Cybersecurity & Privacy
U.S. CISA adds Motex LANSCOPE flaw to its Known Exploited Vulnerabilities catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Motex LANSCOPE flaw, CVE-2025-61932, to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies must fix the vulnerability by November 12, 2025.
Exploitation of Critical Adobe Commerce Flaw Puts Many eCommerce Sites at Risk - SecurityWeek Hackers are exploiting a critical-severity vulnerability in Adobe Commerce and Magento Open Source, tracked as CVE-2025-54236, with 250 attacks observed on Wednesday. Adobe released hotfixes on September 9, but less than half of the ecommerce sites have been patched.
PhantomCaptcha RAT Attack Targets Aid Groups Supporting Ukraine – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More The PhantomCaptcha RAT attack targeted aid groups and Ukrainian government entities, using malicious PDFs and fake Cloudflare captcha pages to deploy a spying tool. This highly coordinated cyberattack lasted only 24 hours but showed meticulous planning and advanced evasion techniques.
Click, Call, Compromise: Hackers Continue to Evolve Tactics Microsoft’s annual cyberthreat assessment reveals a 32% rise in identity-based attacks in 2025, primarily due to stolen credentials. Infostealers, traditionally post-exploitation tools, are now used as initial access payloads, fueling a cybercrime underground with specialized roles. Despite sophisticated counter-hacks, Microsoft emphasizes that multifactor authentication (MFA) can prevent over 99% of identity compromise attacks.
DuckDuckGo browser: privacy by default
In an online landscape often dominated by surveillance-based business models and data extraction, DuckDuckGo Browser stands out as a privacy-first alternative that prioritises simplicity and protection. For users seeking straightforward privacy without complex configurations, DuckDuckGo delivers — though its architecture and feature set differ from traditional browsers.
Orion Browser by Kagi: Privacy-centred performance
In a browser landscape dominated by data-hungry Chromium derivatives and restrictive ecosystems, Orion Browser by Kagi stands out as a WebKit-based alternative that prioritises verifiable zero telemetry, built-in content blocking, and native performance on Apple devices. For privacy-conscious users seeking Safari’s efficiency with Firefox’s extensibility and Chrome’s compatibility, Orion delivers—though not without trade-offs.
Helium Browser: privacy-centred Chromium, without the extras
Helium is a new, open-source Chromium browser that ships with strong privacy defaults and a lean interface. It removes Google services, blocks trackers and third-party cookies by default, and avoids built-in sync and password vaults to keep the attack surface small. For security-minded users, it offers a disciplined starting point with fewer emissions out of the box.
Built to fail: the structural indicators that doom CISOs
If nearly a quarter of Fortune 500 chief information security officers last just one year in the role, we need to stop asking what’s wrong with CISOs—and start asking what’s wrong with how we set them up.
Daily Cyber Threat Intelligence Briefing – Oct. 6, 2025
This post is part of our ongoing daily CTI briefing series, highlighting verified, high-impact cyber incidents from the past 48 hours. All entries meet strict inclusion criteria and have been validated across multiple authoritative sources to support operational decision-making and strategic situational awareness.
AI Sycophancy: What the Latest Research Means for Cybersecurity and Privacy
New research from Stanford University, Carnegie Mellon University and the University of Oxford highlights a behavioural risk in today’s most advanced AI systems: sycophancy. This occurs when models agree with users or flatter them, even when they are wrong. The findings are relevant to anyone who relies on AI assistants for work, decision-making or communication.