Security Bulletin
31 Oct 2025
Biztonsági szemle
ISC Stormcast For Friday, October 31st, 2025 https://isc.sans.edu/podcastdetail/9680, (Fri, Oct 31st)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
31 Oct 2025
Biztonsági szemle
Zombie Projects Rise Again to Undermine Security
Companies left them for dead, but the remnants of old infrastructure and failed projects continue to haunt businesses' security teams.
30 Oct 2025
Biztonsági szemle
An 18-Year-Old Codebase Left Smart Buildings Wide Open
Researcher Gjoko Krstic’s "Project Brainfog" exposed hundreds of zero-day vulnerabilities in building-automation systems still running hospitals, schools, and offices worldwide.
30 Oct 2025
Biztonsági szemle
US Stands Out in Refusal to Sign UN Cybercrime Treaty
The agreement aims to help law enforcement prosecute cross-border cybercrime, but the final treaty could allow unchecked surveillance and human-rights abuses, critics say; and, it includes no protection for pen testers.
30 Oct 2025
Biztonsági szemle
Critical Claroty Authentication Bypass Flaw Opened OT to Attack
CVE-2025-54603 gave attackers an opening to disrupt critical operational technology (OT) environments and critical infrastructure, plus steal data from them.
30 Oct 2025
Biztonsági szemle
LotL Attack Hides Malware in Windows Native AI Stack
Security programs trust AI data files, but they shouldn't: they can conceal malware more stealthily than most file types.
30 Oct 2025
Biztonsági szemle
Cloud Outages Highlight the Need for Resilient, Secure Infrastructure Recovery
Two massive technical outages over the past year underscore the need for cybersecurity teams to consider how to recover safely from disruptions without creating new security risks.
30 Oct 2025
Biztonsági szemle
X-Request-Purpose: Identifying "research" and bug bounty related scans?, (Thu, Oct 30th)
This week, I noticed some new HTTP request headers that I had not seen before:
30 Oct 2025
Biztonsági szemle
Data Leak Outs Students of Iran's MOIS Training Academy
A school for the Iranian state hackers of tomorrow has itself, ironically, been hacked.
30 Oct 2025
Biztonsági szemle
ISC Stormcast For Thursday, October 30th, 2025 https://isc.sans.edu/podcastdetail/9678, (Thu, Oct 30th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
30 Oct 2025
Biztonsági szemle
Data Security Posture Management — What Does 'Best in Class' Look Like?
The emergence of Data Security Posture Management (DSPM) in early 2023, followed by major acquisitions by companies like IBM, Thales, and Palo Alto Networks, demonstrates industry recognition of the need for a more holistic approach to data...
29 Oct 2025
Biztonsági szemle
Malicious NPM Packages Disguised With 'Invisible' Dependencies
In the "PhantomRaven" campaign, threat actors published 126 malicious npm packages that have flown under the radar, while collecting 86,000 downloads.
Pagination
- Previous page ‹‹
- Page 29
- Next page ››