Aggregator
Tornado Cash снова в деле. Хакер переписал на себя контракт GANA на BNB Chain и начал отмывать миллионы
Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs
CISA Urges Patch of Actively Exploited Flaw in Oracle Identity Manager
【安全圈】ShadowPad 恶意软件正在利用 WSUS 漏洞获取系统最高权限
【安全圈】Android 恶意软件 RadzaRat 可对设备实施全面监控
【安全圈】7-Zip 爆出严重漏洞 已有公开利用代码 需立即手动更新
【安全圈】Wireshark 多个漏洞可被恶意构造数据包触发崩溃
When trust turns toxic: Lessons from the Salesloft Drift incident
The recent Salesloft Drift breach offered a sobering reminder of how easily trust can be weaponized in today’s SaaS and AI-integrated environments. In this incident, hackers exploited the Drift chatbot, stole OAuth tokens, and used them to obtain data from CRM systems before the tokens could be revoked. In the wake of the incident, many […]
The post When trust turns toxic: Lessons from the Salesloft Drift incident appeared first on CyberScoop.
The slow rise of SBOMs meets the rapid advance of AI
Despite years of effort to make software safer and more transparent with SBOMs, the rise of AI coding assistants is fueling optimism—and, some experts argue, “kind of insane”—claims about a future with vulnerability-free software.
The post The slow rise of SBOMs meets the rapid advance of AI appeared first on CyberScoop.
24th November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th November, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The notorious “Scattered LAPSUS$ Hunters” group claimed responsibility for a supply-chain attack involving the Salesforce-integrated platform Gainsight. The group stated that data from 300 organizations was compromised, including Verizon, GitLab and Atlassian. […]
The post 24th November – Threat Intelligence Report appeared first on Check Point Research.
Продолжаешь рекламировать в Instagram? Штрафы для блогеров за размещение рекламы в запрещенных соцсетях могут вырасти в 30 раз
Sinobi
You must login to view this content
Microsoft: Windows 11 24H2 bug crashes Explorer and Start Menu
Sinobi
You must login to view this content
Sinobi
You must login to view this content
Hackers Replace ‘m’ with ‘rn’ in Microsoft(.)com to Steal Users’ Login Credentials
A sophisticated phishing campaign is currently leveraging a subtle typographical trick to bypass user vigilance, deceiving victims into handing over sensitive login credentials. Attackers utilize the domain “rnicrosoft.com” to impersonate the tech giant. By replacing the letter ‘m’ with the combination of ‘r’ and ‘n’, fraudsters create a visual doppleganger that is nearly indistinguishable from […]
The post Hackers Replace ‘m’ with ‘rn’ in Microsoft(.)com to Steal Users’ Login Credentials appeared first on Cyber Security News.