Aggregator
Shadow IT Is Expanding Your Attack Surface. Here’s Proof
CVE-2025-3601 | GitLab Community Edition/Enterprise Edition up to 18.1.4/18.2.4/18.3.0 allocation of resources (Issue 536034 / Nessus ID 258045)
CVE-2025-2246 | GitLab Community Edition/Enterprise Edition up to 18.1.4/18.2.4/18.3.0 GraphQL API authorization (Issue 524592 / Nessus ID 258046)
Cisco IMC Virtual Keyboard Video Monitor Let Attacker Direct User to Malicious Website
Cisco disclosed a high-severity open redirect vulnerability in the Virtual Keyboard Video Monitor (vKVM) component of its Integrated Management Controller (IMC). Tracked as CVE-2025-20317 with a CVSS 3.1 base score of 7.1, the vulnerability could enable an unauthenticated remote attacker to redirect administrators or users of affected devices to malicious websites, potentially capturing credentials through […]
The post Cisco IMC Virtual Keyboard Video Monitor Let Attacker Direct User to Malicious Website appeared first on Cyber Security News.
Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33
It is no secret that passwords are highly susceptible to phishing and brute force attacks. This led to the mass adoption of passkeys, a passwordless authentication method leveraging cryptographic key pairs that allows users to log in with biometrics or a hardware key. According to FIDO, over 15 billion accounts have been passkey-enabled, with 69% […]
The post Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33 appeared first on Cyber Security News.
TransUnion suffers data breach impacting over 4.4 million people
CVE-2024-42134 | Linux Kernel up to 6.9.8 virtio_pci_common.c is_avq null pointer dereference (5e2024b0b9b3/c8fae27d141a / Nessus ID 258053)
A deeper look at AI crawlers: breaking down traffic by purpose and industry
Salt Typhoon Exploits Flaws in Edge Network Devices to Breach 600 Organizations Worldwide
New York Attorney General Sues Zelle Parent Over Fraud Failures, Raising Stakes for Real-Time Payment Security
New York AG Letitia James has sued Zelle’s parent, Early Warning Services, over billions lost to fraud, spotlighting the urgent need for stronger safeguards, consumer protections, and risk quantification in real-time payments.
The post New York Attorney General Sues Zelle Parent Over Fraud Failures, Raising Stakes for Real-Time Payment Security appeared first on Security Boulevard.