Aggregator
CVE-2025-8557 | Lenovo XClarity Orchestrator up to 2.1.x LXCO API Service unprotected alternate channel
CVE-2025-43788 | Liferay Portal/DXP Organization Selector authorization (EUVD-2025-29005 / WID-SEC-2025-2041)
CVE-2025-10094 | GitLab Community Edition/Enterprise Edition up to 18.1.5/18.2.5/18.3.1 Token improper validation of specified quantity in input (Patch 528469 / EUVD-2025-29016)
CVE-2025-36222 | IBM Fusion/Fusion HCI/Fusion HCI for Watsonx up to 2.10.1 insecure default initialization of resource
Vimeo 以 13.8 亿美元出售给 Bending Spoons
AMD, Intel и все облачные провайдеры. Уязвимость в популярных процессорах ставит под угрозу безопасность виртуальных машин по всему миру.
CISOs brace for a new kind of AI chaos
AI is being added to business processes faster than it is being secured, creating a wide gap that attackers are already exploiting, according to the SANS Institute. The scale of the problem Attackers are using AI to work at speeds that humans cannot match. Phishing messages are more convincing, privilege escalation happens faster, and automated scripts can adjust mid-attack to avoid detection. The report highlights research showing that AI-driven attacks can move more than 40 … More →
The post CISOs brace for a new kind of AI chaos appeared first on Help Net Security.
Attackers are coming for drug formulas and patient data
In the pharmaceutical industry, clinical trial data, patient records, and proprietary drug formulas are prime targets for cybercriminals. These high-value assets make the sector a constant focus for attacks. Disruptions to research or medicine distribution can have life-threatening consequences. “During global health crises, cyber attackers swiftly exploit vulnerabilities. The COVID-19 pandemic saw a fivefold increase in phishing attempts targeting WHO, with attackers impersonating leadership to distribute malware,” said Flavio Aggio, CISO at the World Health … More →
The post Attackers are coming for drug formulas and patient data appeared first on Help Net Security.
Google убивает блокировщики рекламы. Что делать, чтобы uBlock Origin продолжал работать в Chrome?
ZDI-CAN-26000: CyberArk
Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories
美国政府漏洞经纪人称“苹果最新的iPhone安全特性让间谍软件制造商的生活更加艰难”
Google объявил войну фотошопу: теперь каждый пиксель будет «стучать» на владельца
お知らせ:JPCERT/CC Eyes「解説:脆弱性関連情報取扱制度の運用と今後の課題について(前編)~公益性のある脆弱性情報開示とは何か~」
Ransomware, vendor outages, and AI attacks are hitting harder in 2025
Ransomware, third-party disruptions, and the rise of AI-powered attacks are reshaping the cyber risk landscape in 2025. A new midyear analysis from Resilience shows how these forces are playing out in real-world incidents and how they are changing the financial impact of attacks on organizations across sectors. The report, based on cyber insurance claims, offers a view into which attacks are hitting hardest and where vulnerabilities are emerging. For CISOs, the findings highlight where defenses … More →
The post Ransomware, vendor outages, and AI attacks are hitting harder in 2025 appeared first on Help Net Security.