Aggregator
GitLab patches critical authentication bypass vulnerabilities
86,000+ Healthcare Staff Records Exposed from Misconfigured AWS S3 Bucket
A significant data breach involving sensitive healthcare worker information has been discovered, exposing over 86,000 records belonging to ESHYFT, a New Jersey-based HealthTech company. Cybersecurity researcher Jeremiah Fowler identified an unprotected AWS S3 storage bucket containing approximately 108.8 GB of data that lacked password protection or encryption, leaving private healthcare worker information publicly accessible. The […]
The post 86,000+ Healthcare Staff Records Exposed from Misconfigured AWS S3 Bucket appeared first on Cyber Security News.
CVE-2025-1767
Hackers Abuse Microsoft Copilot for Sophisticated Phishing Attack
As organizations increasingly integrate Microsoft Copilot into their daily workflows, cybercriminals have developed sophisticated phishing campaigns specifically targeting users of this AI-powered assistant. Microsoft Copilot, which launched in 2023, has rapidly become an essential productivity tool for many organizations, integrating deeply with Microsoft 365 apps to provide AI-powered assistance. However, this widespread adoption has created […]
The post Hackers Abuse Microsoft Copilot for Sophisticated Phishing Attack appeared first on Cyber Security News.
0day Today Team Defaced the Website of In A Blink Of An Eye
CVE-2010-4633 | Sumeffect digiSHOP 2.0.2 cart.php id sql injection (EDB-15405 / XFDB-62964)
CVE-2024-0019 | Google Android 12/12L/13/14 AppOpsControllerImpl.java setListening information disclosure
CVE-2023-52370 | Huawei HarmonyOS/EMUI Network Acceleration Module stack-based overflow
CVE-2023-52367 | Huawei HarmonyOS/EMUI Media Library Module access control
CVE-2023-52379 | Huawei HarmonyOS/EMUI calendarProvider module access control
CVE-2023-52377 | Huawei HarmonyOS/EMUI Cellular Data Module buffer overflow
CVE-2023-52360 | Huawei HarmonyOS/EMUI Baseband
CVE-2024-23267 | Apple macOS up to 12.6/13.5/14.3 information disclosure
CVE-2024-27448 | MailDev up to 2.1.0 Header lib/mailserver.js Content-ID cross-site request forgery (Exploit 467)
CVE-2024-2076 | CodeAstro House Rental Management System 1.0 tenant.php missing authentication
Siemens SINAMICS S200 Bootloader Vulnerability Let Attackers Compromise the Device
Siemens has disclosed a critical security vulnerability affecting specific SINAMICS S200 drive systems that could allow attackers to compromise devices by exploiting an unlocked bootloader. The vulnerability, tracked as CVE-2024-56336 and has received the highest severity ratings with a CVSS v3.1 score of 9.8 and CVSS v4.0 score of 9.5. The security advisory SSA-787280 identifies […]
The post Siemens SINAMICS S200 Bootloader Vulnerability Let Attackers Compromise the Device appeared first on Cyber Security News.
How to secure your personal metadata from online trackers
When it comes to safeguarding your privacy online, most people focus on securing passwords, encrypting communications, and clearing browsing history. While these practices are essential, they overlook one important element—metadata. This data, which is collected about your digital interactions, can often reveal more about you than you think. Metadata is an invaluable resource for online trackers, advertisers, cybercriminals, and even government surveillance. Understanding how metadata is collected and what you can do to protect it … More →
The post How to secure your personal metadata from online trackers appeared first on Help Net Security.