This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/202Â 5) for more information.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
In September 2024, French retailer Cultura was the victim of a cyber attack they attributed to an external IT service provider. The resultant data breach included almost 1.5M unique email addresses along with names, phone numbers, physical addresses and orders. Cultura advised that all affected cust...
**[Mise à jour du 06 octobre 2025]** Le CERT-FR a connaissance de codes d'exploitation publics. **[Publication initiale]** Le 25 septembre 2025, Cisco a publié plusieurs avis de sécurité, un billet de blogue ainsi qu'un guide de détection concernant des vulnérabilités affectant le serveur VPN Web...
La Direction générale des impÎts et domaines a été victime d'une cyberattaque, selon Bachir Fofana, ce qui a mis hors service le service informatique. Les agents ont reçu un message les avertissant de ne pas allumer leurs machines en raison de l'attaque. Cette cyberattaque intervient dans un context...
Ransomware doesnât just freeze computers - it can silence alarms too. And when the Natural History Museum in Paris went dark, thieves helped themselves to âŹ600,000 worth of gold in a daring late-night heist. Meanwhile, developers have a new headache: a worm dubbed âShai Huludâ has wriggled its way t...
We connect Bookworm malware to Chinese APT Stately Taurus using our attribution framework, enhancing our understanding of threat group tradecraft.
The post Bookworm to Stately Taurus Using the Unit 42 Attribution Framework appeared first on Unit 42.
The update for libxslt announced in DSA 5979-1 introduced a regression while back porting the upstream deterministic generate-id implementation, which makes the generated IDs may remain in a non-deterministic order.
During the Month of AI Bugs, I described an emerging vulnerability pattern that shows how commonly agentic systems have a design flaw that allows an agent to overwrite its own configuration and security settings.
This allows the agent to break out of its sandbox and escape by executing arbitrary cod...
Posted by Elie Bursztein and Marianna Tishchenko, Google Privacy, Safety and Security TeamEmpowering cyber defenders with AI is critical to tilting the cybersecurity balance back in their favor as they battle cybercriminals and keep users safe. To help accelerate adoption of AI for cybersecurity wor...
INC is the name of a ransomware-as-a-service (RaaS) operation that first appeared in late summer 2023. Learn more about what it has been up to, and how to protect against its attacks, in my article on the Fortra blog.
Malicious npm package Fezbox uses QR codes to steal credentials from browser cookies
New campaign merges traditional malware with DevOps tools, using GitHub CodeSpaces for DDoS attacks
Whether youâre navigating a client pentest or chasing a bounty target, even the most experienced testers hit roadblocks, burn time on repetitive tasks, or just want a second opinion. Burp AI is design
Written by: Sarah Yoder, John Wolfram, Ashley Pearson, Doug Bienstock, Josh Madeley, Josh Murchie, Brad Slaybaugh, Matt Lin, Geoff Carstairs, Austin Larsen
Introduction
Google Threat Intelligence Group (GTIG) is tracking BRICKSTORM malware activity, which is being used to maintain persistent access...
U.S. prosecutors last week levied criminal hacking charges against 19-year-old U.K. national Thalha Jubair for allegedly being a core member of Scattered Spider, a prolific cybercrime group blamed for extorting at least $115 million in ransom payments from victims. The charges came as Jubair and an...
Supply chain attacks exploit fundamental trust assumptions in modern software development, from typosquatting to compromised build pipelines, while new defensive tools are emerging to make these trust relationships explicit and verifiable.
Boyd Gaming Corporation has disclosed that an unauthorized actor removed data from its systems, including information about employees and other individuals
The equipment could be used to disable cell phone towers and conduct denial-of-services attacks across New York City
What happens when you bring in a team of cybersecurity responders? How do we turn chaos into control, and what is the long-term value that Talos IR provides to the organizations we work with?Â