Global

Cloudflare Workers Vulnerability Allows JWT Leakage at 12 Bits Per Second

Cybersecurity researchers have revealed a significant vulnerability in Cloudflare Workers, detailing a remote Spectre attack that can leak a JSON Web Token (JWT) from...

U.S. Agencies Warn of AI-Driven Cyber Attacks Targeting Siemens PLCs in Critical Infrastructure

U.S. government agencies have issued a warning about hackers targeting critical infrastructure, specifically Siemens S7 Series programmable logic controllers (PLCs), using artificial intelligence in...

Critical macOS, SharePoint, vCenter, and Microsoft IKE Vulnerabilities Under Active Exploitation, CISA Warns

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified four critical vulnerabilities that are currently being exploited in the wild. These vulnerabilities have...

Attackers Exploit MLflow SSRF Vulnerability to Exfiltrate Cloud Credentials

Two critical vulnerabilities affecting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, a web-based SCADA/HMI software, are currently being exploited by attackers. Reports...

Microsoft Copilot Personal Vulnerabilities Allow One-Click Data Exfiltration from Connected Apps

Varonis Threat Labs has identified three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, which could enable attackers to extract data from connected applications...

BlackFile Cybercrime Group Continues Targeting Financial Sector with New Extortion Demands

A cybercrime group known as BlackFile continues to target the financial sector, with reports indicating that it remains active and has been shifting its...

Heights Finance Data Breach Exposes Financial Information of Nearly 750,000 Customers

Cybercriminals breached the cloud system of Heights Finance, a debt consolidation loan company, in May, compromising sensitive financial information and personal data of approximately...

Snowflake GitHub Actions Vulnerability Allows Command Injection via Crafted Issues

Cybersecurity researchers at Wiz have disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository. This vulnerability could be exploited through a...

Recent Articles

Cyber Warriors Conclave Chapter X — Beyond the Ballroom