[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 08:00

> ZDI-25-839: Microsoft Teams Real Time Media Manager Integer Underflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Teams. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-53783.
> ZDI-25-838: (Pwn2Own) Microsoft Windows 11 vhdmp Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The follow...
> Google Jules: Vulnerable to Multiple Data Exfiltration Issues
This post explores data exfiltration attacks in Google Jules, an asynchronous coding agent. This is the first of three posts that will highlight my research on Google Jules in May 2025. All information provided was also shared with Google at that time. This first post will focus on data exfiltration...
> ZDI-25-833: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. Th...
> Datadog threat roundup: Top insights for Q2 2025
Threat insights from Datadog Security Labs for Q2 2025.
> University of St. Thomas
Une tentative de piratage a visé les serveurs de l'Université de St. Thomas, entraînant une interruption des services en ligne, mais aucune donnée n'a été compromise selon l'université. Les équipes de sécurité enquêtent sur l'incident et travaillent à rétablir les services le plus rapidement possibl...
> Orchid Island Golf and Beach Club
Orchid Island Golf and Beach Club suffered a data breach where an unauthorized third party gained access to their network and took certain data files from their server, potentially exposing personal information of employees and previous employees.
> That 16 Billion Password Story (AKA "Data Troll")
Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.Spoiler: I have data from the story in the title of this post, it's mostly what I expected it to be, I've just added it to HIBP where I've called it "Data Troll", and I'm going to give ev...
> Donelan's Supermarkets, Inc.
Donelan's Supermarkets experienced a network security incident where an unauthorized third-party accessed their network environment, potentially exposing personal information of customers. The incident occurred on or about August 14, 2025, and was discovered on the same date. The company is providin...
> Marquis Software Solutions
Marquis Software Solutions experienced a data security incident where an unauthorized third party accessed their network and may have accessed and acquired certain files. The incident was limited to Marquis' environment, and the company has no evidence of the misuse of personal information. The comp...
> Data Troll Stealer Logs - 109,532,219 breached accounts
In June 2025, headlines erupted over a "16 billion password" breach. In reality, the dataset was a compilation of publicly accessible stealer logs, mostly repurposed from older leaks, with only a small portion of genuinely new material. HIBP received 2.7B rows containing 109M unique email addresses,...
> North Metro Harness Initiative, LLC dba Running Aces
North Metro Harness Initiative, LLC dba Running Aces experienced a data security incident between July 27, 2025, and August 14, 2025, potentially impacting personal information of customers. A cyberattack against Running Aces was claimed by Qilin on September 8.
> Michigan Sugar
Michigan Sugar Company suffered a data breach on August 14, 2025, where an unauthorized third party gained access to certain systems in its network, potentially resulting in the unauthorized access and acquisition of personal information. An attack was claimed by Akira on September 5.
> Erlang/OTP SSH Vulnerability Sees Spike in Exploitation Attempts
A critical RCE vulnerability in Erlang’s OTP SSH daemon has been identified that allows unauthenticated command execution
> Centers Laboratory
Centers Laboratory, une entreprise de diagnostic de santé basée dans le New Jersey, a informé le gouvernement américain d'une violation de données découverte il y a près d'un an. L'intrusion, qui a eu lieu entre le 9 et le 14 août 2025, a permis aux acteurs de la menace d'exfiltrer des informations...
> Deepfake AI Trading Scams Target Global Investors
AI-powered trading platforms have been observed exploiting deepfake technology to trick investors with fake endorsements
> Staffing Company Manpower Discloses Data Breach
The personal data of almost 145,000 people who were registered in Manpower’s systems was compromised
> Why more transparency around cyber attacks is a good thing for everyone
Eleanor Fairford, Deputy Director of Incident Management at the NCSC, and Mihaela Jembei, Director of Regulatory Cyber at the Information Commissioner’s Office (ICO), reflect on why it’s so concerning when cyber attacks go unreported – and look at some of the misconceptions about how organisations r...
> St. Paul’s Mayor Confirms Interlock Data Leak
Mayor of St. Paul, Minnesota, Melvin Carter, confirmed that employee data was published online by the Interlock ransomware gang
> Ransomware: 'WannaCry' guidance for enterprise administrators
Guidance for enterprise administrators who want to reduce the likelihood of being held to ransom by WannaCry (or other types of ransomware).