Security OperationsSAP patches three critical 9.9 S/4 HANA bugsSteve ZurierAugust 12, 2025SAP releases 19 patches on its August Security Patch Day, including three critical S/4 HANA bugs.
Application securityWordPress plugin UiCore Elements affected by arbitrary file read bugLaura FrenchAugust 12, 2025The flaw could allow an unauthenticated attacker to read any file, including wp-config.php.
IdentityThousands of Exchange Servers unpatched in light of high-severity flawSteve ZurierAugust 12, 2025Shadowserver follows up last week’s warnings from Microsoft and CISA to patch the high-severity Exchange flaw.
Vulnerability ManagementWinRAR zero-day exploited by RomCom threat groupLaura FrenchAugust 12, 2025The group sent emails from purported job seekers with a malicious archive attached.
AI/MLBlack Hat: Sloppy AI defenses take cybersecurity back to the 1990s, researchers sayPaul WagenseilAugust 11, 2025The startling lack of good security practices around AI has cybersecurity veterans wondering which decade we're living in.
Critical Infrastructure SecurityFederal cybersecurity agency issues 10 advisories for industrial control systemsSteve ZurierAugust 11, 2025Despite layoffs and funding woes, CISA continues to focus on critical infrastructure.
RansomwareAkira group using flaw patched in 2024 to attack SonicWall SSL VPNsSteve ZurierAugust 7, 2025SonicWall urges customers to update to latest versions after fears over zero-day subside.