Sami Laiho
@samilaiho.com
1.6K followers
170 following
2.2K posts
Keynote-speaker, Chief Research Officer, Microsoft MVP since 2011
More info: https://samilaiho.com/
Posts
Media
Videos
Starter Packs
Sami Laiho
@samilaiho.com
· 10h
Hackers exploiting zero-day in Gladinet file sharing software
Threat actors are exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet CentreStack and Triofox products, which allows a local attacker to access system files without authentication.
www.bleepingcomputer.com
Sami Laiho
@samilaiho.com
· 11h
Apple now offers $2 million for zero-click RCE vulnerabilities
Apple is announcing a major expansion and redesign of its bug bounty program, doubling maximum payouts, adding new research categories, and introducing a more transparent reward structure.
www.bleepingcomputer.com
Reposted by Sami Laiho
Sami Laiho
@samilaiho.com
· 1d
DDoS Botnet Aisuru Blankets US ISPs in Record DDoS
The world's largest and most disruptive botnet is now drawing a majority of its firepower from compromised Internet-of-Things (IoT) devices hosted on U.S. Internet providers like AT&T, Comcast and Ver...
krebsonsecurity.com
Sami Laiho
@samilaiho.com
· 1d
Reposted by Sami Laiho
Sami Laiho
@samilaiho.com
· 1d
Sami Laiho
@samilaiho.com
· 1d
Responding to Cloud Incidents: A Step-by-Step Guide From the 2025 Unit 42 Global Incident Response Report
Cloud breaches are rising. This step-by-step guide from Unit 42 shows how to investigate, contain and recover from cloud-based attacks.
unit42.paloaltonetworks.com
Sami Laiho
@samilaiho.com
· 1d
Global Cyber Threats September 2025: Attack Volumes Ease Slightly, but GenAI Risks Intensify as Ransomware Surges 46% - Check Point Blog
In September 2025, the global cyber threat landscape reflected a temporary stabilization in overall attack volumes — yet beneath the surface, ransomware
blog.checkpoint.com
Sami Laiho
@samilaiho.com
· 1d
Discord says 70,000 users had government IDs exposed in third-party breach
The social media platform Discord said about 70,000 users had their government IDs stolen by cybercriminals, as the company sought to dispel claims by the purported hackers of a larger breach.
therecord.media
Sami Laiho
@samilaiho.com
· 1d
Sami Laiho
@samilaiho.com
· 1d
Arbitrary Code Execution in Grafana Image Renderer Plugin | Grafana Labs
Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath para...
grafana.com