Aggregator
CVE-2025-55208 | Chamilo LMS up to 1.11.33 cross site scripting (GHSA-2vq2-826h-6hp6)
CVE-2025-70949 | perfood couch-auth 0.26.0 timing discrepancy
CVE-2026-28350 | fedora-python lxml_html_clean up to 0.4.3 escape output (GHSA-xvp8-3mhv-424c / Nessus ID 301400)
Armadin secures $189.9 million to counter AI-driven cyber threats
Armadin has raised $189.9 million in Seed and Series A funding. Led by Accel, with participation from Google Ventures, Kleiner Perkins, Menlo Ventures, In-Q-Tel, and follow-on investment from 8VC and Ballistic Ventures, this marks the largest combined Seed and Series A funding round in cybersecurity history. Armadin’s mission is to prepare organizations for the speed and scale of AI-driven threats. Closing the hyperattack gap AI-powered attackers are launching faster, more complex campaigns that overwhelm security … More →
The post Armadin secures $189.9 million to counter AI-driven cyber threats appeared first on Help Net Security.
Удаление писем, кража данных и новая религия. Как новые ИИ-помощники захватывают компьютеры
运动时肠道细菌会重写与大脑的化学对话
OAuth Device Code Phishing: A New Microsoft 365 Account Breach Vector
ANY.RUN’s analysts are observing a sharp increase in phishing activity abusing Microsoft’s OAuth Device Code flow, with more than 180 phishing URLs detected in just one week. This technique represents a shift from credential phishing to token-based account takeover, making detection significantly harder for many SOC teams. Key Takeaways How the Attack Works In this campaign, attackers abuse Microsoft’s device […]
The post OAuth Device Code Phishing: A New Microsoft 365 Account Breach Vector appeared first on ANY.RUN's Cybersecurity Blog.
Teen crew caught selling DDoS attack tools
Seven minors who distributed online programs designed to facilitate DDoS attacks have been identified by Poland’s Central Bureau for Combating Cybercrime (CBZC). They were between 12 and 16 at the time of the crime. CBZC officer during a cybercrime investigation (Source: Poland’s Central Bureau for Combating Cybercrime) According to investigators, using the tools they administered, the minors attacked popular websites, including auction and sales portals, IT domains, hosting services and accommodation booking sites. The activity … More →
The post Teen crew caught selling DDoS attack tools appeared first on Help Net Security.