Aggregator
CVE-2025-2418 | TR7 Cyber Defense Web Application Firewall up to 16022026 redirect
BeyondTrust security advisory (AV26-097) - Update 2
LockBit 5.0 ransomware expands its reach across Windows, Linux, and ESXi
The Acronis Threat Research Unit (TRU) has identified a new and significantly enhanced version of the LockBit ransomware, LockBit 5.0, currently being deployed in active campaigns. The latest variant demonstrates expanded cross-platform capabilities, enabling attackers to target Windows, Linux, and VMware ESXi systems within a single coordinated attack. According to analysis, LockBit 5.0 introduces dedicated builds tailored for enterprise environments, reflecting the continued evolution of ransomware-as-a-service (RaaS) operations. By supporting multiple operating systems and virtualization … More →
The post LockBit 5.0 ransomware expands its reach across Windows, Linux, and ESXi appeared first on Help Net Security.
Passwork 7.4 enhances enterprise security with centralized User vault restrictions
Passwork has released version 7.4, introducing restrictive settings for User vaults along with enhancements to improve security and user experience. The update enables administrators to enforce stricter controls over password sharing and distribution, reducing data breach risks and supporting compliance with strong security policies. Key features of Passwork 7.4 Restrictive settings for User Vaults: Administrators can centrally enable or restrict the following actions for all User vaults: Adding users and groups Sending passwords Creating password … More →
The post Passwork 7.4 enhances enterprise security with centralized User vault restrictions appeared first on Help Net Security.
ClawBands GitHub Project Looks to Put Human Controls on OpenClaw AI Agents
A software developer has created ClawBands, a project on GItHub that is designed to put human-in-the-loop controls on OpenClaw, the highly popular personal AI assistant that comes with a range of security risks. At the same time, OpenClaw developer Peter Steinberger is being hired by OpenAI to continue working on such AI agents.
The post ClawBands GitHub Project Looks to Put Human Controls on OpenClaw AI Agents appeared first on Security Boulevard.
CVE-2026-2560 | kalcaddle kodbox up to 1.64.05 Media File Preview Plugin VideoResize.class.php run localFile os command injection
Zr.Ms. Johan de Witt neemt deel aan arctisch Cold Response
Магия закончилась, расходимся. Почему квантовый мир оказался гораздо прозаичнее, чем мы думали
New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware
A sophisticated social engineering campaign targeting macOS users has emerged, deploying a dangerous stealer malware through an evolved version of the ClickFix attack technique. Named “Matryoshka” after the Russian nesting dolls, this variant uses nested obfuscation layers to hide malicious code from security scanners and automated analysis systems. The attack tricks victims into executing Terminal […]
The post New Clickfix Variant ‘Matryoshka’ Attacking Users to Deploy macOS Stealer Malware appeared first on Cyber Security News.
CVE-2026-20624 | Apple macOS up to 14.7/15.6/26.2 App information disclosure (Nessus ID 298657)
CVE-2026-20609 | Apple macOS/watchOS/visionOS/iOS/iPadOS/tvOS up to 26.2 File memory corruption (Nessus ID 298657)
CVE-2026-20620 | Apple macOS up to 14.7/15.6/26.2 Kernel Memory out-of-bounds (Nessus ID 298657)
CVE-2026-20611 | Apple macOS/watchOS/visionOS/iOS/iPadOS/tvOS up to 26.2 Media File out-of-bounds (Nessus ID 298657)
CVE-2025-46283 | Apple macOS up to 26.1 App access control (Nessus ID 298658)
CVE-2025-43338 | Apple iOS/iPadOS/macOS Media File out-of-bounds (Nessus ID 298658 / WID-SEC-2025-2475)
CVE-2025-43533 | Apple tvOS/iOS/iPadOS/visionOS/macOS/watchOS up to 26.1 HID Device memory corruption (EUVD-2025-203980 / Nessus ID 298658)
Microsoft equips CISOs and AI risk leaders with a new security tool
Microsoft released Security Dashboard for AI in public preview for enterprise environments. The dashboard aggregates posture and real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into a single view within security tools. Security Dashboard for AI in browser (Source: Microsoft) “The dashboard equips CISOs and AI risk leaders with a governance tool to discover agents and AI apps, track AI posture and drift, and correlate risk signals to investigate and act across … More →
The post Microsoft equips CISOs and AI risk leaders with a new security tool appeared first on Help Net Security.