Aggregator
CVE-2025-50179 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition cross-site request forgery (GHSA-rxpm-g7gw-4mrv / EUVD-2025-19103)
CVE-2025-5309 | BeyondTrust Remote Support/Privileged Remote Access up to 24.2.4/24.3.4/25.1.1 Chat code injection (bt25-04 / EUVD-2025-18420)
每周勒索威胁摘要
每周勒索威胁摘要
Breach Roundup: Scattered Spider Hacker Gets 10 Years
This week, a Scattered Spider hacker sentenced, new squishing tricks, a pro-Houthi hacker gets 20 months in the United Kingdom, a Taiwanese web hosting provider hacked, the Business Council of New York and Ohio Medical Cannabis Center breached, North Korean hackers target Seoul and an Apple Patch.
Nuance Agrees to Pay $8.5M to Settle MOVEit Hack Litigation
Nuance Communications, a Microsoft subsidiary, has agreed to pay $8.5 million to settle class action litigation filed after hackers exploited a zero-day flaw in Progress Software's MOVEit file transfer software in 2023, stealing data belonging to more than a dozen of Nuance's healthcare clients.
Menlo-Votiro Deal Integrates File Protection With Browsers
Through its acquisition of Votiro, Menlo Security has embedded file-level sanitization and AI-powered detection directly into its enterprise browser stack. CEO Amir Ben-Efraim says the move helps prevent malware, data leaks and phishing risks at the browser level.
Copilot Kept Access Logs Unless You Told It Not To
Microsoft quietly fixed a flaw that allowed users to instruct embedded artificial intelligence model Copilot not to log its access corporate files. "If you work at an organization that used Copilot prior to Aug 18, there is a very real chance that your audit log is incomplete."
Breach Roundup: Scattered Spider Hacker Gets 10 Years
This week, a Scattered Spider hacker sentenced, new squishing tricks, a pro-Houthi hacker gets 20 months in the United Kingdom, a Taiwanese web hosting provider hacked, the Business Council of New York and Ohio Medical Cannabis Center breached, North Korean hackers target Seoul and an Apple Patch.
Nuance Agrees to Pay $8.5M to Settle MOVEit Hack Litigation
Nuance Communications, a Microsoft subsidiary, has agreed to pay $8.5 million to settle class action litigation filed after hackers exploited a zero-day flaw in Progress Software's MOVEit file transfer software in 2023, stealing data belonging to more than a dozen of Nuance's healthcare clients.
Menlo-Votiro Deal Integrates File Protection With Browsers
Through its acquisition of Votiro, Menlo Security has embedded file-level sanitization and AI-powered detection directly into its enterprise browser stack. CEO Amir Ben-Efraim says the move helps prevent malware, data leaks and phishing risks at the browser level.
Copilot Kept Access Logs Unless You Told It Not To
Microsoft quietly fixed a flaw that allowed users to instruct embedded artificial intelligence model Copilot not to log its access corporate files. "If you work at an organization that used Copilot prior to Aug 18, there is a very real chance that your audit log is incomplete."
Hello community!
New infosec products of the week: August 22, 2025
Here’s a look at the most interesting products from the past week, featuring releases from Doppel, Druva, LastPass, and StackHawk. StackHawk empowers security teams to expand their API testing coverage StackHawk releaseed LLM-Driven OpenAPI Specifications, a powerful new capability that creates API documentation directly from source code. With this new capability, StackHawk analyzes source code repositories, extracts API details using homegrown LLMs, and produces accurate OpenAPI specifications automatically. Doppel Simulation combats social engineering attacks Informed … More →
The post New infosec products of the week: August 22, 2025 appeared first on Help Net Security.
非洲受野火影响最严重
非洲受野火影响最严重
US Officials Claim to Have Gained Control of the RapperBot
Overview Recently, US officials claimed to have successfully gained control of RapperBot, effectively curbing this powerful source of DDoS attacks. The operation pinpointed the key figure behind the botnet, Ethan Foltz. According to the investigation, Foltz has been developing and operating RapperBot since 2021, with his residence in Eugene, Oregon, USA. Since its activity, the […]
The post US Officials Claim to Have Gained Control of the RapperBot appeared first on NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks..
The post US Officials Claim to Have Gained Control of the RapperBot appeared first on Security Boulevard.