Security Bulletin
23 Mar 2025
Biztonsági szemle
Let's Talk About HTTP Headers., (Sun, Mar 23rd)
Walking my dog earlier, I came across the sign on the right. Having just looked at yet another middleware/HTTP header issue (the Next.js problem that became public this weekend) [1], I figured I should write something about HTTP headers. We all know...
21 Mar 2025
Biztonsági szemle
North Korea launches hacking hub focused on artificial intelligence
"Research Center 227" reportedly focused on using AI for cyberattacks.
21 Mar 2025
Biztonsági szemle
Orange Drop Caps, apps, Veeam, jobs, Heathrow, vpentest, Aaran Leyland, and More... - SWN #461
21 Mar 2025
Biztonsági szemle
What CISA's Red Team Disarray Means for US Cyber Defenses
DOGE is making wild moves at CISA, including bringing back fired probationary employees only to put them on paid leave, and reportedly gutting the agency's red teams.
21 Mar 2025
Biztonsági szemle
Attackers Pivot to SEMrush Spoof to Steal Google Credentials
The attackers are taking an indirect approach to targeting SEO professionals and their Google credentials, using a fake digital marketing website.
21 Mar 2025
Biztonsági szemle
Nation-State 'Paragon' Spyware Infections Target Civil Society
Law enforcement entities in democratic states have been deploying top-of-the-line messaging app spyware against journalists and aid workers.
21 Mar 2025
Biztonsági szemle
Popular AI tools tricked to create malware for Chrome browser
Cato Networks researchers create jailbreak method where hacking is normal in an alternate reality.
21 Mar 2025
Biztonsági szemle
Updated CISA vulnerabilities catalog includes Edimax, NAKIVO, SAP NetWeaver bugs
Most severe of the newly added flaws is the Edimax IC-7100 IP camera OS command injection vulnerability, tracked as CVE-2025-1316.
21 Mar 2025
Biztonsági szemle
Data breach refuted by Baidu after user info leak
All of the information posted by the daughter of Baidu Vice President Xie Guangjun has been procured from foreign platforms' "doxing databases," said Baidu.
21 Mar 2025
Biztonsági szemle
GitHub Action supply chain attack less impactful than thought
Most of the exposed secrets were GitHub install action tokens but their 24-hour expiration has restricted exploitation opportunities.
21 Mar 2025
Biztonsági szemle
Suspected Chinese-linked hackers set sights on Taiwan
After achieving initial access by targeting vulnerable internet-exposed web and application servers, UAT-5918 utilized tools previously associated with Volt Typhoon and Flax Typhoon to facilitate lateral movement, credential and data theft, and...
21 Mar 2025
Biztonsági szemle
Ukrainian defense sector hit with Dark Crystal RAT
Attackers, tracked under the UAC-0200 threat cluster, leveraged the Signal messaging app to deliver messages purportedly containing minutes of the meeting reports as archive files.
Pagination
- Previous page ‹‹
- Page 294
- Next page ››