Fortinet confirms active exploitation of a FortiOS SSL VPN flaw that bypasses 2FA.
CVE-2020-12812 lets attackers log in by changing the case of a username when LDAP is misconfigured.
The bug can allow admin or VPN access without second-factor checks.
CVE-2020-12812 lets attackers log in by changing the case of a username when LDAP is misconfigured.
The bug can allow admin or VPN access without second-factor checks.
CISA added a Digiever NVR bug to its exploited list after confirmed attacks.
CVE-2023-52163 allows remote code execution through command injection once logged in.
Researchers link it to Mirai and ShadowV2 botnets. The device is end-of-life and unpatched.
CVE-2023-52163 allows remote code execution through command injection once logged in.
Researchers link it to Mirai and ShadowV2 botnets. The device is end-of-life and unpatched.
A new MacSync malware variant hit macOS via a signed and notarized app, letting it bypass Apple Gatekeeper.
The fake messaging installer ran like a legitimate app until Apple revoked the certificate.
The fake messaging installer ran like a legitimate app until Apple revoked the certificate.
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution.
Ten former Samsung employees arrested for industrial espionage charges for giving China chipmaker 10nm tech — executives and researchers allegedly leaked DRAM technology to China-based CXMT, resulting in trillions of losses in Korean Won.
''NHS Warns of PoC Exploit for 7-Zip Symbolic Link–Based RCE Vulnerability''.
Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection.
Mark Zuckerberg and Meta are lobbying the Canadian government to implement mandatory digital IDs, pushing for regulations that would require age verification at the app store level.
MongoDB fixed a server flaw that lets unauthenticated users read uninitialized heap memory.
The bug, CVE-2025-14847 (8.7), affects releases from 3.6 through 8.2 and is tied to zlib compression handling.
The bug, CVE-2025-14847 (8.7), affects releases from 3.6 through 8.2 and is tied to zlib compression handling.
Cyber Dispatch™️
Handala claims hack of Netanyahu chief of staff’s phone.
The hacker group Handala claimed it hacked the phone of Israeli Benjamin Netanyahu’s chief of staff, Tzachi Braverman, alleging long-term access to his device and warning it may release files, audio, and video purportedly linking Netanyahu’s inner circle to corruption and misconduct.
👏1