Expert In the Cloud
  • Welcome to My Cloud & Security Hub
  • About Me
  • Cloud
    • AWS
    • MICROSOFT
      • EXCHANGE
        • EXCHANGE 2010
        • EXCHANGE 2013
        • EXCHANGE 2016
        • EXCHANGE 2019
      • OFFICE 365
        • Azure
        • Azure Powershell
        • OneDrive
        • Outlook
        • Portal Management
        • SharePoint
        • Skype for Business
        • Teams
  • Contact Us
  • HYPERVISORS
    • VMWare
  • NETWORK & SECURITY
    • NETWORK
    • SECURITY
      • SONICWALL
      • FORTINET
        • FORTIVM
  • SERVER
    • Powershell
    • SQL
  • BLOGS
    • BLOGS

Month: November 2025

Key Update: CVE-2021-26829 Added to CISA KEV

November 30, 2025 Faeem 0

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2021-26829 — a cross-site scripting (XSS) flaw in OpenPLC ScadaBR — to its Known Exploited […]

Legacy Python Bootstrap Scripts Pose Domain‑Takeover Risk in PyPI Packages

November 28, 2025 Faeem 0

Researchers at ReversingLabs have uncovered a latent supply‑chain vulnerability in several Python packages that still ship legacy bootstrap.py scripts tied to the discontinued Distribute project. […]

Malicious LLMs Like WormGPT 4 and KawaiiGPT Are Accelerating Cybercrime — What Security Teams Must Know

November 28, 2025 Faeem 0

The emergence of unrestricted large language models (LLMs) like WormGPT 4 and KawaiiGPT marks a turning point in cybercrime tooling. These models are specifically tuned […]

ASUS CVE-2025-59366 Alert: Critical Auth Bypass in AiCloud Routers — What You Need to Do Now

November 26, 2025 Faeem 0

ASUS has issued a firmware update to patch nine vulnerabilities, including a critical authentication bypass flaw (CVE-2025-59366) affecting routers with AiCloud enabled. This flaw allows […]

RomCom + SocGholish: Fake Updates Deliver Mythic Agent Malware

November 26, 2025 Faeem 0

A new campaign highlights the convergence of RomCom (a Russia‑aligned threat actor) and SocGholish (aka FakeUpdates), a long‑running JavaScript loader used by multiple cybercrime groups. […]

Sha1‑Hulud Second Wave — Executive Summary and Immediate Risk

November 24, 2025 Faeem 0

What happened: A new wave of Sha1‑Hulud supply‑chain attacks trojanized hundreds of npm packages (uploaded Nov 21–23, 2025) to run malicious code during the preinstall […]

Summary of the Windows 11 24H2 XAML registration bug

November 24, 2025 Faeem 0

Microsoft confirmed a timing bug in Windows 11 24H2 cumulative updates (since July 2025) that prevents key XAML packages from registering quickly enough after update/install. […]

WhatsApp enumeration: how researchers scraped 3.5 billion accounts and what it means for defenders

November 20, 2025 Faeem 0

Researchers at the University of Vienna demonstrated a powerful account‑enumeration technique against WhatsApp that allowed them to check hundreds of millions of phone numbers per […]

Sneaky2FA Adds Browser‑in‑the‑Browser to Its Phishing Toolkit — Why Microsoft 365 Users Are at Heightened Risk

November 20, 2025 Faeem 0

Sneaky2FA’s adoption of the browser‑in‑the‑browser (BitB) trick marks a meaningful escalation in phishing sophistication. The kit already automated real‑time MFA relay (AitM) and SVG‑based UI […]

WrtHug Hijacks EoL ASUS Routers at Scale — What Network Owners Need to Know

November 19, 2025 Faeem 0

SecurityScorecard’s STRIKE team has uncovered Operation WrtHug, a large‑scale campaign that has seized tens of thousands of end‑of‑life ASUS WRT routers worldwide by chaining several […]

Posts pagination

1 2 3 »

Recent Posts

  • CVE‑2026‑39987 Exploited: Blockchain‑Powered Backdoor Targets AI Developers April 17, 2026
  • Operation PowerOFF: Global Crackdown on DDoS-for-Hire Services April 17, 2026
  • AI in Recruitment: When Candidates and Recruiters Both Use Algorithms April 17, 2026
  • How Each Cloud Giant Is Leveraging AI April 16, 2026
  • ThreatsDay Bulletin: Defender 0‑Day, SonicWall Brute‑Force, and Supply Chain Chaos April 16, 2026

Categories

  • AWS
  • Azure
  • AZURE
  • Azure Powershell
  • BLOGS
  • Calendar
  • EXCHANGE
  • EXCHANGE 2010
  • EXCHANGE 2013
  • EXCHANGE 2016
  • EXCHANGE 2019
  • FORTINET
  • FORTIVM
  • Hypervisors
  • MICROSOFT
  • NETWORK
  • NETWORK & SECURITY
  • OFFICE 365
  • OneDrive
  • Outlook
  • Portal Management
  • Powershell
  • SECURITY
  • Server
  • SharePoint
  • Skype for Business
  • SONICWALL
  • SQL
  • Teams
  • Uncategorized
  • VMWare
  • Windows
Follow Us
  • LinkedIn
  • Facebook
Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Copyright © 2026 | WordPress Theme by MH Themes