[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 16:00

> CVE-2025-55316 Azure Connected Machine Agent Elevation of Privilege Vulnerability
Updated CVE title. This is an informational change only.
> CVE-2025-53799 Windows Imaging Component Information Disclosure Vulnerability
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
> Collaborator Everywhere v2
Collaborator Everywhere is a well-known extension for Burp Suite Professional to probe and detect out-of-band pingbacks.  We developed an upgrade to the existing extension with several new exiting features. Payloads can now be edited, interactions are displayed in a separate tab and stored with the...
> CVE-2024-21907 VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json
[CVE-2024-21907](https://www.cve.org/CVERecord?id=CVE-2024-21907) addresses a mishandling of exceptional conditions vulnerability in Newtonsoft.Json before version 13.0.1. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denia...
> CVE-2025-47997 Microsoft SQL Server Information Disclosure Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.
> OS command injection in CLI
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiDDoS-F CLI may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests. Revised on 2025-09-09 00:00:00
> CVE-2025-55227 Microsoft SQL Server Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
> Path traversal in policy scripting
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests. Revised on 2025-09-09 00:00:00
> preparing for the worst
One of these mantras I keep repeating is how we in the curl project keep improving, keep polishing and keep tightening every bolt there is. No one can do everything right from day one, but given time and will we can over time get a lot of things lined up in neat and tidy lines. … Continue reading pr...
> ZDI-25-892: Microsoft .NET IsTypeAuthorized Deserialization of Untrusted Data Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Microsoft .NET. Interaction with the .NET framework is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS ratin...
> Knowledge Base Digest - August 2025
Articles Evil Twin access points not correctly detected by Airspace Monitoring How to use device folders in WatchGuard Cloud Wireless Fireboxes or WatchGuard access points managed by WatchGuard Cloud classified as Rogue AP in Wi-Fi Cloud WIPS Configuration verification failed error message when you...
> Abhe & Svoboda
Abhe & Svoboda, Inc. suffered a data breach resulting in the unauthorized acquisition of personal information of one resident of Maine. The impacted information included the individuals' name and Social Security number. Abhe & Svoboda is offering twelve months of credit monitoring and proactive frau...
> Trailer Transit
Trailer Transit suffered a data breach in September 2025, where unauthorized parties accessed internal systems and stole personal information. The breach was discovered on November 21, 2025, and affected personal data including names, dates of birth, addresses, email addresses, phone numbers, and so...
> 18 Popular Code Packages Hacked, Rigged to Steal Crypto
At least 18 popular JavaScript code packages that are collectively downloaded more than two billion times each week were briefly compromised with malicious software today, after a developer involved in maintaining the projects was phished. The attack appears to have been quickly contained and was na...
> Corban OneSource, LLC
Unauthorized access to certain systems within Corban OneSource, LLC's network occurred on September 9, 2025, resulting in the access of a file containing personal information of two Maine residents. A cyberattack was claimed by Qilin on October 4.
> Credit Technologies, Inc
Credit Technologies Inc. experienced unauthorized access to certain systems and servers, resulting in the potential exposure of protected personal information. The incident occurred on or about September 9, 2025, and was discovered on April 10, 2026. The company is providing complimentary identity m...
> Former WhatsApp security boss in lawsuit likens Meta’s culture to a “cult”
Meta allegedly prioritized user growth over security, lawsuit said.
> Tarter Krinsky & Drogin LLP
Tarter Krinsky & Drogin LLP suffered a data breach between July 9, 2025, and September 9, 2025, resulting in unauthorized access to certain servers and potential exposure of sensitive information. The breach was discovered on September 10, 2025. The firm is offering credit monitoring services to aff...
> Wealthsimple Confirms Data Breach After Supply Chain Attack
Wealthsimple confirmed a third-party vendor data breach affecting roughly 30,000 customers
> MostereRAT Targets Windows Users With Stealth Tactics
Phishing campaign unveiled MostereRAT, targeting Windows systems with advanced evasion techniques