Aggregator
Palo Alto Networks Confirms Data Breach via Compromised Salesforce Instances
Cybersecurity vendor Palo Alto Networks disclosed that its Salesforce environment was breached through a compromised Salesloft Drift integration, marking the latest in a series of supply chain attacks targeting customer relationship management platforms. According to a statement from Palo Alto Networks, Salesloft’s Drift application—used by hundreds of organizations to streamline sales engagement—suffered an intrusion that […]
The post Palo Alto Networks Confirms Data Breach via Compromised Salesforce Instances appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-9573 | ns_backup Backup Plus Extension up to 13.0.2 on TYPO3 os command injection (EUVD-2025-26375 / WID-SEC-2025-1941)
CVE-2025-52551 | Copeland LP E2 Facility Management System up to 4.11F02 missing authentication (EUVD-2025-26381)
CVE-2025-8067 | Red Hat Enterprise Linux 6/7/8/9/10 D-BUS Interface out-of-bounds (EUVD-2025-26083 / Nessus ID 258093)
CVE-2025-46810 | openSUSE Tumbleweed up to 2.11.28 symlink (EUVD-2025-26380)
CVE-2024-12973 | Akinsoft OctoCloud up to 1.11.00 HTTP Response origin validation (EUVD-2024-54942)
CVE-2024-12972 | Akinsoft OctoCloud up to 1.11.00 cross site scripting (EUVD-2024-54943)
Google Dismiss Reports of Major Gmail Security Alert
Google has firmly rejected widespread reports suggesting it issued a global security alert to its 2.5 billion Gmail users, calling such claims “entirely false”. The tech giant moved swiftly to clarify the situation after viral headlines sparked unnecessary panic among users worldwide. Recent reports circulated claiming that Google had sent out widespread notifications warning all […]
The post Google Dismiss Reports of Major Gmail Security Alert appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Palo Alto Networks disclosed a data breach linked to Salesloft Drift incident
CVE-2024-52284 | SUSE Rancher up to 0.11.9/0.12.5 BundleDeployment cleartext storage (EUVD-2024-54941)
CVE-2025-0640 | Akinsoft OctoCloud up to 1.11.00 authorization (EUVD-2025-26378)
CVE-2025-57140 | rsbi-pom 4.7 DatasetService sql injection (EUVD-2025-26379)
CVE-2025-56254 | PHPGurukul Employee Leave Management System 2.1 leave-details.php leaveid resource injection (EUVD-2025-26376)
CVE-2024-58259 | SUSE rancher up to 2.9.10/2.10.8/2.11.4/2.12.0 API Endpoint allocation of resources (EUVD-2024-54940)
CVE-2025-2414 | Akinsoft OctoCloud up to 1.11.00 excessive authentication (EUVD-2025-26377)
【金秋校招|京东安全喊你上车!】
Pennsylvania AG Office says ransomware attack behind recent outage
CVE-2025-9845 | code-projects Fruit Shop Management System 1.0 products.php product_code/gen_name/product_name/supplier cross site scripting
OneDrive Phishing Attack Targets Corporate Executives for Credential Theft
A newly discovered spearphishing campaign is targeting executives and senior leadership across multiple industries by exploiting trusted OneDrive document‐sharing notifications. The Stripe OLT SOC has identified this sophisticated attack, which leverages highly tailored emails to impersonate internal HR communications and harvest corporate credentials through a convincing Microsoft Office/OneDrive login page. At the heart of the […]
The post OneDrive Phishing Attack Targets Corporate Executives for Credential Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.