Aggregator
CVE-2025-6233 | Mattermost up to 9.11.16/10.5.7/10.7.3/10.8.1 JSONL File Import path traversal (EUVD-2025-21866 / Nessus ID 242669)
CVE-2025-46786 | Zoom Workplace Desktop App up to 6.3.x neutralization (Nessus ID 236763)
Cryptohack Roundup: White House Pulls CFTC Chair Nom
This week, Brian Quintenz won't lead the U.S. CFTC, Canada fined KuCoin $14M, Texas brothers charged in an $8M kidnapping case, South Korean actor given suspended sentence for embezzlement, phishing campaign used robots.txt and an ex-LASD deputy pleaded guilty in a business extortion scam.
Hospital Chain to Pay $7.6M to Settle Breach Litigation
A network of 13 Catholic hospitals, community health centers and clinics in the Midwest will pay $7.6 million and implement improvements to its data security practices to settle consolidated class action litigation filed in the aftermath of a 2023 hacking incident affecting nearly 900,000 people.
Descope Gets $35M for AI Agent Identity Controls, Governance
Descope raised $35 million to expand its agentic identity hub and MCP authorization capabilities. As enterprises adopt AI, CISOs demand granular governance, auditing and secure identity frameworks for nonhuman agents. Descope aims to lead this emerging space.
Breach Roundup: FTC Sues Sendit Over Kid's Data Collection
This week, FTC sued Sendit, another Harrods breach, Allianz data breach and a cyberattack disrupted Asahi's Japan operations. WestJet disclosed data theft. Hackers targeted Kido Nursery chain, a VMware privilege escalation flaw was exploited as zero-day, DarkCloud infostealer resurfaced.
Daily Dose of Dark Web Informer - 1st of October 2025
Red Hat confirms breach of GitLab instance, which stored company’s consulting data
The open-source software company said exposure is limited to consulting engagements, adding that it hasn’t found evidence of personal or sensitive data theft.
The post Red Hat confirms breach of GitLab instance, which stored company’s consulting data appeared first on CyberScoop.
CVE-2025-2905 | WSO2 API Manager up to 2.0.0 XML Parser xml external entity reference
CVE-2025-25014 | Elastic Kibana up to 8.17.5/8.18.0/9.0.0 Machine Learning/Reporting prototype pollution
Renault UK Customer Records Stolen in Third-Party Breach
IOC Alert: Telegram Bot API Abused for XWorm C2 Communications
Hacker Stole Sensitive Data From FEMA, Border Patrol: Reports
An assessment by DHS found that hackers were able to access FEMA servers by exploiting the CitrixBleed 2 vulnerability and steal data from both that agency and the border patrol office, contradicting an earlier statement by Homeland Security Secretary Kristi Noem that no personal information was taken during the weeks-long breach.
The post Hacker Stole Sensitive Data From FEMA, Border Patrol: Reports appeared first on Security Boulevard.
Lynx
You must login to view this content
Ransom House
You must login to view this content
Top 10 Best Brand Protection Solutions for Enterprises in 2025
Brand protection solutions are essential for enterprises in 2025 as digital commerce continues to grow and online threats evolve more rapidly than ever. With the surge in counterfeit products, trademark infringements, phishing attacks, and reputation risks, enterprises must safeguard their intellectual property and digital assets. Choosing the right brand protection tool not only builds consumer […]
The post Top 10 Best Brand Protection Solutions for Enterprises in 2025 appeared first on Cyber Security News.
Here is the email Clop attackers sent to Oracle customers
The emails, which are littered with broken English, aim to instill fear, apply pressure, threaten public exposure and seek negotiation for a ransom payment.
The post Here is the email Clop attackers sent to Oracle customers appeared first on CyberScoop.