Karacena Blog – News and Practical Tips

CVE‑2025‑59287: Understanding the WSUS Remote Code Execution Vulnerability and Protecting Your Organisation

Introduction In October 2025 a critical remote‑code‑execution (RCE) bug in Windows Server Update Services (WSUS) shook the security community. The flaw, tracked as CVE‑2025‑59287, resides in WSUS’s handling of encrypted AuthorizationCookie data. An unauthenticated attacker can send a specially crafted SOAP request and trigger unsafe deserialization in the WSUS service, leading to arbitrary code execution with […]

Fake LastPass & Bitwarden Breach Alerts

The latest threat landscape On October 15 2025 BleepingComputer broke the news that attackers had launched a convincing phishing campaign aimed at users of LastPass and Bitwarden—two of the most popular password managers. E‑mails arriving from domains such as lastpasspulse[.]blog and bitwardenbroadcast[.]blog falsely warned users that the companies had suffered security breaches and urged recipients […]

Agentic AI – Ally or Adversary? Navigating the New Player in Cybersecurity

Agentic artificial intelligence – AI systems capable of setting goals, devising strategies and executing actions without constant human oversight – is no longer science fiction. As generative AI exploded into the mainstream and cybersecurity platforms began to sprinkle “AI‑powered” on every dashboard, a more advanced class of agents quietly emerged. These agentic AI systems are […]

RediShell (CVE‑2025‑49844)

Overview A critical remote‑code execution (RCE) vulnerability dubbed RediShell (CVE‑2025‑49844) recently sent shockwaves through the cloud‑security community. Discovered by the Wiz research team and demonstrated at Pwn2Own Berlin, the bug has been lurking in the Redis in‑memory database for more than 13 years. It arises from a use‑after‑free flaw in Redis’s embedded Lua scripting engine. […]

Privacy-Focused Web Browsers: Firefox, LibreWolf, Tor & Focus

As part of our ongoing series on tools that protect your digital privacy and security, this edition focuses on web browsers—your gateway to the internet. While most browsers prioritize speed and convenience, few are designed with privacy as a core principle. Fortunately, several alternatives offer enhanced protection against tracking, fingerprinting, and surveillance. In this article, […]

NIS2 – a new wave of cyber obligations

If you run a business in the EU (or have clients in the EU) and the word “cybersecurity” gives you a little shiver, you’ve come to the right place. Introducing NIS2 – a new EU directive that will come into force in 2024/2025 and will affect significantly more companies than its predecessor, NIS1. But don’t […]

Our knowledge, your security – a shield in the digital reality.

Ustawienia ciastek
Cookie settings
Certain cookies are necessary for our website to function properly. We also encourage you to consent to the use of analytical cookies. They allow us to continuously improve our website. For more information, please see our Privacy Policy. Privacy Policy.
Cookie settings
Adapt
“Necessary” cookies are required for the website to function. Consent to other categories will help us improve the performance of the website. Third parties, such as Google, also store cookies. For more information, see data use and privacy. Cookies set by Google for logged in users.
Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.
We’d like to set Google Analytics cookies to help us improve our website by collecting and reporting information on how you use it. The cookies collect information in a way that does not directly identify anyone. For more information on how these cookies work please see our 'Privacy policy’.
Allows user data related to ads to be sent to Google.

There is no cookies.

Enables display of personalized ads.

There is no cookies.

Cookie settings