Aggregator
How I Hack Websites With Just HTML Injection
Salesloft Drift data breach: Investigation reveals how attackers got in
The attack that resulted in the Salesloft Drift data breach started with the compromise of the company’s GitHub account, Salesloft confirmed this weekend. Supply chain compromise On August 26, the company publicly revealed that earlier that month, a threat actor exfiltrated data from their customers’ Salesforce instances by leveraging stolen OAuth credentials that enable the integration of their Drift (Salesloft) chatbot with said instances. Google Threat Intelligence Group attributed the attack to an attack group … More →
The post Salesloft Drift data breach: Investigation reveals how attackers got in appeared first on Help Net Security.
Спам-ловушки поймали команду Трампа. Эстонские эксперты разрушили миф 'Gmail против правых'
CVE-2014-125128 | sanitize-html up to 1.0.2 Anchor Tag naughtyHref cross site scripting
CVE-2019-25225 | sanitize-html 1.4.3 index.js sanitizeHtml transformTags cross site scripting (Issue 293 / EUVD-2019-19375)
CVE-2025-5993 | ITCube CRM up to 2025.2 fileName path traversal
Chaining Path Traversal Vulnerability to RCE — Meta’s 111,750$ Bug
CVE-2023-21044 | Google Android init out-of-bounds (A-253425086 / EUVD-2023-25212)
CVE-2023-21045 | Google Android cpif out-of-bounds (A-259323725 / EUVD-2023-25213)
CVE-2023-21042 | Google Android use after free (A-239873326 / EUVD-2023-25210)
CVE-2023-21043 | Google Android use after free (A-239872581 / EUVD-2023-25211)
CVE-2023-21039 | Google Android Dumpstate.cpp dumpstateBoard out-of-bounds (A-263783650 / EUVD-2023-25207)
CVE-2023-21040 | Google Android bluetooth_ccc.cc buildCommand out-of-bounds write (A-238420277 / EUVD-2023-25208)
CVE-2023-21041 | Google Android param_util.c append_to_params out-of-bounds write (A-250123688 / EUVD-2023-25209)
CVE-2023-21038 | Google Android 24000736 cs40l2x.c cs40l2x_cp_trigger_queue_show out-of-bounds write (A-224000736 / EUVD-2023-25206)
Hunting OS Command Injection
8th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 8th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES A supply chain breach involving Salesloft’s Drift integration to Salesforce exposed sensitive customer data from multiple organizations, including Cloudflare, Zscaler, Palo Alto Networks, and Workiva. The attackers accessed Salesforce CRM systems via […]
The post 8th September – Threat Intelligence Report appeared first on Check Point Research.
AI in Government
Just a few months after Elon Musk’s retreat from his unofficial role leading the Department of Government Efficiency (DOGE), we have a clearer picture of his vision of government powered by artificial intelligence, and it has a lot more to do with consolidating power than benefitting the public. Even so, we must not lose sight of the fact that a different administration could wield the same technology to advance a more positive future for AI in government.
To most on the American left, the DOGE end game is a dystopic vision of a government run by machines that benefits an elite few at the expense of the people. It includes AI ...
The post AI in Government appeared first on Security Boulevard.