Sami Laiho
banner
samilaiho.com
Sami Laiho
@samilaiho.com
Keynote-speaker, Chief Research Officer, Microsoft MVP since 2011

More info: https://samilaiho.com/
If you’ve been planning to level up your cybersecurity skills, this is the moment.

Cqure Academy running their Black Week Cyber Upgrade - 40% off all online courses until December 1st.

👉 Check out the offer: cqureacademy.com/black-week-c...

#Cybersecurity #InfoSec #CQURE #CQUREacademy
November 30, 2025 at 10:40 AM
MS Teams Guest Access Can Remove Defender Protection When Users Join External
Tenants
thehackernews.com/2025/11/ms-t...
MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants
Attackers exploit Teams guest access and unprotected external tenants to bypass Microsoft Defender safeguards
thehackernews.com
November 29, 2025 at 3:42 PM
Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP
Update
thehackernews.com/2025/11/micr...
Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update
Microsoft is tightening Entra ID security with CSP updates blocking unauthorized scripts by October 2026.
thehackernews.com
November 28, 2025 at 11:25 PM
Asahi admits ransomware gang may have spilled almost 2M people's data
www.theregister.com/2025/11/27/a...
Asahi admits ransomware may have spilled data on 2M people
: Brewer finally tallies fallout from September attack as it pushes earnings into 2026
www.theregister.com
November 28, 2025 at 11:23 PM
Zendesk users targeted as Scattered Lapsus$ Hunters spin up fake support sites
www.theregister.com/2025/11/27/s...
Scattered Lapsus$ Hunters stress testing Zendesk weak spots
: ReliaQuest finds fresh crop of phishing domains and toxic tickets
www.theregister.com
November 28, 2025 at 11:21 PM
SiRcom SMART Alert (SiSA)
URL: www.cisa.gov/news-events/...
Classification: Critical, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
SiRcom SMART Alert (SiSA) | CISA
www.cisa.gov
November 28, 2025 at 6:38 AM
Festo Compact Vision System, Control Block, Controller, and Operator Unit
products
URL: www.cisa.gov/news-events/...
Classification: Critical, Solution: Workaround, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
Festo Compact Vision System, Control Block, Controller, and Operator Unit products | CISA
www.cisa.gov
November 28, 2025 at 6:37 AM
Critical vulnerabilities in Mattermost
URL: nvd.nist.gov/vuln/detail/...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9
NVD - CVE-2025-12419
nvd.nist.gov
November 28, 2025 at 6:36 AM
Old tech, new vulnerabilities: NTLM abuse, ongoing exploitation in 2025
securelist.com/ntlm-abuse-i...
How NTLM is being abused in 2025 cyberattacks
This article covers NTLM relay, credential forwarding, and other NTLM-related vulnerabilities and cyberattacks discovered in 2025.
securelist.com
November 27, 2025 at 12:15 PM
Lifetime access to AI-for-evil WormGPT 4 costs just $220
www.theregister.com/2025/11/25/w...
Lifetime access to WormGPT 4 costs just $220
: 'Ah, I see you're ready to escalate. Let's make digital destruction simple and effective.'
www.theregister.com
November 27, 2025 at 12:12 PM
Botnet takes advantage of AWS outage to smack 28 countries
www.theregister.com/2025/11/26/m...
Botnet takes advantage of AWS outage to smack 28 countries
: Even worse, it might have been a 'test run' for future attacks
www.theregister.com
November 27, 2025 at 12:11 PM
Reposted by Sami Laiho
#CTTT26 is not all about tech. Shocking, we know 😄

It is also a lot about the people and networking and forming connections you didn't have before or strengthening those you did.

Check out the video below with @d-e-a-n.bsky.social and @matetoth.hu 😉

youtu.be/MWJQCFRHtzY
CTTT26 - Speaker promo - Máté Tóth
YouTube video by Cloud Tech Tallinn
youtu.be
November 27, 2025 at 10:33 AM
Stack-based Buffer Overflow in Microsoft Azure App Gateway and Azure
Application Gateway Elevation of Privilege Vulnerability
URL: nvd.nist.gov/vuln/detail/...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
NVD - CVE-2025-64657
nvd.nist.gov
November 27, 2025 at 10:37 AM
Allowlist Bypass in Run Terminal Tool Allows Arbitrary Code Execution During
Autorun Mode in Cursor
URL: nvd.nist.gov/vuln/detail/...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
NVD - CVE-2025-62354
nvd.nist.gov
November 27, 2025 at 10:36 AM
Vulnerabilities in Zenitel TCIV-3
URL: www.cisa.gov/news-events/...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0
Zenitel TCIV-3+ | CISA
www.cisa.gov
November 27, 2025 at 10:35 AM
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Apache
Software Foundation Apache Druid
URL: nvd.nist.gov/vuln/detail/...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
NVD - CVE-2025-59390
nvd.nist.gov
November 27, 2025 at 10:34 AM