A vulnerability was found in Microsoft Entra ID. It has been declared as critical. This affects an unknown part. Executing manipulation can lead to improper authentication.
This vulnerability is registered as CVE-2025-55241. It is possible to launch the attack remotely. No exploit is available.
This product is provided as a managed service, meaning users do not have the ability to maintain vulnerability countermeasures themselves.
A vulnerability identified as problematic has been detected in MongoDB Server up to 6.0.24/7.0.21/8.0.11. Affected by this issue is some unknown functionality. The manipulation leads to operation on a resource after expiration.
This vulnerability is documented as CVE-2025-10060. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
Default credentials, weak passwords, misconfigurations and a variety of other security shortcomings are exposing millions of medical devices and their data on the internet, said Soufian El Yadmani, CEO and co-founder of Modat, who shared recent research findings.
Users Download Malware in Bid to Placate Meta A newly surfaced FileFix social engineering campaign puts a new spin on ClickFix attacks by goading users into loading malware under the guise of reporting a wrongful account suspension to social media giant Facebook. Victims likely get sucked into the scam by following a link from a phishing email.
Also, Colt Services Outage Persists, Finland Charges Americans in Vastaamo Hack This week, Microsoft hit RaccoonO365, Colt Technology Services, Finland charged a U.S. citizen in Vastaamo hack. RevengeHotels hackers used AI, Meta can't overturn a privacy case verdict. Chinese hackers unleashed spear phishing emails. Prosper confirmed a data breach, as did Kering fashion houses.
Silicon Valley Startup Brings AI Agent and Prompt Injection Protections to Falcon CrowdStrike plans to purchase Pangea to add native AI detection and response capabilities to its Falcon platform. The company says the acquisition will help secure AI models and users alike from preventing prompt injection to tracking agent activity across enterprise environments.
Senate Homeland Security Cancels Markup Session Lawmakers are racing to extend a key cyber sharing law before it expires Sept. 30, but partisan gridlock and proposed restrictions on the U.S. cyber defense agency's disinformation work threaten reauthorization - risking federal insight into active threats and chilling private cooperation.