Security Bulletin

13 Apr 2025
Biztonsági szemle
Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248), (Sat, Apr 12th)
Two weeks ago, version 1.3.0 of Langflow was released. The release notes list many fixes but do not mention that one of the "Bug Fixes" addresses a major vulnerability. Instead, the release notes state, "auth current user on code validation." [1]

11 Apr 2025
Biztonsági szemle
Founder of e-commerce firm hit with fraud charge for lying about AI tech
The $40 million startup was relying on manpower in the Philippines to run the so-called "AI" tool.

11 Apr 2025
Biztonsági szemle
Black Basta-like Microsoft Teams phishing leads to novel backdoor
A new PowerShell backdoor and persistence technique that hijacks TypeLib were discovered.

11 Apr 2025
Biztonsági szemle
Win95, Shuckworm, Ottokit, DCs, EC2, IAB, OSS, Recall, Josh Marpet, and More... - SWN #467

11 Apr 2025
Biztonsági szemle
Pall Mall Process Progresses but Leads to More Questions
Nations continue to sign the Code of Practice for States in an effort to curb commercial spyware, yet implementation and enforcement concerns have yet to be figured out.

11 Apr 2025
Biztonsági szemle
Paper Werewolf Threat Actor Targets Flash Drives With New Malware
The threat actor, also known as Goffee, has been active since at least 2022 and has changed its tactics and techniques over the years while targeting Russian organizations.

11 Apr 2025
Biztonsági szemle
Palo Alto confirms brute-force attacks on PAN-OS GlobalProtect gateways
PAN points out that to date, the brute-force attacks have not led to exploitation.

11 Apr 2025
Biztonsági szemle
Financial Fraud, With a Third-Party Twist, Dominates Cyber Claims
The most damaging attacks continue to be ransomware, but financial fraud claims are more numerous — and both are driven by increasing third-party breaches.

11 Apr 2025
Biztonsági szemle
Using Third-Party ID Providers Without Losing Zero Trust
With $4.4 billion in worldwide data breach fines in 2024, the cost of not knowing who's walking into your systems is devastating.

11 Apr 2025
Biztonsági szemle
Organizations Lack Incident Response Plans, But Answers Are on the Way
Developing strong incident response plans remains an area that requires significant improvement. Here are some shortcomings and how to address them.

11 Apr 2025
Biztonsági szemle
Numerous Juniper Networks Junos vulnerabilities addressed
SecurityWeek reports that fixes have been issued by Juniper Networks for dozens of security issues impacting its Junos OS and Junos OS Evolved offerings, as well as Junos Space third-party dependencies.

11 Apr 2025
Biztonsági szemle
Cybersecurity gaps prevalent in genetic testing sector
Ninety percent of 40 widely known genetic testing services firms, including 23andMe, Ancestry, and MyHeritage, had received a C grade at most for their cybersecurity efforts, indicating the pervasiveness of poor cybersecurity practices across the DNA...
Pagination
- Previous page ‹‹
- Page 158
- Next page ››