Aggregator
Joint cyber security advisory on worldwide network compromises by People’s Republic of China state-sponsored actors
Allied spy agencies blame 3 Chinese tech companies for Salt Typhoon attacks
Alleged Data Breach Exposes Sensitive Login Records from Willrich Precision Instrument Company, Inc.
Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424
21.98 万起!小鹏 P7 要让 Model 3 和小米 SU7 睡不着觉
Месяц в системах незамеченными, 10 тысяч пострадавших пользователей. Как вымогатели атаковали создателей MATLAB и парализовали научные проекты
Nevada “Network Security Incident” Shuts Down State Offices and Services
DragonForce
You must login to view this content
DragonForce
You must login to view this content
Docker security advisory (AV25–546)
Cline: Vulnerable To Data Exfiltration And How To Protect Your Data
Cline is quite a popular AI coding agent, according to the product website it has 2+ million downloads and over 47k stars on GitHub.
Unfortunately, Cline is vulnerable to data exfiltration through the rendering of markdown images from untrusted domains in the chat box.
This allows an adversary to exfiltrate sensitive user information during a prompt injection attack by reading sensitive data (e.g. .env file) and appending its contents to the URL of an image.
Anthropic Disrupts AI-Powered Cyberattacks Automating Theft and Extortion Across Critical Sectors
Rhysida
You must login to view this content
韩国禁止中小学生课堂使用手机
Qilin
You must login to view this content
ShadowSilk Campaign Targets Central Asian Governments
Хакеры получили свою премию «Оскар». Pentest Award отметил лучших охотников за уязвимостями
Spanish police arrest student suspected of hacking school system to change grades
Hundreds of Salesforce customer orgs hit in clever attack with potentially huge blast radius
A threat group Google tracks as UNC6395 has pilfered troves of data from Salesforce corporate instances, in search of credentials that can be used to compromise those organizations’ environments. “[Google Threat Intelligence Group] observed UNC6395 targeting sensitive credentials such as Amazon Web Services (AWS) access keys (AKIA), passwords, and Snowflake-related access tokens,” the company’s incident responders shared. How did UNC6395 access Salesforce instances? Salesforce is a cloud-based customer relationship management platform. To access the targeted … More →
The post Hundreds of Salesforce customer orgs hit in clever attack with potentially huge blast radius appeared first on Help Net Security.