Category: eSecurity Planet

ServiceNow AI Flaw Allows Unauthenticated User Impersonation

CVE-2025-12420 enables unauthenticated ServiceNow user impersonation. The post ServiceNow AI Flaw Allows Unauthenticated User Impersonation appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: ServiceNow AI Flaw Allows Unauthenticated User Impersonation

Red-Teaming BrowseSafe Exposes AI Browser Guardrail Gaps

Red-team testing shows encoded prompt injections can bypass BrowseSafe guardrails. The post Red-Teaming BrowseSafe Exposes AI Browser Guardrail Gaps  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: Red-Teaming BrowseSafe Exposes AI…

Why the Start of the Year Is Prime Time for Insider Risk

As workforce transitions accelerate, identity becomes the primary attack surface, increasing insider risk. The post Why the Start of the Year Is Prime Time for Insider Risk  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet…

Why DNS Resiliency Is Critical as Outages Surge

As outages grow more frequent, DNS resiliency is critical to keeping services online when primary systems fail. The post Why DNS Resiliency Is Critical as Outages Surge  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet…

BreachForums Data Breach Exposes Nearly 324,000 Users

A January 2026 breach exposed data on nearly 324,000 BreachForums users, weakening Dark Web anonymity and aiding investigations. The post BreachForums Data Breach Exposes Nearly 324,000 Users appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet…

377,000 Affected in Texas Gas Station Operator Breach

A phishing attack at Texas fuel operator Gulshan Management Services exposed personal data of more than 377,000 individuals. The post 377,000 Affected in Texas Gas Station Operator Breach appeared first on eSecurity Planet. This article has been indexed from eSecurity…

AI Deployments Targeted in 91,000+ Attack Sessions

Researchers observed over 91,000 attack sessions targeting AI infrastructure and LLM deployments. The post AI Deployments Targeted in 91,000+ Attack Sessions  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: AI Deployments…

Trend Micro Apex Central Flaws Enable Remote Code Execution

Trend Micro patched three Apex Central flaws that could allow unauthenticated remote code execution or service disruption. The post Trend Micro Apex Central Flaws Enable Remote Code Execution  appeared first on eSecurity Planet. This article has been indexed from eSecurity…

OWASP CRS Flaw Lets Encoded Attacks Slip Past WAFs

A critical OWASP CRS flaw allows encoded XSS attacks to bypass WAF charset validation. The post OWASP CRS Flaw Lets Encoded Attacks Slip Past WAFs appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the…

GenDigital Research Exposes AuraStealer Infostealer Tactics

GenDigital researchers reveal how AuraStealer uses advanced evasion and a MaaS model to steal data from Windows systems. The post GenDigital Research Exposes AuraStealer Infostealer Tactics appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…

Cisco ISE Flaw Lets Admins Access Restricted System Files

A Cisco ISE flaw lets authenticated admins access restricted system files, risking sensitive data exposure. The post Cisco ISE Flaw Lets Admins Access Restricted System Files appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…

Cisco Snort 3 Security Flaws Threaten Network Inspection

Cisco Snort 3 flaws allow unauthenticated attacks that disrupt inspection or leak sensitive data. The post Cisco Snort 3 Security Flaws Threaten Network Inspection appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original…

50,000 Servers Exposed as GoBruteforcer Scales Brute-Force Attacks

GoBruteforcer is exploiting weak credentials to compromise thousands of exposed Linux servers. The post 50,000 Servers Exposed as GoBruteforcer Scales Brute-Force Attacks appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: 50,000…

Critical n8n Vulnerability Enables Authenticated RCE

A critical n8n vulnerability allows authenticated users to execute arbitrary code, putting automation workflows at risk. The post Critical n8n Vulnerability Enables Authenticated RCE appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original…

1M Customer Records Allegedly Stolen in Brightspeed Breach

Brightspeed is investigating claims that the Crimson Collective stole data from more than one million customers. The post 1M Customer Records Allegedly Stolen in Brightspeed Breach appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read…

Flare Researchers Analyze SafePay Ransomware Leak Data

Flare researchers analyzed SafePay leak data, showing how the group targets regulated SMBs to maximize pressure. The post Flare Researchers Analyze SafePay Ransomware Leak Data appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the…