Aggregator
The Alliance of Chaos: How ShinyHunters and Scattered Spider Merged to Target Salesforce
The hacker groups ShinyHunters and Scattered Spider, once operating independently, now appear to have joined forces in a coordinated campaign to extort data from Salesforce’s corporate clients. As noted by ReliaQuest, ShinyHunters has undergone...
The post The Alliance of Chaos: How ShinyHunters and Scattered Spider Merged to Target Salesforce appeared first on Penetration Testing Tools.
国内知名厂商网络摄像头存在新漏洞,可被远程利用进行攻击
Tor, AppArmor и двойная изоляция — Whonix 17.4 закрывает IP даже при взломе браузера
Curly COMrades: The Stealthy Cyber-Espionage Group You Haven’t Heard Of
Bitdefender researchers have identified a previously unknown cyber-espionage group, provisionally dubbed Curly COMrades. According to the report, the threat actors are focused on maintaining long-term, covert access to the infrastructure of Georgian governmental and...
The post Curly COMrades: The Stealthy Cyber-Espionage Group You Haven’t Heard Of appeared first on Penetration Testing Tools.
CVE-2025-49568 | Adobe Illustrator up to 28.7.8/29.6.1 use after free (apsb25-74)
CVE-2025-49567 | Adobe Illustrator up to 28.7.8/29.6.1 null pointer dereference (apsb25-74)
CVE-2023-45584 | Fortinet FortiPAM/FortiProxy/FortiOS HTTP Request double free (FG-IR-23-209)
CVE-2024-26009 | Fortinet FortiPAM/FortiSwitchManager/FortiProxy/FortiOS FGFM Request authentication bypass (FG-IR-24-042)
CVE-2024-52964 | Fortinet FortiManager up to 7.6.1 path traversal (FG-IR-24-473)
CVE-2024-40588 | Fortinet FortiRecorder CLI path traversal (FG-IR-24-309)
CVE-2024-48892 | Fortinet FortiSOAR up to 7.3.3/7.4.5/7.5.1/7.6.0 path traversal (FG-IR-24-421)
CVE-2025-25248 | Fortinet FortiOS/FortiPAM/FortiProxy SSL-VPN integer overflow (FG-IR-24-364)
CVE-2025-49758 | Microsoft SQL Server privileges management
CVE-2025-49759 | Microsoft SQL Server sql injection
CVE-2025-53727 | Microsoft SQL Server sql injection
CVE-2025-27759 | Fortinet FortiWeb up to 7.0.10/7.2.10/7.4.7/7.6.3 CLI Command os command injection (FG-IR-25-150 / WID-SEC-2025-1805)
Web DDoS, App Exploitation Attacks Saw a Huge Surge in First Half of 2025
The cybersecurity landscape experienced an unprecedented escalation in digital threats during the first half of 2025, with Web Distributed Denial of Service (DDoS) attacks surging by 39% compared to the second half of 2024. The second quarter alone witnessed a staggering 54% quarter-over-quarter spike in attack activity, marking the highest levels on record and signaling […]
The post Web DDoS, App Exploitation Attacks Saw a Huge Surge in First Half of 2025 appeared first on Cyber Security News.
Brivo Visitor Management, powered by Envoy, boosts front-desk security
Brivo a strategic partnership with Envoy. The integration brings Envoy’s workplace platform, designed to connect people, spaces, and data, into Brivo Security Suite. Together, Brivo Visitor Management powered by Envoy merges workplace experience with physical security, eliminating silos and enabling a modern, secure sign-in process that scales from single offices to Fortune 500 enterprises. This partnership makes visitor management simpler, more secure, and boosts front-desk security by automating approvals, notifications, and compliance tracking. Unlike fragmented … More →
The post Brivo Visitor Management, powered by Envoy, boosts front-desk security appeared first on Help Net Security.