<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security News &#8211; Brandefense</title>
	<atom:link href="https://brandefense.io/category/security-news/feed/" rel="self" type="application/rss+xml" />
	<link>https://brandefense.io</link>
	<description>Digital Risk Protection Services Platform  &#124; Brandefense</description>
	<lastBuildDate>Wed, 10 Dec 2025 14:38:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://brandefense.io/wp-content/uploads/2021/05/logo_black-150x150.png</url>
	<title>Security News &#8211; Brandefense</title>
	<link>https://brandefense.io</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>React2Shell — The Day 5 Reality Check</title>
		<link>https://brandefense.io/security-news/react2shell-the-day-5-reality-check/</link>
		
		<dc:creator><![CDATA[BRANDEFENSE]]></dc:creator>
		<pubDate>Wed, 10 Dec 2025 14:38:36 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[brand protection]]></category>
		<category><![CDATA[ciso guide]]></category>
		<category><![CDATA[cyber resilience]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[drps]]></category>
		<category><![CDATA[executive people]]></category>
		<category><![CDATA[exposure management]]></category>
		<category><![CDATA[fraud monitoring]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[software supply chain]]></category>
		<category><![CDATA[supply chain]]></category>
		<category><![CDATA[supply chain management]]></category>
		<category><![CDATA[trends]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=33730</guid>

					<description><![CDATA[<p>React2Shell (CVE-2025-55182) is a pre-auth RCE vulnerability in React Server Components with a CVSS 10.0 score. This blog examines the first five days after disclosure, how attackers weaponized it, and the urgent actions organizations must take to reduce exposure.</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/react2shell-the-day-5-reality-check/">React2Shell — The Day 5 Reality Check</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Data Breach at Internet Archive Exposes 31 Million User Records</title>
		<link>https://brandefense.io/security-news/data-breach-at-internet-archive-exposes-31-million-user-records/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Fri, 11 Oct 2024 08:31:31 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[internet archive]]></category>
		<category><![CDATA[leak]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=31174</guid>

					<description><![CDATA[<p>A recent cyber attack has resulted in a significant data breach at the Internet Archive, impacting 31 million users. The breach was made public after a JavaScript alert appeared on the website, confirming the compromise of the site’s authentication database. The stolen database includes sensitive user information such as email addresses, bcrypt-hashed passwords, and other...</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/data-breach-at-internet-archive-exposes-31-million-user-records/">Data Breach at Internet Archive Exposes 31 Million User Records</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CISA Warns of Active Exploitation in SonicWall, Linux Kernel, and ImageMagick Vulnerabilities</title>
		<link>https://brandefense.io/security-news/cisa-warns-of-active-exploitation-in-sonicwall-linux-kernel-and-imagemagick-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Thu, 12 Sep 2024 07:30:16 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Active Exploitation]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[ImageMagick]]></category>
		<category><![CDATA[Linux Kernel]]></category>
		<category><![CDATA[SonicWall]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=29495</guid>

					<description><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the active exploitation of three critical vulnerabilities, which have been added to its Known Exploited Vulnerabilities (KEV) catalog. This warning emphasizes the urgent need for Federal Civilian Executive Branch (FCEB) agencies to patch affected systems by September 30, 2024, to protect against...</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/cisa-warns-of-active-exploitation-in-sonicwall-linux-kernel-and-imagemagick-vulnerabilities/">CISA Warns of Active Exploitation in SonicWall, Linux Kernel, and ImageMagick Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CVE-2024-8105: Critical UEFI Vulnerability</title>
		<link>https://brandefense.io/security-news/cve-2024-8105-critical-uefi-vulnerability/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Thu, 05 Sep 2024 07:01:14 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[bios]]></category>
		<category><![CDATA[CVE-2024-8105]]></category>
		<category><![CDATA[pkfai]]></category>
		<category><![CDATA[uefi]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=29234</guid>

					<description><![CDATA[<p>CVE-2024-8105, also known as &#8220;PKfai,&#8221; is a significant vulnerability identified within the UEFI (Unified Extensible Firmware Interface) ecosystem. With a CVSS score of 8.2, this flaw weakens critical UEFI security mechanisms, making systems vulnerable to malicious attacks that can bypass fundamental protections like Secure Boot. Overview of UEFI and Its Role: UEFI is a vital...</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/cve-2024-8105-critical-uefi-vulnerability/">CVE-2024-8105: Critical UEFI Vulnerability</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Actively Exploited Two New Zero-Day Vulnerabilities Hit Google Chrome</title>
		<link>https://brandefense.io/security-news/actively-exploited-two-new-zero-day-vulnerabilities-hit-google-chrome/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Wed, 28 Aug 2024 12:53:40 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[google vulnerability]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Zero-Day]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=28830</guid>

					<description><![CDATA[<p>Google has recently confirmed that two zero-day vulnerabilities, CVE-2024-7965 and CVE-2024-7971, have been actively exploited in the wild, posing a significant threat to Chrome users. CVE-2024-7965, with a CVSS score of 8.8, affects the V8 JavaScript engine in Chrome. This flaw involves improper implementation within the engine, enabling remote attackers to exploit heap corruption through...</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/actively-exploited-two-new-zero-day-vulnerabilities-hit-google-chrome/">Actively Exploited Two New Zero-Day Vulnerabilities Hit Google Chrome</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CVE-2024-38193: Microsoft Patches Critical Zero-Day Exploit Used by North Korea&#8217;s Lazarus Group</title>
		<link>https://brandefense.io/security-news/microsoft-patches-critical-zero-day-exploit-used-by-north-koreas-lazarus-group/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Wed, 21 Aug 2024 14:59:42 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[apt group]]></category>
		<category><![CDATA[dark web]]></category>
		<category><![CDATA[lazarus]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[north korea]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Zero-Day]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=28997</guid>

					<description><![CDATA[<p>A new vulnerability discovered in the Microsoft Windows operating system has been exploited as a zero-day attack by the Lazarus Group, a state-sponsored actor affiliated with North Korea. This vulnerability tracked as CVE-2024-38193, is identified as an elevation of a privilege bug in the Windows Ancillary Function Driver (AFD.sys) file for WinSock. The vulnerability was...</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/microsoft-patches-critical-zero-day-exploit-used-by-north-koreas-lazarus-group/">CVE-2024-38193: Microsoft Patches Critical Zero-Day Exploit Used by North Korea&#8217;s Lazarus Group</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>August&#8217;24 Patch Tuesday: Six Actively Exploited Zero-Day Vulnerabilities</title>
		<link>https://brandefense.io/security-news/august24-patch-tuesday-six-actively-exploited-zero-day-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Wed, 14 Aug 2024 11:36:06 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[dark web]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Zero-Day]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=28941</guid>

					<description><![CDATA[<p>In its August 2024 Patch Tuesday release, Microsoft addressed 88 vulnerabilities, including seven critical flaws and ten zero-day vulnerabilities. Notably, six of these zero-day vulnerabilities are currently being actively exploited in the wild, underscoring the urgent need for organizations to implement patches without delay. Comprehensive Update Scope This extensive update affects a wide range of...</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/august24-patch-tuesday-six-actively-exploited-zero-day-vulnerabilities/">August&#8217;24 Patch Tuesday: Six Actively Exploited Zero-Day Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Critical Zero-Day Kernel Vulnerability Actively Exploited in Android Devices</title>
		<link>https://brandefense.io/security-news/critical-zero-day-kernel-vulnerability-actively-exploited-in-android-devices/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Wed, 07 Aug 2024 11:46:41 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[kernel vulnerability]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Zero-Day]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=28800</guid>

					<description><![CDATA[<p>Google’s recent Android security updates have revealed a critical zero-day vulnerability, CVE-2024-36971, which has been actively exploited in targeted attacks. This flaw, found in the network route management of the Linux kernel, is a use-after-free (UAF) vulnerability that can lead to memory corruption. If successfully exploited, this vulnerability could allow attackers to execute arbitrary code...</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/critical-zero-day-kernel-vulnerability-actively-exploited-in-android-devices/">Critical Zero-Day Kernel Vulnerability Actively Exploited in Android Devices</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>First Days, First Shots: Scammers Exploit Paris Olympics with 48GB Mobile Data</title>
		<link>https://brandefense.io/security-news/first-days-first-shots-scammers-exploit-paris-olympics-with-48gb-mobile-data/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Mon, 29 Jul 2024 11:32:42 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[mobile data]]></category>
		<category><![CDATA[paris 2024]]></category>
		<category><![CDATA[paris olympics]]></category>
		<category><![CDATA[scam]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=28550</guid>

					<description><![CDATA[<p>As the Paris Olympics are set to begin this weekend, threat actors are attempting to exploit the situation for their own gain. They have initiated fraudulent activities aimed at profiting from tickets and products related to the event. With approximately 15.3 million visitors expected in Paris, scammers are taking advantage of the excitement and enthusiasm...</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/first-days-first-shots-scammers-exploit-paris-olympics-with-48gb-mobile-data/">First Days, First Shots: Scammers Exploit Paris Olympics with 48GB Mobile Data</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>BlastRADIUS Vulnerability (CVE-2024-3596) Exposes RADIUS Protocol to Critical Network Security Risk</title>
		<link>https://brandefense.io/security-news/blastradius-vulnerability-cve-2024-3596-exposes-radius-protocol-to-critical-network-security-risk/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Wed, 10 Jul 2024 14:20:37 +0000</pubDate>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[blastradius]]></category>
		<category><![CDATA[cve-2024-3596]]></category>
		<category><![CDATA[radius]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=28076</guid>

					<description><![CDATA[<p>A newly identified vulnerability&#160;(CVE-2024-3596), dubbed &#8220;BlastRADIUS,&#8221; has been discovered in the RADIUS protocol, posing a critical risk to network security. Researchers from the University of California, San Diego, have published a practical exploit for this flaw, marking the first successful demonstration of an attack against the RADIUS protocol. The FreeRADIUS Server Project has promptly responded...</p>
<p>The post <a rel="nofollow" href="https://brandefense.io/security-news/blastradius-vulnerability-cve-2024-3596-exposes-radius-protocol-to-critical-network-security-risk/">BlastRADIUS Vulnerability (CVE-2024-3596) Exposes RADIUS Protocol to Critical Network Security Risk</a> appeared first on <a rel="nofollow" href="https://brandefense.io">Brandefense</a>.</p>
]]></description>
		
		
		
			</item>
	</channel>
</rss>
