments need urgent updates.
Cisco reports active exploitation of two Secure FMC flaws, including a CVSS 10 authentication bypass enabling root access.