Aggregator
IOC Alert: NetSupport Manager RAT Payload Delivery – wood-simple[.]com/drip.sym
HashiCorp security advisory (AV25-555)
CVE-2020-24363 | TP-LINK TL-WA855RE V5 20200415-rel37464 Access Control POST Request missing authentication (EDB-49092)
CVE-2025-55177 | Facebook WhatsApp Desktop for Mac Synchronization Message authorization (EUVD-2025-26214)
Так сможет ли робот написать симфонию, создать шедевр? 3 млн фанатов говорят “да”
联合国报告称深圳-香港-广州是全球第一大创新集群
Palo Alto Networks, Zscaler and PagerDuty Hit in Salesforce Linked Data Breaches
CVE-2024-42067 | Linux Kernel up to 6.6.36/6.6.37/6.9.7 bpf set_memory_rox return value (Nessus ID 210060 / WID-SEC-2024-1722)
CVE-2024-42065 | Linux Kernel up to 6.9.7 xe xe_ttm_stolen_mgr_init null pointer dereference (cc796a77985d/a6eff8f9c7e8 / Nessus ID 210060)
CVE-2024-42064 | Linux Kernel up to 6.9.7 AMD Display denial of service (27df59c60714/af114efe8d24 / Nessus ID 210060)
CVE-2024-42066 | Linux Kernel up to 6.9.7 xe integer overflow (79d54ddf0e29/4f4fcafde343 / Nessus ID 210060)
CVE-2024-42063 | Linux Kernel up to 6.1.96/6.6.36/6.9.7 kernel/bpf/devmap.c kmsan_unpoison_memory initialization (Nessus ID 210060 / WID-SEC-2024-1722)
CVE-2024-41098 | Linux Kernel up to 6.6.36/6.9.7 libata-core ata_port_alloc null pointer dereference (119c97ace2a9/8a8ff7e3b736/5d92c7c566dc / Nessus ID 208099)
Zscaler, Palo Alto Networks, SpyCloud among the affected by Salesloft Drift breach
In the wake of last week’s revelation of a breach at Salesloft by a group tracked by Google as UNC6395, several companies – including Zscaler, Palo Alto Networks, PagerDuty, Tanium, and SpyCloud – have confirmed their Salesforce instances were accessed. The companies noted that attackers had only limited access to Salesforce databases, not to other systems or resources. They warned, however, that the stolen customer data could be used for convincing phishing and social engineering … More →
The post Zscaler, Palo Alto Networks, SpyCloud among the affected by Salesloft Drift breach appeared first on Help Net Security.
唯有热爱,可抵岁月漫长
Azure AD Credentials Exposed in Public App Settings File
AI Governance and Risk in Securing Software Supply Chains
Artificial intelligence (AI) is rapidly transforming software development, accelerating innovation, streamlining processes, and opening the door to entirely new capabilities.
The post AI Governance and Risk in Securing Software Supply Chains appeared first on Security Boulevard.