Aggregator
Colt Confirms Customer Data Stolen in Ransomware Attack
Telecommunications giant Colt Technology Services has confirmed that customer data was compromised in a sophisticated cyber attack that began on August 12, 2025. The company disclosed that threat actors accessed sensitive files containing customer information and subsequently posted document titles on the dark web, prompting immediate containment measures and law enforcement notification. Key Takeaways1. Colt […]
The post Colt Confirms Customer Data Stolen in Ransomware Attack appeared first on Cyber Security News.
CVE-2024-1706 | ZKTeco ZKBio Access IVS up to 3.3.2 Department Name Search Bar cross site scripting
CVE-2025-9135 | Verkehrsauskunft Österreich SmartRide/cleVVVer/BusBahnBim up to 12.1.1(258) AndroidManifest.xml improper export of android application components
本周看什么 | 最近值得一看的 9 部作品
每周蓝军技术推送(2025.8.16-8.22)
Vulinbox SQL 注入攻防实录:靶场通关与技巧拆解
威胁情报:Clickfix 钓鱼攻击
威胁情报:Clickfix 钓鱼攻击
CVE-2005-1183 | mvnForum 1.0 Rc4 Search cross site scripting (EDB-25438 / Nessus ID 18359)
CVE-2005-3324 | Appindex MWChat 6.8 chat.php Username sql injection (EDB-26394 / XFDB-22845)
CVE-2005-4500 | MusicBox 2.3 index.php Type sql injection (EDB-27445 / XFDB-24055)
CVE-2005-1054 | Moderngigabyte ModernBill 4.3.0 news.php DIR file inclusion (EDB-25376 / Nessus ID 18008)
CVE-2005-3649 | Moodle 1.5.2 jumpto.php jump (EDB-1312 / SA17526)
Azure’s Default API Connection Vulnerability Enables Full Cross-Tenant Compromise
A critical vulnerability in Microsoft Azure’s API Connection infrastructure enabled attackers to compromise resources across different Azure tenants worldwide. The flaw, which earned Gulbrandsrud a $40,000 bounty and a Black Hat presentation slot, exploited Azure’s shared API Management (APIM) instance architecture to gain unauthorized access to Key Vaults, Azure SQL databases, and third-party services like […]
The post Azure’s Default API Connection Vulnerability Enables Full Cross-Tenant Compromise appeared first on Cyber Security News.