UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal…
Tag: Security Affairs
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum…
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has…
CareCloud Breach Exposes Medical and Financial Data of 345,000
CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that…
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter…
Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email…
CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday,…
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence…
Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed…
South Korea Warns of State-Backed Watering Hole Attacks
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies…
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s…
What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature…
Anthropic Finds Claude Breached Real Companies During Security Evaluations
Anthropic says a misconfigured test let Claude access three real organizations, prompting tighter AI evaluation and monitoring controls. Anthropic…
SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign
SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL…
Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
Researchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and…
Why brand impersonation is becoming an initial access vector
Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks.…
Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents
Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how…
Analog Devices Discloses Data Breach After Unauthorized System Access
Chipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing. Semiconductor…
FCC Restricts New Foreign Robots and Inverters Over Security Risks
The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC…
U.S. CISA adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited…
