Aggregator
Ваш "VPN" шпионит за вами уже месяцами, пока вы платите за "защиту" — срочно удалите эти приложения
Google Confirms Salesforce Data Breach by ShinyHunters via Vishing Scam
Securing the AI Era: Sonatype Safeguards Open Source Software Supply Chains
Open source drives modern software—but with innovation comes risk. Learn how Sonatype secures the software supply chain to enable safer, faster delivery.
The post Securing the AI Era: Sonatype Safeguards Open Source Software Supply Chains appeared first on Security Boulevard.
CVE-2025-50098 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 Optimizer denial of service (EUVD-2025-21482 / Nessus ID 244814)
CVE-2025-50078 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 DML improper authorization (Nessus ID 244819)
CVE-2024-27308 | mio Token use after free (Nessus ID 244820)
CVE-2025-50097 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 Encryption improper authorization (Nessus ID 244830)
CVE-2025-50100 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 Thread Pooling denial of service (EUVD-2025-21480 / Nessus ID 244827)
CVE-2025-50085 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 InnoDB improper authorization (Nessus ID 244833)
CVE-2025-50093 | Oracle MySQL Server up to 8.0.42/8.4.5/9.3.0 DDL improper authorization (Nessus ID 244835)
Weaponized npm Packages Target WhatsApp Developers with Remote Kill Switch
Socket’s Threat Research Team has uncovered a sophisticated supply chain attack targeting developers integrating with the WhatsApp Business API. Two malicious npm packages, naya-flore and nvlore-hsc, published by the npm user nayflore using the email [email protected], disguise themselves as legitimate WhatsApp socket libraries. These packages exploit the growing ecosystem of third-party tools for WhatsApp automation, […]
The post Weaponized npm Packages Target WhatsApp Developers with Remote Kill Switch appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Microsoft urges admins to plug severe Exchange security hole (CVE-2025-53786)
“In an Exchange hybrid deployment, an attacker who first gains administrative access to an on-premises Exchange server could potentially escalate privileges within the organization’s connected cloud environment without leaving easily detectable and auditable trace,” Microsoft has announced on Wednesday. The privilege escalation can be performed by exploiting CVE-2025-53786, a newly disclosed vulnerability that stems from Exchange Server and Exchange Online sharing the same service principal – i.e., the Office 365 Exchange Online application – in … More →
The post Microsoft urges admins to plug severe Exchange security hole (CVE-2025-53786) appeared first on Help Net Security.
Evolving Your DSPM Program: A Data-First Imperative
DSPM has become essential in today’s complex security landscape. This piece explores how organizations are evolving beyond basic deployment, the trends reshaping DSPM, and how Netwrix helps deliver continuous, actionable data security at scale. Data Security Posture Management (DSPM) has rapidly matured into a critical component of modern cybersecurity. Today’s security landscape—defined by hybrid environments, … Continued
Black Hat USA 2025: Does successful cybersecurity today increase cyber-risk tomorrow?
CVE-2025-8708 | Antabot White-Jotter 0.22 com.gm.wj.config.ShiroConfiguration ShiroConfiguration.java CookieRememberMeManager deserialization
Submit #621105: Antabot White-Jotter v0.22 deserialization attack [Accepted]
CVE-2025-8707 | Huuge Box App 1.0.3 on Android com.huuge.game.zjbox AndroidManifest.xml improper export of android application components (EUVD-2025-23974)
Human Error: Lessons from the 2006 VA Data Breach
In a recent podcast interview with Cybercrime Magazine host, Davie Braue, Scott Schober, Cyber Expert, Author of "Hacked Again," and CEO of Berkeley Varitronics Systems reflect on a 2006 data breach which served as a cybersecurity wake up call for the Department of Veterans Affairs and the rest of the federal government. The podcast can be listened to in its entirety below.
The post Human Error: Lessons from the 2006 VA Data Breach appeared first on Security Boulevard.