Aggregator
CVE-2023-1990 | Linux Kernel ndlc.c ndlc_remove use after free (EUVD-2023-24170 / Nessus ID 239841)
Croatian research institute confirms ransomware attack via ToolShell vulnerabilities
The Ruđer Bošković Institute (RBI), the largest Croatian science and technology research institute, has confirmed that it was the one of “at least 9,000 institutions worldwide” that were attacked using the Microsoft SharePoint “ToolShell” vulnerabilities. The attack happened on Thursday, July 31, 2025, and resulted in the deployment of ransomware. “The ransomware attack affected part of the network related to the business processes of the [Institute]’s administrative and professional services, and all those documents and … More →
The post Croatian research institute confirms ransomware attack via ToolShell vulnerabilities appeared first on Help Net Security.
Hackers Deploy Dedicated Phishlet for FIDO Authentication Downgrade Attacks
Proofpoint researchers have uncovered a novel technique allowing threat actors to bypass FIDO-based authentication through downgrade attacks, leveraging a custom phishlet within adversary-in-the-middle (AiTM) frameworks. This method exploits gaps in browser compatibility and user agent handling, forcing victims to revert to less secure multi-factor authentication (MFA) mechanisms, thereby enabling credential theft and session hijacking. While […]
The post Hackers Deploy Dedicated Phishlet for FIDO Authentication Downgrade Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Deepfake-кандидаты и ИИ-подсказки на интервью заставили компании снова смотреть людям в глаза
DevSecOps Pipeline Checklist → are you doing enough for security in CI/CD?
If It Builds, It Should Be Secure Let’s be honest, your CI/CD pipeline probably wasn’t designed with security in mind. It was built to ship fast, to keep developers happy,...
The post DevSecOps Pipeline Checklist → are you doing enough for security in CI/CD? appeared first on Strobes Security.
The post DevSecOps Pipeline Checklist → are you doing enough for security in CI/CD? appeared first on Security Boulevard.