Aggregator
【2025合作伙伴巡礼】天鉴科技:立足取证,服务实战
5 months 3 weeks ago
立足取证,服务实战
KL-001-2024-010: Journyx Unauthenticated XML External Entities Injection
5 months 3 weeks ago
Full Disclosuremailing list archivesFrom: KoreLogic Disclosures via Fulldisclosu
Hazy Issue in Entra ID Allows Privileged Users to Become Global Admins
5 months 3 weeks ago
Invisible authentication mechanisms in Microsoft allow any attacker to escalate from privileged to super-duper privileged in cloud environments, paving the way for complete takeover.
Nate Nelson, Contributing Writer
Ronin Network hacked, $12 million returned by "white hat" hackers
5 months 3 weeks ago
Gambling blockchain Ronin Network suffered a security incident yesterday when white hat hackers exploited an undocumented vulnerability on the Ronin bridge to withdraw 4,000 ETH and 2 million USDC, totaling $12 million. [...]
Bill Toulas
SEC ends probe into MOVEit attacks impacting 95 million people
5 months 3 weeks ago
The SEC concludes its investigation into Progress Software's handling of the widespread exploitation of a MOVEit Transfer zero-day flaw that exposed data of over 95 million people. [...]
Lawrence Abrams
FBI: BlackSuit ransomware behind over $500 million in ransom demands
5 months 3 weeks ago
CISA and the FBI confirmed today that the Royal ransomware rebranded to BlackSuit and has demanded over $500 million from victims since it emerged more than two years ago. [...]
Sergiu Gatlan
FBI: BlackSuit ransomware made over $500 million in ransom demands
5 months 3 weeks ago
CISA and the FBI confirmed today that the Royal ransomware rebranded to BlackSuit and has demanded over $500 million from victims since it emerged more than two years ago. [...]
Sergiu Gatlan
Monitoring Changes in KEV List Can Guide Security Teams
5 months 3 weeks ago
The number of additions to the Known Exploited Vulnerabilities catalog is growing quickly, but even silent changes to already-documented flaws can help security teams prioritize.
Robert Lemos, Contributing Writer
Почему SOAR мертвы?!
5 months 3 weeks ago
Counting the API arguments…
5 months 3 weeks ago
Today Matt posted a half-joking twit about the acceptable number of arguments that can be p
How to Build-in Security as a SaaS Feature: A Guide
5 months 3 weeks ago
In this post, I'm going to show you how to provide more granular and more secure connectivity to and
Easterly: Too early to say if Supreme Court’s Chevron decision will affect cyber incident notification rules
5 months 3 weeks ago
LAS VEGAS – The head of the leading U.S. cybersecurity agency said it is too early to know whether
Splitting the email atom: exploiting parsers to bypass access controls
5 months 3 weeks ago
Published: 07 August 2024 at 21:32 UTC
New CMoon USB worm targets Russians in data theft attacks
5 months 3 weeks ago
error code: 1106
New CMoon USB worm targets Russians in data theft attacks
5 months 3 weeks ago
A new self-spreading worm named 'CMoon,' capable of stealing account credentials and other data, has been distributed in Russia since early July 2024 via a compromised gas supply company website. [...]
Bill Toulas
Critical XSS bug in Roundcube Webmail allows attackers to steal emails and sensitive data
5 months 3 weeks ago
Researchers warn of flaws in the Roundcube webmail software that could be exploited to steal sensitive information from target accounts. Sonar’s Vulnerability Research Team discovered a critical Cross-Site Scripting (XSS) vulnerability in the popular open-source webmail software Roundcube. Roundcube is included by default in the server hosting panel cPanel which has millions of installations worldwide. […]
Pierluigi Paganini
Critical XSS bug in Roundcube Webmail allows attackers to steal emails and sensitive data
5 months 3 weeks ago
Critical XSS bug in Roundcube Webmail allows attackers to steal emails and sensitive dataResea
Royal ransomware successor BlackSuit has demanded more than $500 million
5 months 3 weeks ago
The hackers behind a notorious ransomware operation that shut down the city of Dallas last year hav
Introducing Outflank C2 with Implant Support for Windows, macOS, and Linux
5 months 3 weeks ago
We are rebranding our commercial