[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (1 articles)

|

// AI-powered summary generated at 08:00

> ZDI-25-939: (0Day) Ivanti Endpoint Manager MP_VistaReport SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-62387.
> ZDI-25-938: (0Day) Ivanti Endpoint Manager Report_RunPatch SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-62385.
> Adpost - 3,339,512 breached accounts
In February 2025, data allegedly obtained from an earlier Adpost breach surfaced. The dataset contained 3.3M records including email addresses, usernames, and display names. Multiple attempts to contact Adpost regarding the incident received no response.
> ZDI-25-937: (0Day) Ivanti Endpoint Manager Report_Run SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-62383.
> ZDI-25-936: (0Day) Ivanti Endpoint Manager Report_Run2 SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-11623.
> Mitigating AI's new risk frontier: Unifying enterprise cybersecurity with AI safety
These are exciting times for AI. Enterprises are blending AI capabilities with enterprise data to deliver better outcomes for employees, customers, and partners. But as organizations weave AI deeper into their systems, that data and infrastructure also become more attractive targets for cybercrimina...
> ZDI-25-935: (0Day) Ivanti Endpoint Manager OnSaveToDB Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Alternatively, no user interaction is require...
> ZDI-25-934: MindManager Attachment Insufficient UI Warning Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindManager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
> Alfred-Wegener-Institut fĂĽr Polar- und Meeresforschung (AWI)
L'Institut Alfred-Wegener pour la recherche polaire et marine a été victime d'une attaque informatique, mais l'institut dément cela et parle d'une panne technique. Les systèmes ont été mis hors service pour des raisons de sécurité. Les services devraient être rétablis dans le courant de la semaine.
> Prince Housing & Development Corp.
La compagnie a subi une attaque de hackers sur ses systèmes d'information, mais a activé des mesures de protection et n'a pas subi de pertes significatives. Les systèmes sont en cours de scan et de test pour assurer la sécurité. La compagnie renforce ses mesures de protection pour prévenir de future...
> Inside Microsoft Threat Intelligence: Calm in the chaos
Incident response is never orderly. Threat actors don’t wait. Environments are compromised. Data is missing. Confidence is shaken. But for Microsoft’s Incident Response (IR) team, that chaos is exactly where the work begins. The post Inside Microsoft Threat Intelligence: Calm in the chaos appeared f...
> Bristol Broadcasting
Bristol Broadcasting a signalé des problèmes techniques après la mention d'un ransomware à l'antenne, les émissions en ligne de certaines stations étant affectées. Les causes de l'incident sont encore en cours d'évaluation. Les émissions en direct ont continué, mais les flux en ligne ont été interro...
> Appalachian Community Federal Credit Union
A data breach occurred at Appalachian Community Federal Credit Union, resulting in the theft of sensitive personal information, including names, Social Security numbers, and financial account information. The breach was discovered on October 7, 2025, and the affected individuals were notified on Dec...
> Clop hackers caught exploiting Oracle zero-day bug to steal executives’ personal data
Oracle fixes another security flaw that Clop hackers were using to steal sensitive personal information about executives as part of a mass-extortion campaign.
> Taylor Clay Products
Cette victime n'a pas été revendiquée par Akira, mais un affidé de l'enseigne divulgue des données qu'il lui attribue.
> Europol Calls for Stronger Data Laws to Combat Cybercrime
Europol’s Cybercrime Conference has warned that cybercriminals are exploiting new technologies faster than law enforcement can adapt
> Scattered Lapsus$ Hunters offering $10 in Bitcoin to 'endlessly harass' execs
Crime group claims to have already doled out $1K to those in it 'for money and for the love of the game' Scattered Lapsus$ Hunters has launched an unusual crowdsourced extortion scheme, offering $10 in Bitcoin to anyone willing to help pressure their alleged victims into paying ransoms.…
> Ransomware Group “Trinity of Chaos” Launches Data Leak Site
A new TOR data leak site published by the Trinity of Chaos ransomware group unveils 39 firms’ data and threatens Salesforce litigation
> Inside Microsoft’s AI bet with CTO Kevin Scott at TechCrunch Disrupt 2025
Microsoft CTO Kevin Scott joins the Disrupt Stage at TechCrunch Disrupt 2025 to share how one of the world’s largest technology companies is navigating the AI revolution and what it means for startups and the future of innovation. Register now to join.
> Case Study: How Advance2000 keeps 10K+ users secure with Sophos
Sophos MDR is all but mandatory to keep this New York-based MSP’s customers secure.