Aggregator
Automaker giant Stellantis confirms data breach after Salesforce hack
9 months ago
Automotive manufacturing giant Stellantis has confirmed that attackers stole some of its North American customers' data after gaining access to a third-party service provider's platform. [...]
Sergiu Gatlan
Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments
9 months ago
In recent weeks, security researchers have observed a surge in attacks exploiting Oracle Database Scheduler’s External Jobs feature to gain a foothold in corporate environments. This technique abuses the scheduler’s ability to execute arbitrary commands on Windows-based database servers, allowing adversaries to bypass perimeter defenses. Initial intrusion vectors involve probing publicly exposed Oracle listener ports […]
The post Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments appeared first on Cyber Security News.
Tushar Subhra Dutta
Alleged Data Sale of Fortis Healthcare
9 months ago
Alleged Data Sale of Fortis Healthcare
Dark Web Informer
За три года — ни одного потерянного байта. Алготрейдинговый гигант открыл исходный код TernFS для Linux
9 months ago
овый инструмент для работы с петабайтами и эксабайтами данных теперь доступен сообществу.
Stellantis probes data breach linked to third-party provider
9 months ago
Stellantis is investigating a data breach after unauthorized access to a third-party provider’s platform potentially exposed customer data. Car maker giant Stellantis announced it is investigating a data breach following unauthorized access to a third-party provider’s platform that supports North American customer service operations. The company did not name the impacted third-party provider. Stellantis N.V. […]
Pierluigi Paganini
Астероид размером с пирамиду. Как падение 160-метрового небесного тела вызвало 100-метровое цунами и оставило след на дне океана.
9 months ago
80% геологов ошиблись в голосовании 2009 года.
Threat Detection Made Simple: Splunk Attack Range Basics
9 months ago
by Ian Briley Let’s be honest, when starting a new skill or interest, one of the largest hurdles is setting up an environment//playground//attack range for your learning activities. Sometimes it […]
Red Siege
Russia steps up disinformation efforts to sway Moldova’s parliamentary vote
9 months ago
Russia is reportedly ramping up covert influence operations ahead of Moldova’s parliamentary election in an alleged attempt to block its path to the European Union.
New EDR-Freeze tool uses Windows WER to suspend security software
9 months ago
A new method and proof-of-concept tool called EDR-Freeze demonstrates that evading security solutions is possible from user mode with Microsoft's Windows Error Reporting (WER) system. [...]
Bill Toulas
Randall Munroe’s XKCD ‘’Cursed Number”
9 months ago
via the comic artistry and dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘’Cursed Number” appeared first on Security Boulevard.
Marc Handelman
Свой софт, свои правила. Минцифры скорректировало требования к российскому ПО
9 months ago
Ведомство разрешило разработчикам не спешить с импортозамещением.
Microsoft lifts Windows 11 update block after face detection fix
9 months ago
Microsoft has removed a compatibility hold that prevented devices with integrated cameras from installing Windows 11 24H2 due to a face detection bug causing app freezes. [...]
Sergiu Gatlan
Multi-Kernel 架构支持代码公开
9 months ago
Multikernel Technologies 公司的 Cong Wang 公布了代码递交了 RFC。代码为 Linux 内核加入多内核架构支持,让多个独立内核实例能在一台物理机器上共存并通信,每个内核实例能在专用 CPU 核心上运行,共享底层硬件资源。Multikernel Technologies 公司承诺将采用社区优先的开发方法。
Пруфов нет, но платят все. Группа Warlock сломала главное правило кибервымогательства
9 months ago
За полгода неизвестные хакеры ворвались в Топ-20 самых опасных киберпреступников мира.
Bitcoin continues to increase its institutional popularity
9 months ago
Not long ago, the mere idea that cryptocurrencies could ever be integrated into mainstream finance would have seemed…
Owais Sultan
CVE-2025-57432 | Blackmagic Web Presenter 3.3 Telnet Service improper authentication
9 months ago
A vulnerability was found in Blackmagic Web Presenter 3.3. It has been classified as critical. This affects an unknown part of the component Telnet Service. Performing manipulation results in improper authentication.
This vulnerability is cataloged as CVE-2025-57432. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-35042 | Airship AI Acropolis up to 10.2.34/11.0.20/11.1.8 default credentials
9 months ago
A vulnerability was found in Airship AI Acropolis up to 10.2.34/11.0.20/11.1.8 and classified as very critical. Affected by this issue is some unknown functionality. Such manipulation leads to use of default credentials.
This vulnerability is listed as CVE-2025-35042. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-35041 | Airship AI Acropolis up to 10.2.34/11.0.20/11.1.8 excessive authentication
9 months ago
A vulnerability has been found in Airship AI Acropolis up to 10.2.34/11.0.20/11.1.8 and classified as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes improper restriction of excessive authentication attempts.
This vulnerability is tracked as CVE-2025-35041. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2025-57430 | Creacast Creabox Manager 4.4.4 Configuration /get information disclosure
9 months ago
A vulnerability, which was classified as problematic, was found in Creacast Creabox Manager 4.4.4. Affected is an unknown function of the file /get of the component Configuration Handler. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2025-57430. The attack can only be performed from the local network. There is not any exploit available.
vuldb.com