The Breach Beyond the Runway: Cybercriminals Targeted Qantas Through a Trusted Partner
澳大利亚航空因第三方客服平台遭受网络攻击,泄露客户姓名、邮箱、电话号码等信息。调查指向Scattered Spider网络犯罪团伙,FBI已发出警告。建议加强第三方风险管理、员工安全意识培训及异常行为检测等措施以防范类似事件。
A newly disclosed vulnerability, CVE-2025-46647, has been identified in the openid-connect plugin of Apache APISIX, a widely used open-source API gateway. This flaw, rated as important, could allow attackers to gain unauthorized access across different identity issuers under specific misconfigurations. The vulnerability was reported by JunXu Chen to the Apache APISIX development mailing list on July 2, […]
The post Apache APISIX Vulnerability Enables Cross-Issuer Access Under Misconfigurations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.