Aggregator
OLLVM学习以及平坦化源码分析
CVE-2025-10193 | neo4j neo4j-cypher MCP server up to 0.3.1 DNS origin validation (GHSA-vcqx-v2mg-7chx / EUVD-2025-28908)
CVE-2025-8716 | OpenText Content Management up to 25.3 unusual condition (KB0847046)
New VMScape attack breaks guest-host isolation on AMD, Intel CPUs
Google Pixel 10 Adds C2PA Support to Verify AI-Generated Media Authenticity
Lessons from Salesforce/Salesloft Drift Data Breaches – Detailed Case Study
The Salesloft Drift data breaches of August 2025 stand as one of the most significant supply chain attacks in SaaS history, demonstrating how a single compromised integration can cascade into widespread organizational exposure. This sophisticated campaign, staged by the threat actor UNC6395, exploited OAuth token vulnerabilities to access sensitive data from over 700 organizations, including […]
The post Lessons from Salesforce/Salesloft Drift Data Breaches – Detailed Case Study appeared first on Cyber Security News.
BSidesSF 2025: Your Intrusion Detection Still Sucks (And What To Do About It)
Creator, Author and Presenter: Jason Craig
Our deep appreciation to Security BSides - San Francisco and the Creators, Authors and Presenters for publishing their BSidesSF 2025 video content on YouTube. Originating from the conference’s events held at the lauded CityView / AMC Metreon - certainly a venue like no other; and via the organization's YouTube channel.
Additionally, the organization is welcoming volunteers for the BSidesSF Volunteer Force, as well as their Program Team & Operations roles. See their succinct BSidesSF 'Work With Us' page, in which, the appropriate information is to be had!
The post BSidesSF 2025: Your Intrusion Detection Still Sucks (And What To Do About It) appeared first on Security Boulevard.
Wyden Urges FTC Investigation Over Ascension Ransomware Hack
CVE-2019-1761 | Cisco IOS/IOS XE Hot Standby Router Protocol Subystem initialization (cisco-sa-20190327-ios-infoleak / ID 316406)
CVE-2021-1620 | Cisco IOS/IOS XE IKEv2 denial of service (cisco-sa-ikev2-ebFrwMPr)
CVE-2025-10252 | SEAT Queue Ticket Kiosk up to 20250827 Java RMI Registry deserialization
CVE-2025-10253 | openDCIM 23.04 SVG File /scripts/uploadifive.php Filedata cross site scripting
CVE-2025-8743 | Scada-LTS up to 2.7.8.1 Virtual Data Source Property /data_source_edit.shtm Name cross site scripting (EUVD-2025-24024)
CVE-2025-8511 | Portabilis i-Diario 1.5.0 Observações /diario-de-observacoes/ Descrição cross site scripting (EUVD-2025-23479)
Privileged AWS Permissions You Should Restrict Immediately (Top 25 + Bonus)
Drumroll, please… 🥁 After five weeks of countdowns, breakdowns, and some very lively conversations, we’ve finally reached the end of the Top 25 Most Risky AWS Privileged Permissions, plus a special bonus round for AWS Organizations. These permissions aren’t just “potentially risky.” They’ve been abused in real-world incidents to steal data, bypass controls, and escalate […]
The post Privileged AWS Permissions You Should Restrict Immediately (Top 25 + Bonus) appeared first on Security Boulevard.
Akira ransomware affiliates continue breaching organizations via SonicWall firewalls
Over a year after SonicWall patched CVE-2024-40766, a critical flaw in its next-gen firewalls, ransomware attackers are still gaining a foothold in organizations by exploiting it. Like last September and earlier this year, the attackers are affiliates of the Akira ransomware-as-a-service outfit. The July 2025 surge in attacks was, according to SonicWall, facilitated by the fact that organizations has migrated from Gen 6 to Gen 7 firewalls but did not reset local user passwords (as … More →
The post Akira ransomware affiliates continue breaching organizations via SonicWall firewalls appeared first on Help Net Security.
Senator Wyden Urges FTC to Probe Microsoft for Ransomware-Linked Cybersecurity Negligence
Realm.Security Joins Google Cloud Partner Advantage Program to Deliver Cost-Effective Security Data Management at Scale
Realm.Security joins the Google Cloud Partner Advantage program to deliver AI-powered security data pipelines that cut SIEM costs, streamline log management, and improve SOC efficiency for Google Cloud customers.
The post Realm.Security Joins Google Cloud Partner Advantage Program to Deliver Cost-Effective Security Data Management at Scale appeared first on Realm.Security.
The post Realm.Security Joins Google Cloud Partner Advantage Program to Deliver Cost-Effective Security Data Management at Scale appeared first on Security Boulevard.