Aggregator
CVE-2025-11192 | Extreme Fabric Engine up to 9.2 SD-WAN AutoSense improper authentication (EUVD-2025-32906)
CVE-2025-59342 | esm-dev esm.sh up to 136 HTTP Header X-Zone-Id path traversal (GHSA-g2h5-cvvr-7gmw / EDB-52461)
印度重申对中巴经济走廊的反对立场及对我风险评估
间谍如何炼成,揭秘十大间谍招募术与心理战
Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network
Microsoft released security updates on January 13, 2026, addressing a critical elevation of privilege vulnerability in SQL Server that enables authorized attackers to bypass authentication controls and gain elevated system privileges remotely. Tracked as CVE-2026-20803, the vulnerability stems from missing authentication mechanisms for critical functions within the database engine. The flaw affects multiple SQL Server […]
The post Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network appeared first on Cyber Security News.
PharMerica Will Pay at Least $5.2M to Settle Hack Lawsuit
Pharmacy services firm PharMerica will pay at least $5.27 million - plus millions more on enhancing its security - as part of a preliminary class action settlement approved this week by a federal court involving a 2023 data theft incident the company reported as affecting 5.8 million individuals.
Court Axes Investor Lawsuit Over CrowdStrike Software Update
A U.S. district judge tossed most claims from investors accusing CrowdStrike of misrepresenting its software testing rigor before a July 2024 outage. The judge said two statements about federal compliance could plausibly be misleading, but said plaintiffs failed to establish intent or recklessness.
Incorporating Geopolitical Risk Into Your IT Strategy
IT organizations know how to plan for outages, but even the most rigorously designed strategy is vulnerable to the shifting winds of geopolitics. CIOs and technology leaders need to know how their organizations will respond to geopolitical disruptions, and scenario planning needs to be a priority.
ChatGPT's upcoming cross-platform feature is codenamed "Agora"
Microsoft, Law Enforcement Disrupt RedVDS Global Cybercrime Service
Microsoft and law enforcement agencies in Europe disrupted the operations of RedVDS, a global cybercrime service that sold cheap and disposable dedicated virtual servers to threat actors that used them to run BEC, phishing, and other fraud campaigns. The vendor now wants to shut down its payment networks and find the operators behind it.
The post Microsoft, Law Enforcement Disrupt RedVDS Global Cybercrime Service appeared first on Security Boulevard.