Talk With an Expert

NewsBites Cyber Security News

SANS NewsBites is a semiweekly executive summary of the most important cyber security news articles published recently. Each news item is annotated with important context provided by respected subject matter experts within the SANS community.

Filter by:

DEF CON Franklin Assists US Water Utilities at No Cost; CISA Pledges Ongoing CVE Funding; DARPA AI Cyber Challenge Winners Announced

NewsletterNewsbites
  • 12 Aug 2025
  • Volume #XXVII
  • Issue #58

Patch Now: Privilege Escalation in MS Exchange Hybrid Deployments; RCE in ControlVault Firmware on Dell Laptops; Zero-Day RCE in Adobe Experience Manager on Java Enterprise Edition

NewsletterNewsbites
  • 08 Aug 2025
  • Volume #XXVII
  • Issue #57

NVIDIA Patches Flaws in Triton Inference Server; SonicWall Investigates Reports of Attacks on Firewalls; Cursor IDE Had Multiple RCE Flaws

NewsletterNewsbites
  • 05 Aug 2025
  • Volume #XXVII
  • Issue #56

Google Project Zero Shortens Upstream Patch Gap; Saint Paul, MN Cyberattack Requires National Guard Assistance; Apple Updates and Microsoft Analysis of macOS Sploitlight

NewsletterNewsbites
  • 01 Aug 2025
  • Volume #XXVII
  • Issue #55

US Senator Requests Mandiant's Salt Typhoon Telco Reports; EU Firms Struggle to Comply With DORA; Google Offers Defensive Measures Against Scattered Spider VMWare Attacks

NewsletterNewsbites
  • 29 Jul 2025
  • Volume #XXVII
  • Issue #54

SharePoint – Assume Compromise and Implement Mitigations

NewsletterNewsbites
  • 25 Jul 2025
  • Volume #XXVII
  • Issue #53

Little-Known Microsoft "Escorts" Handle Sensitive DOD Data; Salt Typhoon Compromised US Army National Guard Network; Stuxnet Anniversary Congressional Hearing on Cyber Threats to Critical Infrastructure

NewsletterNewsbites
  • 18 Jul 2025
  • Volume #XXVII
  • Issue #52

Actively Exploited Flaws to Patch Now: CitrixBleed 2 Memory Safety, Wing FTP Server RCE; Former Employee Steals & Shares Semiconductor IP, Lands 3-Year Prison Sentence

NewsletterNewsbites
  • 15 Jul 2025
  • Volume #XXVII
  • Issue #51

UK Arrests Four Over Retailer Cyberattacks; CitrixBleed2 and Four Older Flaws Added to KEV; Patch Tuesday: Microsoft and Adobe

NewsletterNewsbites
  • 11 Jul 2025
  • Volume #XXVII
  • Issue #50

Norwegian Dam’s OT Breached via Weak Password; OpenVSX was Critically Vulnerable to Supply Chain Attack; Scam Texts Arrive After Glasgow City Council Takes Services Offline

NewsletterNewsbites
  • 01 Jul 2025
  • Volume #XXVII
  • Issue #49

Another NetScaler Flaw; Multiple Vulnerabilities in Multifunction Printers; Cisco Fixes Critical Flaws in ISE

NewsletterNewsbites
  • 27 Jun 2025
  • Volume #XXVII
  • Issue #48

Experimental MCP Server Exposed Asana Data; WordPress Motors Theme Exploited for Privilege Escalation; Linux Kernel Flaw Added to KEV

NewsletterNewsbites
  • 24 Jun 2025
  • Volume #XXVII
  • Issue #47