News – November 2025


  • Cloudflare outage impacts thousands, disrupts transit systems, ChatGPT, X and more

    November 18, 2025

    A widely used Internet infrastructure company said that it has resolved an issue that led to outages impacting users of everything from ChatGPT and the online game, “League of Legends,” to the New Jersey Transit system early Tuesday. Around 10 a.m. ET, Cloudflare said it was “continuing to monitor for errors to ensure all services are ...

  • Active Exploitation Reported for CVE-2025-11001 in 7-Zip

    November 18, 2025

    Active exploitation of CVE-2025-11001 has been observed in the wild. A security researcher has also publicly released a proof-of-concept (PoC) exploit for CVE-2025-11001. The PoC allows attackers to abuse symbolic-link handling to write files outside of the intended extraction folder, which in some scenarios, can enable arbitrary code execution. Read more… Source: NHS Digital Sign up for the Cyber ...

  • Microsoft says Azure was hit with a massive DDoS attack launched from over 500,000 IP addresses

    November 18, 2025

    Microsoft has said it successfully mitigated, “the largest DDoS attack ever observed in the cloud” after cybercriminals running the Aisuru botnet targeted a single endpoint, located in Australia. The attack was a sight to behold: more than 500,000 source IPs, across various regions, descended upon the endpoint, delivering a multi-vector Distributed Denial of Service (DDoS) attack ...

  • Google Releases Security Update for Chrome

    November 18, 2025

    Google has released security updates for Chrome to address two high severity vulnerabilities in the V8 JavaScript engine. CVE-2025-13223 – Type Confusion in V8 – High severity – Google is aware an exploit exists in the wild. CVE-2025-13224 – Type Confusion in V8 – High severity Read more… Source: NHS Digital Sign up for the Cyber Security Review Newsletter The latest ...

  • Surveillance tech provider Protei was hacked, its data stolen, and its website defaced

    November 17, 2025

    A Russian telecom company that develops technology to allow phone and internet companies to conduct web surveillance and censorship was hacked, had its website defaced, and had data stolen from its servers, TechCrunch has learned. Founded in Russia, Protei makes telecommunications systems for phone and internet providers across dozens of countries, including Bahrain, Italy, Kazakhstan, Mexico, ...

  • Twitter hacker ordered to pay back £4.1m worth of Bitcoin

    November 17, 2025

    A Twitter hacker who breached the accounts of celebrities including Barack Obama and Jeff Bezos has been forced to hand over £4million. Joseph James O’Connor, 26, was jailed in the US for the hacks which involved scamming people out of Bitcoin and threatening celebrities with the release of personal images and messages. Now the CPS Proceeds ...

  • Five major changes to the regulation of cybersecurity in the UK under the Cyber Security and Resilience Bill

    November 16, 2025

    As the UK Government has recognized, cyber incidents—such as Jaguar Land Rover, Marks and Spencer, Royal Mail and the British Library—are costing UK businesses billions annually and causing severe disruption. The Government recognizes that cybersecurity is a critical enabler of economic growth (“we cannot have growth without stability”), and that the current laws have “fallen out ...

  • NATO Communications and Information Agency hosts DCOS Cyber SHAPE at Satellite Ground Station Kester

    November 14, 2025

    On 14 November 2025, NATO Communications and Information Agency (NCIA) hosted the Deputy Chief of Staff Cyberspace, Supreme Headquarters Allied Powers Europe (SHAPE), Major General Rainer Beeck, for an official visit to NATO’s Satellite Ground Station (SGS) in Kester, Belgium. Major General Beeck and the SHAPE delegation were welcomed by NCIA General Manager, Ludwig Decamps, NCIA ...

  • Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT

    November 14, 2025

    Palo Alto Unit 42 researchers have identified two interconnected malware campaigns active throughout 2025, using large-scale brand impersonation to deliver Gh0st remote access Trojan (RAT) variants to Chinese-speaking users. From the first campaign to the second, the adversary advanced from simple droppers to complex, multi-stage infection chains that misuse legitimate, signed software to bypass modern defenses. ...

  • Fortinet Releases Security Advisory for Relative Path Traversal Vulnerability Affecting FortiWeb Products

    November 14, 2025

    CISA is aware of exploitation of a newly disclosed vulnerability, CVE-2025-64446, in Fortinet FortiWeb, a web application firewall. This vulnerability affects the following FortiWeb versions:1 8.0.0 through 8.0.1 7.6.0 through 7.6.4 7.4.0 through 7.4.9 7.2.0 through 7.2.11 7.0.0 through 7.0.11 CVE-2025-64446 is a relative path traversal vulnerability CWE-23: Relative Path Traversal that may allow an unauthenticated ...