Aggregator
Lynx
CVE-2025-28028 | TOTOLINK A830R/A950RG/A3000RU/A3100R downloadFile.cgi v5 buffer overflow
Как пара физиков доказали невозможное: точная формула для очищения квантовой запутанности таки существует
CVE-2024-47829 | pnpm up to 9.x MD5 /node_modoules/ weak hash (GHSA-8cc4-rfj6-fhg4)
CVE-2025-32968 | xwiki-platform up to 15.10.15/16.4.5/16.10.0 sql injection (GHSA-g9jj-75mx-wjcx)
CVE-2025-32966 | DataEase up to 2.10.7 Backend JDBC link authentication spoofing (GHSA-h7hj-4j78-cvc7)
CVE-2025-32969 | xwiki-platform up to 15.10.15/16.4.5/16.10.0 sql injection (GHSA-f69v-xrj8-rhxf)
CVE-2025-21605 | Redis up to 7.4.2 allocation of resources (GHSA-r67f-p999-2gff)
Popular British Retailer Marks & Spencer Addresses 'Cyber Incident'
Massive Increase to Unwanted Cell Calls
Something happened this weekend — starting on Monday my cellphone has been lighting up with unknown callers — a 30x increase!
I rarely give out the number so I assume one of the following:
- Ended up on a cybercriminal call-list because of a Data Breach from one of the few vendors that actually do have my cell number. Might have been Hertz or perhaps one of the databases on Oracle. Could be an unannounced breach. Not sure.
- Cybersecurity sales vendors, preparing for RSA somehow acquired my number as part of a purchased marketing list (if I ever find out who did this I will call them out and advise everyone to never use their products), making a massive unethical call campaign that I somehow got caught up in.
- Perhaps a Nation State actor that I perturbed is seeking to compromise my phone. I have been talking and doing media interviews calling out aggressive state sponsored hacking from China, Russia, North Korea, and Iran. The calls are highly persistent, even though they are not getting anywhere. Given the vastly dispersed number range (looks to be a prodigious use of spoofed CallerID numbers) they are determined even though I do not answer. A sales team or criminal should have moved on by now.
I do find it amusing and intellectually intriguing, from a cybersecurity perspective!
Some details:- So far I see a 30x increase in calls, all starting Monday
- A huge range of numbers, one after the other but never at the same time
- All the numbers are from the US. Appears to be spoofed Caller ID numbers
- Never leaves a voicemail
- Are not sending SMS text messages — which is interesting…
- I don’t see any equitable rise in email phishing, this is only phone calls
- I NEVER answer my cell unless it is a number I know. Never. I follow a whitelist methodology when it comes to calls
- I immediately BLOCK the number. Yup, I force them to spoof another CallerID number
- If a salesperson does cold-call my cell I make a note and will NEVER use their products
- Shields-Up! Now I am on-guard.
- I am paying extra attention to every DM, text, and email. I am even vetting known numbers.
- I am double checking all my OS & apps patch levels across my all my PC’s and servers, and will do an unscheduled full backup of critical data (that I store offline is a safe).
- Lastly, I am scanning my systems, removing any old or unneeded apps, and scrutinizing every running Process and device on my network.
…these are all things I like to do anyways, so it really is no bother.
Overall, it has been interesting and I am so tempted to answer a call to just to investigate. But that would be in opposition to what I preach.
Anyone else experiencing such a flood of undesired calls the past few days?
The post Massive Increase to Unwanted Cell Calls appeared first on Security Boulevard.
North Korean Operatives Use Deepfakes in IT Job Interviews
Restoring Trust in Business Communications
At IRONSCALES, we believe trust is the bedrock of every business conversation. Whether it's a deal being negotiated, a partner being onboarded, or a CEO addressing their workforce, trust underpins it all. Yet, as we step into the era of Phishing 3.0, that trust is under siege.
The post Restoring Trust in Business Communications appeared first on Security Boulevard.
Meta Fined 200 Million Euros for its 'Pay or Consent' Model
European regulators said Facebook conducted an end run around privacy regulations by requiring users to pay a monthly subscription fee or else accept that their personal data would be fed to advertisers. The European Commission fined the social media giant 200 million euros.
Kelly Benefits Notifying Nearly 264,000 of Data Theft Hack
Kelly Benefits is notifying nine large clients and nearly 264,000 individuals that their sensitive personal information was potentially compromised in a December data theft incident. The tally of affected people has climbed eight-fold since the company's first estimate earlier this month.
BSidesLV24 – Common Ground – Securing Your Cloud-Native DevOps: A Zero Trust Approach
Author/Presenter: Emma Fang
Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel.
The post BSidesLV24 – Common Ground – Securing Your Cloud-Native DevOps: A Zero Trust Approach appeared first on Security Boulevard.