Sami Laiho
@samilaiho.com
đ€ 1621
đ„ 180
đ 3106
Keynote-speaker, Chief Research Officer, Microsoft MVP since 2011 More info:
https://samilaiho.com/
The who, what, and why of the attack that has shut down Strykerâs Windows network
arstechnica.com/security/202...
loading . . .
The who, what, and why of the attack that has shut down Stryker's Windows network
Company says it doesn't know how long it will take to restore its Microsoft environment.
https://arstechnica.com/security/2026/03/whats-known-about-wiper-attack-on-stryker-a-major-supplier-of-lifesaving-devices/
1 day ago
0
0
0
Poland's nuclear research centre targeted by cyberattack
www.bleepingcomputer.com/news/securit...
loading . . .
Poland's nuclear research centre targeted by cyberattack
Poland's National Centre for Nuclear Research (NCBJ) says hackers targeted its IT infrastructure, but the attack was detected and blocked before causing any impact.
https://www.bleepingcomputer.com/news/security/polands-nuclear-research-centre-targeted-by-cyberattack/
1 day ago
0
0
0
Police sinkholes 45,000 IP addresses in cybercrime crackdown
www.bleepingcomputer.com/news/securit...
loading . . .
Police sinkholes 45,000 IP addresses in cybercrime crackdown
An international law enforcement action codenamed "Operation Synergia III" has sinkholed tens of thousands of IP addresses and seized servers linked to cybercrime operations worldwide.
https://www.bleepingcomputer.com/news/security/police-sinkholes-45-000-ip-addresses-in-cybercrime-crackdown/
1 day ago
0
0
0
Fake enterprise VPN sites used to steal company credentials
www.bleepingcomputer.com/news/securit...
loading . . .
Fake enterprise VPN sites used to steal company credentials
A threat actor tracked as Storm-2561 is distributing fake enterprise VPN clients from Ivanti, Cisco, and Fortinet to steal VPN credentials from unsuspecting users.
https://www.bleepingcomputer.com/news/security/fake-enterprise-vpn-downloads-used-to-steal-company-credentials/
1 day ago
0
0
0
blog.qualys.com/vulnerabilit...
loading . . .
CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root | Qualys
Qualys TRU has discovered confused deputy vulnerabilities in AppArmor (named âCrackArmorâ) that allow unprivileged users to bypass kernel protections, escalate to root, and break container isolation. ...
https://blog.qualys.com/vulnerabilities-threat-research/2026/03/12/crackarmor-critical-apparmor-flaws-enable-local-privilege-escalation-to-root
1 day ago
0
0
0
Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation URL:
thehackernews.com/2026/03/nine...
Classification: Critical, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: None
loading . . .
Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation
Nine CrackArmor flaws in Linux AppArmor since 2017 enable root escalation and container bypass, putting 12.6M systems at risk.
https://thehackernews.com/2026/03/nine-crackarmor-flaws-in-linux-apparmor.html
1 day ago
0
0
0
Veeam Patches 7 Critical Backup
1 day ago
0
0
0
Google patches two Chrome zero-days under active attack. Update now URL:
www.malwarebytes.com/blog/news/20...
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None
loading . . .
Google patches two Chrome zero-days under active attack. Update now
Google has released an out-of-band Chrome update to patch two zero-day vulnerabilities that are already being actively exploited.
https://www.malwarebytes.com/blog/news/2026/03/google-patches-two-chrome-zero-days-under-active-attack-update-now
1 day ago
0
1
0
Stryker tells SEC that timeline for recovery from cyberattack unknown
therecord.media/stryker-tell...
loading . . .
Stryker tells SEC that timeline for recovery from cyberattack unknown
In an 8-K filing with the SEC, Stryker confirmed that the cyberattack caused a global disruption to the companyâs Microsoft environment and said external cybersecurity experts were brought in to âasse...
https://therecord.media/stryker-tells-sec-unknown-timeline-recovery
2 days ago
0
3
0
Operating Lightning takes down SocksEscort proxy network blamed for tens of millions in fraud
www.theregister.com/2026/03/12/s...
loading . . .
SocksEscort fraud-enabling proxy service taken down
: International cops stuck down 23 servers in 7 countries
https://www.theregister.com/2026/03/12/socksescort_fraud_proxy_taken_down_fbi/
2 days ago
0
1
0
How âHandalaâ Became the Face of Iranâs Hacker Counterattacks
www.wired.com/story/handal...
loading . . .
How âHandalaâ Became the Face of Iranâs Hacker Counterattacks
Amid a paralyzing breach of medical tech firm Stryker, the group has come to represent Iran's use of âhacktivismâ as cover for chaotic, retaliatory state-sponsored cyberattacks.
https://www.wired.com/story/handala-hacker-group-iran-us-israel-war/
2 days ago
0
0
0
techcommunity.microsoft.com/blog/windows...
loading . . .
Introducing the Windows NVMe-oF Initiator Preview in Windows Server Insiders Builds | Microsoft Community Hub
What Is NVMe-over-Fabrics? NVMe-over-Fabrics (NVMe-oF) extends the NVMe protocolâoriginally designed for local PCIe-attached SSDsâacross a network fabric....
https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/introducing-the-windows-nvme-of-initiator-preview-in-windows-server-insiders-bui/4501344
2 days ago
0
1
0
www.bleepingcomputer.com/news/securit...
loading . . .
New PhantomRaven NPM attack wave steals dev data via 88 packages
New attack waves from the 'PhantomRaven' supply-chain campaign are hitting the npm registry, with dozens of malicious packages that exfiltrate sensitive data from JavaScript developers.
https://www.bleepingcomputer.com/news/security/new-phantomraven-npm-attack-wave-steals-dev-data-via-88-packages/
4 days ago
0
0
0
Analyzing "Zombie Zip" Files (CVE-2026-0866)
isc.sans.edu/diary/32786?n
loading . . .
Analyzing
Analyzing "Zombie Zip" Files (CVE-2026-0866), Author: Didier Stevens
https://isc.sans.edu/diary/32786?n
4 days ago
0
0
0
Through the Lens of MDR: Analysis of KongTukeâs ClickFix Abuse of Compromised WordPress Sites
www.trendmicro.com/en_us/resear...
loading . . .
Through the Lens of MDR: Analysis of KongTukeâs ClickFix Abuse of Compromised WordPress Sites
Our analysis of an active KongTuke campaign deploying modeloRAT â malware capable of reconnaissance, command execution, and persistent access â through compromised WordPress sites and fake CAPTCHA lur...
https://www.trendmicro.com/en_us/research/26/c/kongtuke-clickfix-abuse-of-compromised-wordpress-sites.html
4 days ago
0
0
0
CISA orders feds to patch n8n RCE flaw exploited in attacks
www.bleepingcomputer.com/news/securit...
loading . . .
CISA orders feds to patch n8n RCE flaw exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies on Wednesday to patch their systems against an actively exploited n8n vulnerability.
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-n8n-rce-flaw-exploited-in-attacks/
4 days ago
0
1
1
Iran-linked hackers claim cyberattack on Albaniaâs parliament email systems
therecord.media/iran-linked-...
loading . . .
Iran-linked hackers claim cyberattack on Albaniaâs parliament email systems
In a statement shared with local media, parliament said its main systems and official website remained operational but confirmed that internal email services used by the parliamentary administration h...
https://therecord.media/iran-linked-hackers-claim-cyberattack-albania-parliament
4 days ago
0
0
0
Disobey 2026 videos out!!
youtube.com/@disobey?si=...
loading . . .
Disobey
https://youtube.com/@disobey?si=bY0wadbrqhAmcFPt
4 days ago
0
1
0
cybersecuritynews.com/stryker-cybe...
loading . . .
Stryker Cyber Attack - Hackers Claim System Breach and Device Wipe
On March 11, 2026, global medical technology giant Stryker suffered a devastating cyberattack when Iranian-linked hackers deployed wiper malware to permanently erase data across its network.
https://cybersecuritynews.com/stryker-cyber-attack/
4 days ago
0
1
0
SAP Security Patch Day - March 2026 URL:
support.sap.com/en/my-suppor...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 9.8
loading . . .
SAP Security Patch Day - March 2026
SAP security patch day bulletin
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/march-2026.html
4 days ago
0
0
0
krebsonsecurity.com/2026/03/iran...
loading . . .
Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
A hacktivist group with links to Iran's intelligence agencies is claiming responsibility for a data-wiping attack against Stryker, a global medical technology company based in Michigan. News reports o...
https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/
5 days ago
0
1
0
securityaffairs.com/189230/apt/a...
loading . . .
APT28 conducts long-term espionage on Ukrainian forces using custom malware
APT28 used BEARDSHELL and COVENANT malware to spy on Ukrainian military personnel, enabling long-term surveillance since April 2024.
https://securityaffairs.com/189230/apt/apt28-conducts-long-term-espionage-on-ukrainian-forces-using-custom-malware.html
5 days ago
0
0
0
BeatBanker: A dualâmode Android Trojan
securelist.com/beatbanker-m...
loading . . .
BeatBanker: both banker and miner for Android
Kaspersky researchers identified a new Android Trojan dubbed BeatBanker targeting Brazil, posing as government apps and Google Play Store, and capable of both crypto mining and stealing banking data.
https://securelist.com/beatbanker-miner-and-banker/119121/
5 days ago
0
1
0
Pre-Authentication SQL Injection in FortiClient EMS
bishopfox.com/blog/cve-202...
loading . . .
Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 -âŠ
FortiClient EMS 7.4.4 has a pre-auth SQL injection (CVSS 9.1) in multi-tenant routing that lets attackers inject SQL via a crafted Site HTTP header.
https://bishopfox.com/blog/cve-2026-21643-pre-authentication-sql-injection-in-forticlient-ems-7-4-4
5 days ago
0
1
0
HPE warns of critical AOS-CX flaw allowing admin password resets
www.bleepingcomputer.com/news/securit...
loading . . .
HPE warns of critical AOS-CX flaw allowing admin password resets
Hewlett Packard Enterprise (HPE) has patched multiple security vulnerabilities in the Aruba Networking AOS-CX operating system, including several authentication and code execution issues.
https://www.bleepingcomputer.com/news/security/hpe-warns-of-critical-aos-cx-flaw-allowing-admin-password-resets/
5 days ago
0
1
0
research.checkpoint.com/2026/iranian...
loading . . .
Iranian MOIS Actors & the Cyber Crime Connection - Check Point Research
Iranâlinked MOIS threat actors increasingly leverage cybercrime tools, malware, and ransomware ecosystems to enhance capability, obscure attribution, and advance state objectives.
https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connection/
5 days ago
0
0
0
Polish cops bust alleged teen DDoS kit sellers â youngest just 12
www.theregister.com/2026/03/10/p...
loading . . .
Polish cyber police busts gang of alleged teen DDoS peddlers
: Kids profited from tools used to attack popular websites, say officials
https://www.theregister.com/2026/03/10/poland_ddos_teens_bust/
5 days ago
0
1
0
Salesforce Sounds Alarm Over Fresh Data Extortion Campaign
www.databreachtoday.com/salesforce-s...
loading . . .
Salesforce Sounds Alarm Over Fresh Data Extortion Campaign
A prolific and noisy cybercrime gang with a penchant for stealing Salesforce customers' data and holding it ransom is taking advantage of misconfigured guest
https://www.databreachtoday.com/salesforce-sounds-alarm-over-fresh-data-extortion-campaign-a-30958
5 days ago
0
0
0
Warning: Critical Missing Authentication Vulnerability in Nginx UI Leads to Full System Compromise, Patch Immediately! URL:
ccb.belgium.be/advisories/w...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8
loading . . .
Warning: Critical Missing Authentication Vulnerability in Nginx UI Leads to Full System Compromise, Patch Immediately! | CCB Safeonweb
https://ccb.belgium.be/advisories/warning-critical-missing-authentication-vulnerability-nginx-ui-leads-full-system
5 days ago
0
1
0
HPESBNW05027 rev.1 - HPE Aruba Networking AOS-CX, Multiple Vulnerabilities URL:
support.hpe.com/hpesc/public...
loading . . .
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05027en_us
5 days ago
0
1
0
www.bleepingcomputer.com/news/microso...
loading . . .
Windows 11 KB5079473 & KB5078883 cumulative updates released
Microsoft has released Windows 11 KB5079473 and KB5078883 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5079473-and-kb5078883-cumulative-updates-released/
5 days ago
0
1
0
www.bleepingcomputer.com/news/microso...
loading . . .
Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
Today is Microsoft's March 2026Â Patch Tuesday with security updates for 79 flaws, including 2Â publicly disclosed zero-day vulnerabilities.
https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/
5 days ago
0
1
0
www.bleepingcomputer.com/news/microso...
loading . . .
Microsoft releases Windows 10 KB5078885 extended security update
Microsoft has released the Windows 10 KB5078885 extended security update to fix the March 2026 Patch Tuesday vulnerabilities, including 2 zero-days and an issue that prevent some devices from shutting...
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5078885-extended-security-update/
5 days ago
0
0
0
ShinyHunters claims more high-profile victims in latest Salesforce customers data heist
www.theregister.com/2026/03/09/s...
loading . . .
ShinyHunters claims yet another Salesforce customers breach
: And they abused a Mandiant-developed open source tool in the attacks
https://www.theregister.com/2026/03/09/shinyhunters_claims_more_highprofile_victims/
6 days ago
0
2
2
Ericsson US discloses data breach after service provider hack
www.bleepingcomputer.com/news/securit...
loading . . .
Ericsson US discloses data breach after service provider hack
Ericsson Inc., the U.S. subsidiary of Swedish networking and telecommunications giant Ericsson, says attackers have stolen data belonging to over 15,000Â employees and customers after hacking one of it...
https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/
6 days ago
1
1
0
Russian cybercrims phish their way into officials' Signal and WhatsApp accounts
www.theregister.com/2026/03/09/d...
loading . . .
Russian crims phish way into Signal and WhatsApp accounts
: Dutch spies flag large-scale campaign to hijack secure messaging accounts
https://www.theregister.com/2026/03/09/dutch_spies_say_russian_cybercrims/
6 days ago
0
1
0
China-Nexus Activity Against Qatar Observed Amid Expanding Regional Tensions
blog.checkpoint.com/research/chi...
loading . . .
ChinaâNexus APT Targets Qatar
Chineseânexus threat actors are accelerating cyberâespionage targeting Qatar, deploying PlugX, Rustâbased loaders, and Cobalt Strike with conflictâthemed lures. Explore how APT groups like Camaro Drag...
https://blog.checkpoint.com/research/china-nexus-activity-against-qatar-observed-amid-expanding-regional-tensions/
6 days ago
0
0
0
Massive GitHub malware operation spreads BoryptGrab stealer
securityaffairs.com/189110/malwa...
loading . . .
Massive GitHub malware operation spreads BoryptGrab stealer
Experts found BoryptGrab stealer spreading through 100+ GitHub repositories, stealing browser data, crypto wallets, system info, and more
https://securityaffairs.com/189110/malware/massive-github-malware-operation-spreads-boryptgrab-stealer.html
7 days ago
0
0
0
krebsonsecurity.com/2026/03/how-...
loading . . .
How AI Assistants are Moving the Security Goalposts
AI-based assistants or "agents" -- autonomous programs that have access to the user's computer, files, online services and can automate virtually any task -- are growing in popularity with developers ...
https://krebsonsecurity.com/2026/03/how-ai-assistants-are-moving-the-security-goalposts/
7 days ago
0
1
0
EU Auto Rules Shift Gears on Cybersecurity Standards
www.darkreading.com/cyber-risk/e...
loading . . .
EU Auto Rules Shift Gears on Cybersecurity Standards
The European Union is taking new precautions as climate change and cybersecurity threats rise across the automotive industry.
https://www.darkreading.com/cyber-risk/eu-auto-rules-shift-gears-on-cybersecurity-standards
8 days ago
0
1
0
One click on this fake Google Meet update can give attackers control of your PC
www.malwarebytes.com/blog/threat-...
loading . . .
One click on this fake Google Meet update can give attackers control of your PC
We found a fake Google Meet update that enrolls the victim's Windows PC in an attacker's device management system.
https://www.malwarebytes.com/blog/threat-intel/2026/03/one-click-on-this-fake-google-meet-update-can-give-attackers-control-of-your-pc
8 days ago
0
1
0
Mobile spyware campaign impersonates Israel's Red Alert rocket warning system
www.acronis.com/en/tru/posts...
loading . . .
Mobile spyware campaign impersonates Israel's Red Alert rocket warning system
Acronis Threat Research Unit (TRU) has identified a targeted campaign distributing a trojanized version of the Red Alert rocket warning Android app to Israeli users via SMS messages impersonating offi...
https://www.acronis.com/en/tru/posts/mobile-spyware-campaign-impersonates-israels-red-alert-rocket-warning-system/
8 days ago
0
1
0
Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition
cloud.google.com/blog/topics/...
loading . . .
Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition | Google Cloud Blog
Proactive recommendations organizations must prioritize to protect against destructive attacks within an environment.
https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacks/
8 days ago
0
0
0
securelist.com/vulnerabilit...
The 4th quarter of 2025 went down as one of the most intense periods on record for, critical vuln disclosures, hitting popular libraries and mainstream applications. Several vulnerabilities were picked up by attackers and exploited in the wild almost immediately.
loading . . .
Vulnerability landscape in Q4 2025
This report provides statistical data on published vulnerabilities and exploits we researched during Q4 2025. It also includes summary data on the use of C2 frameworks in APT attacks.
https://securelist.com/vulnerabilities-and-exploits-in-q4-2025/119105/
8 days ago
0
0
0
Patch, track, repeat: The 2025 CVE retrospective
blog.talosintelligence.com/patch-track-...
loading . . .
Patch, track, repeat: The 2025 CVE retrospective
Thor analyzes CVE data from 2025 and provides recommendations for where and how organizations should strengthen their defenses.
https://blog.talosintelligence.com/patch-track-repeat-the-2025-cve-retrospective/
8 days ago
0
0
0
Wikipedia hit by self-propagating JavaScript worm that vandalized pages
www.bleepingcomputer.com/news/securit...
loading . . .
Wikipedia hit by self-propagating JavaScript worm that vandalized pages
The Wikimedia Foundation suffered a security incident today after a self-propagating JavaScript worm began vandalizing pages and modifying user scripts across multiple wikis.
https://www.bleepingcomputer.com/news/security/wikipedia-hit-by-self-propagating-javascript-worm-that-vandalized-pages/
8 days ago
0
1
0
www.bleepingcomputer.com/news/securit...
loading . . .
FBI investigates breach of surveillance and wiretap systems
The U.S. Federal Bureau of Investigation (FBI) confirmed on Thursday that it's investigating a breach that affected systems used to manage surveillance and wiretap warrants.
https://www.bleepingcomputer.com/news/security/fbi-investigates-breach-of-surveillance-and-wiretap-systems/
9 days ago
0
1
0
securityaffairs.com/188928/secur...
loading . . .
Google uncovers Coruna iOS Exploit Kit targeting iOS 13â17.2.1
Google warns of the Coruna iOS exploit kit, using 23 exploits across five chains to target iPhones running iOS 13â17.2.1.
https://securityaffairs.com/188928/security/google-uncovers-coruna-ios-exploit-kit-targeting-ios-13-17-2-1.html
10 days ago
0
0
0
www.csoonline.com/article/4141...
loading . . .
LeakBase marketplace unplugged by cops in 14 countries
The action coordinated by Europol seized two of the group's domains and captured the forum's data, as well as making arrests.
https://www.csoonline.com/article/4141400/leakbase-marketplace-unplugged-by-cops-in-14-countries.html
10 days ago
0
0
0
LatAm Now Faces 2x More Cyberattacks Than US
www.darkreading.com/threat-intel...
loading . . .
LatAm Now Faces 2x More Cyberattacks Than US
Much of Central and South America struggles with cybersecurity maturity, and hackers are taking advantage.
https://www.darkreading.com/threat-intelligence/latam-2x-more-cyberattacks-us
10 days ago
0
0
0
Load more
feeds!
log in