This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk Revit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The followi...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Web Help Desk. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-26399.
Le systèmes informatiques du Comune di Forlì ont été victimes d'une attaque non autorisée, mais aucune preuve de fuite de données personnelles n'a été trouvée pour le moment. Les procédures de sécurité ont été activées et des vérifications techniques sont en cours. Certains systèmes et services numé...
This vulnerability allows local attackers to escalate privileges on affected installations of Gen Digital CCleaner. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Some interaction on the part of an administrator i...
Okuma Europe GmbH, une filiale d'Okuma Corporation, a subi une attaque de ransomware, ce qui a entraîné une infection de son serveur et un risque possible d'exfiltration de données personnelles et d'informations confidentielles. L'entreprise travaille actuellement avec des experts externes pour enqu...
La société Thermofin a été victime d'une attaque cybernétique massive, entraînant des fuites de données, y compris des informations sur les employés. L'entreprise est actuellement seulement accessible de manière limitée via une hotline. Les filiales en Chine et en Pologne sont également touchées.
One of the reasons we opposed the TikTok "ban" is that the First Amendment is supposed to protect us from government using its power to manipulate speech. But as predicted, the TikTok "ban" has only resulted in turning over the platform to the allies of a president who seems to have no respect for t...
L'attaque n'a pas été revendiquée, mais l'enseigne Qilin divulgue des données présentées comme issues des systèmes de Herker.
L'attaque n'a pas été revendiquée, mais l'enseigne Qilin divulgue des données présentées comme issues des systèmes du Turf Valley Resort.
SEO poisoning campaign "Operation Rewrite” uses a malicious IIS module called BadIIS to redirect users to unwanted websites.
The post Operation Rewrite: Chinese-Speaking Threat Actors Deploy BadIIS in a Wide Scale SEO Poisoning Campaign appeared first on Unit 42.
Lumena Financial Strategies suffered a data breach after a threat actor accessed their computer systems using ransomware. The breach occurred on September 23, 2025, and potentially exposed client information including names, dates of birth, home addresses, social security numbers, banking informatio...
InsightinHealth, Inc. suffered a data breach after an unauthorized actor gained access to their network by exploiting a previously unknown vulnerability in a third-party application. The breach occurred between September 17, 2025, and September 23, 2025, and may have impacted certain files stored on...
October 1, 2025: This post was updated to reflect the new name of Security Hub, which is AWS Security Hub CSPM (Cloud Security Posture Management). Security teams must efficiently validate and document exceptions to AWS Security Hub (Cloud Security Posture Management, previously known as Security Hu...
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.
This is the fourth installment in a blog series documenting EFF's findings from the Stop Censoring Abortion campaign. You can read additional posts here.Â
One of the goals of our Stop Censoring Abortion campaign was to put names, stories, and numbers to the experiences we’d been hearing about: peopl...
LinkedIn will share your public data with Microsoft to train AI. Find what this means for your privacy and how to opt out.
Experts at a Gartner event highlighted areas of focus in identity, processes and third-party risk management to tackle the novel tactics employed by Scattered Spider
Le conseil d’administration du 19 septembre 2025 a élu Odile Duthil à la présidence du Clusif. Loïc Guézo, Anne Doré, Michel Dubois ont été réélus au bureau. « Je remercie Benoît Fuzeau pour son engagement et tout le travail réalisé. Sous sa présidence, le Clusif a acquis une nouvelle dimension nat...
MITRE said it understands why Microsoft, SentinelOne and Palo Alto pulled out of its 2025 of ATT&CK Evaluations test – and promises to do better next year