Security Bulletin
28 Apr 2025
Biztonsági szemle
Escalating attacks against Ivanti VPN appliances expected
Organizations using Ivanti Connect Secure and Pulse Secure VPN systems have been urged to update their instances following a ninefold increase in suspicious IP scanning activity recorded on Apr. 18, The Register reports.
28 Apr 2025
Biztonsági szemle
Intrusions chaining critical Craft CMS zero-days ongoing
Threat actors have been combining a pair of critical Craft CMS vulnerabilities to facilitate server compromise as part of ongoing attacks, according to BleepingComputer.
28 Apr 2025
Biztonsági szemle
Education subjected to Storm-1977 password spraying intrusions
Security Affairs reports that cloud tenants in the education industry have been targeted by the Storm-1977 threat operation in password spraying attacks that facilitated cryptomining activities during the past 12 months.
28 Apr 2025
Biztonsági szemle
Inner workings of ToyMaker IAB examined
Initial access broker ToyMaker has been providing Cactus ransomware gang and other double extortion threat operations access to compromised systems, The Hacker News reports.
28 Apr 2025
Biztonsági szemle
TikTok user database purportedly compromised, over 900K users' info exposed
TikTok had its user database claimed to have been stolen by the R00TK1T hacking collective, which has already posted a sample of credentials belonging to 972,000 users, according to GBHackers News.
28 Apr 2025
Biztonsági szemle
AI, Automation, and Dark Web Fuel Evolving Threat Landscape
Attackers are leveraging the benefits of new technology and the availability of commodity tools, credentials, and other resources to develop sophisticated attacks more quickly than ever, putting defenders on their heels.
28 Apr 2025
Biztonsági szemle
Forget the Stack; Focus on Control
Security teams are under more pressure than ever — and cybersecurity debt is adding fuel to the fire. While it can't be eliminated overnight, it can be managed.
28 Apr 2025
Biztonsági szemle
DoJ Data Security Program Highlights Data Sharing Challenges
The Department of Justice announced compliance rules for the Data Security Program that will require organizations to reexamine how they do business and with whom.
28 Apr 2025
Biztonsági szemle
BSides SF: Using AI to spot shadow patches in open-source software
An indisputable security use case for ChatGPT: scouring open-source changelogs for undisclosed vulnerability patches.
25 Apr 2025
Biztonsági szemle
Microsoft Office 365 MFA targeted by ‘SessionShark’ phishing kit
The malicious service is advertised to evade detection and closely mimic a real login page.
25 Apr 2025
Biztonsági szemle
Beating the AI Game, Ripple, Numerology, Darcula, Special Guests from Hidden Layer... - Malcolm Harkins, Kasimir Schulz - SWN #471
25 Apr 2025
Biztonsági szemle
SAP patches zero day rated 10.0 in NetWeaver
Attackers observed exploiting vulnerability in SAP's NetWeaver Visual Composer product.
Pagination
- Previous page ‹‹
- Page 137
- Next page ››