Security Bulletin

14 Apr 2025
Biztonsági szemle
Fortinet FortiGate fixes circumvented by symlink exploit
Already patched Fortinet FortiGate devices impacted by the CVE-2022-42475, CVE-2023-27997, and CVE-2024-21762, continued to provide read-only access to threat actors who established a symbolic link between the user file system and root file system in...

14 Apr 2025
Biztonsági szemle
Cracked cybercrime forum reemerges
Cybernews reports that major cybercrime forum Cracked.io has resumed operations under the new Cracked[.]sh domain over two months after it was sequestered alongside three other dark web marketplaces as part of the international law enforcement effort...

14 Apr 2025
Biztonsági szemle
Stealthier Tycoon2FA phishing kit appears as PhaaS platforms fuel SVG exploitation
Stealthier Tycoon2FA phishing kit appears as PhaaS platforms fuel SVG exploitation Threat detection and endpoint security systems are being better evaded by a new iteration of the Tycoon2FA phishing-as-a-service kit, reports BleepingComputer.

14 Apr 2025
Biztonsági szemle
How DigitalOcean Moved Away From Manual Identity Management
DigitalOcean executives describe how they automated and streamlined many of the identity and access management functions that had been previously handled manually.

14 Apr 2025
Biztonsági szemle
Sign Up for a Tour at the SOC at RSAC™ 2025 Conference
Cisco and Endace provide Security Operations Center services at RSAC™ 2025 Conference. Sign up for a tour and see what happens in the SOC.

14 Apr 2025
Biztonsági szemle
xorsearch.py: Searching With Regexes, (Mon, Apr 14th)
As promised in diary entry " XORsearch: Searching With Regexes", I will outline another method to search with xorsearch and regexes.

14 Apr 2025
Biztonsági szemle
Morocco Investigates Social Security Agency Data Leak
A threat actor has claimed responsibility for the alleged politically motivated attack and has uploaded the stolen data to a Dark Web forum.

14 Apr 2025
Biztonsági szemle
ISC Stormcast For Monday, April 14th, 2025 https://isc.sans.edu/podcastdetail/9406, (Mon, Apr 14th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

13 Apr 2025
Biztonsági szemle
Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248), (Sat, Apr 12th)
Two weeks ago, version 1.3.0 of Langflow was released. The release notes list many fixes but do not mention that one of the "Bug Fixes" addresses a major vulnerability. Instead, the release notes state, "auth current user on code validation." [1]

11 Apr 2025
Biztonsági szemle
Founder of e-commerce firm hit with fraud charge for lying about AI tech
The $40 million startup was relying on manpower in the Philippines to run the so-called "AI" tool.

11 Apr 2025
Biztonsági szemle
Black Basta-like Microsoft Teams phishing leads to novel backdoor
A new PowerShell backdoor and persistence technique that hijacks TypeLib were discovered.

11 Apr 2025
Biztonsági szemle
Win95, Shuckworm, Ottokit, DCs, EC2, IAB, OSS, Recall, Josh Marpet, and More... - SWN #467
Pagination
- Previous page ‹‹
- Page 11
- Next page ››