Aggregator
CVE-2025-10531 | Mozilla Firefox up to 142 authentication bypass (WID-SEC-2025-2074)
CVE-2025-10532 | Mozilla Firefox up to 142 unusual condition (Nessus ID 265341 / WID-SEC-2025-2074)
CVE-2025-10529 | Mozilla Firefox up to 142 cross-domain policy (Nessus ID 265341 / WID-SEC-2025-2074)
CVE-2025-10527 | Mozilla Firefox up to 142 use after free (Nessus ID 265341 / WID-SEC-2025-2074)
Luxury Jeweler Tiffany Reports Data Breach Exposing User Personal Data
Luxury jeweler Tiffany and Company has confirmed a data breach that exposed the personal information of 2,590 customers. The company discovered unauthorized access to an external system on September 9, 2025, but determined the incident first occurred on May 12, 2025. Tiffany notified affected customers in writing on September 16, 2025, and filed a breach notification […]
The post Luxury Jeweler Tiffany Reports Data Breach Exposing User Personal Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Тестовый аккаунт = полный доступ: забытый код Microsoft стал ключом ко всей инфраструктуре Azure
Surveying the Global Spyware Market
The Atlantic Council has published its second annual report: “Mythical Beasts: Diving into the depths of the global spyware market.”
Too much good detail to summarize, but here are two items:
First, the authors found that the number of US-based investors in spyware has notably increased in the past year, when compared with the sample size of the spyware market captured in the first Mythical Beasts project. In the first edition, the United States was the second-largest investor in the spyware market, following Israel. In that edition, twelve investors were observed to be domiciled within the United States—whereas in this second edition, twenty new US-based investors were observed investing in the spyware industry in 2024. This indicates a significant increase of US-based investments in spyware in 2024, catapulting the United States to being the largest investor in this sample of the spyware market. This is significant in scale, as US-based investment from 2023 to 2024 largely outpaced that of other major investing countries observed in the first dataset, including Italy, Israel, and the United Kingdom. It is also significant in the disparity it points to the visible enforcement gap between the flow of US dollars and US policy initiatives. Despite numerous US policy actions, such as the addition of spyware vendors on the ...
The post Surveying the Global Spyware Market appeared first on Security Boulevard.
【安全圈】Gamaredon 与 Turla 合作在乌克兰部署 Kazuar 后门
【安全圈】英国两名少年因参与 Scattered Spider 黑客组织攻击伦敦交通局被起诉
【安全圈】俄罗斯克拉斯诺亚尔斯克航空遭遇网络攻击,官网与系统瘫痪
【安全圈】苹果承认 iPhone 17 系列与 iPhone Air 相机偶现黑色方块问题,将通过更新修复
How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines
UK police arrested two teen Scattered Spider members linked to the 2024 attack on Transport for London
UK Police Arrest Two Scattered Spider Hackers Over London Transport Breach
UK law enforcement agencies have arrested two individuals linked to the notorious Scattered Spider cybercriminal group. The arrests, announced on Tuesday, pertain to a sophisticated attack on London’s transport systems. Authorities say the suspects infiltrated critical infrastructure networks, demanding ransom payments and causing widespread disruption. Details of the Arrests and Charges On Sept. 16, officers […]
The post UK Police Arrest Two Scattered Spider Hackers Over London Transport Breach appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
【LYSRC大模型专项众测】探索AI安全边界,3倍奖励等你来拿!
Nokia CBIS/NCS Manager API Vulnerability Allows Attackers to Bypass Authentication
On September 18, 2025, Orange Cert publicly disclosed a critical authentication bypass vulnerability affecting Nokia’s CBIS (CloudBand Infrastructure Software) and NCS (Nokia Container Service) Manager API (CVE-2023-49564). With a CVSS 3.1 score of 9.6 (AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), the vulnerability poses a severe risk to organizations relying on these management platforms to orchestrate and secure their containerized network […]
The post Nokia CBIS/NCS Manager API Vulnerability Allows Attackers to Bypass Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Чтобы взломать вас, преступникам больше не нужен интернет. Только автомобиль и рюкзак
HubSpot’s Jinjava Engine Vulnerability Exposes Thousands of Websites to RCE Attacks
A newly disclosed flaw in HubSpot’s open-source Jinjava template engine could allow attackers to bypass sandbox restrictions and achieve remote code execution (RCE) on thousands of websites relying on versions prior to 2.8.1. Tracked as CVE-2025-59340 and rated Critical with a CVSS v3.1 score of 10.0, the issue stems from JavaType‐based deserialization, enabling threat actors […]
The post HubSpot’s Jinjava Engine Vulnerability Exposes Thousands of Websites to RCE Attacks appeared first on Cyber Security News.
Luxury Jewelry Creator Tiffany Confirms Data breach – Hackers Stolen Users Personal Information
Luxury jewelry brand Tiffany and Company has confirmed a data breach that resulted in the theft of customers’ personal information. The company is in the process of sending out notification letters to affected individuals, detailing the scope of the incident and the data that was compromised. According to the notification, Tiffany experienced a “cybersecurity issue” […]
The post Luxury Jewelry Creator Tiffany Confirms Data breach – Hackers Stolen Users Personal Information appeared first on Cyber Security News.