nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery
25
Jun
2025

nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery

Jun 25, 2025Ravie LakshmananSaaS Security / Vulnerability New research has uncovered continued risk from a known security weakness in Microsoft’s…

WinRAR
25
Jun
2025

WinRAR patches bug letting malware launch from extracted archives

WinRAR has addressed a directory traversal vulnerability tracked as CVE-2025-6218 that, under certain circumstances, allows malware to be executed after…

Kubernetes NodeRestriction Flaw Lets Nodes Bypass Resource Authorization
25
Jun
2025

Kubernetes NodeRestriction Flaw Lets Nodes Bypass Resource Authorization

A critical security vulnerability (CVE-2025-4563) in Kubernetes allows nodes to bypass authorization checks for dynamic resource allocation, potentially enabling privilege…

Judge approves AT&T’s $177M data breach settlement
25
Jun
2025

Judge approves AT&T’s $177M data breach settlement

Dive Brief: A federal district court judge has given preliminary approval to a proposed $177 million settlement between AT&T and…

Citrix
25
Jun
2025

New ‘CitrixBleed 2’ NetScaler flaw let hackers hijack sessions

A recent vulnerability in Citrix NetScaler ADC and Gateway is dubbed “CitrixBleed 2,” after its similarity to an older exploited…

CISA Publishes Guide to Address Memory Safety Vulnerabilities in Modern Software Development
25
Jun
2025

CISA Publishes Guide to Address Memory Safety Vulnerabilities in Modern Software Development

The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA), has released a comprehensive guide…

Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC
25
Jun
2025

Citrix Releases Emergency Patches for Actively Exploited CVE-2025-6543 in NetScaler ADC

Jun 25, 2025Ravie LakshmananVulnerability / Network Security Citrix has released security updates to address a critical flaw affecting NetScaler ADC…

Latest Citrix vulnerability could be every bit as bad as Citrix Bleed
25
Jun
2025

Latest Citrix vulnerability could be every bit as bad as Citrix Bleed

Cyber security experts are urging operators of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances to get in…

Critical vulnerability in Citrix Netscaler raises specter of exploitation wave
25
Jun
2025

Critical vulnerability in Citrix Netscaler raises specter of exploitation wave

A critical vulnerability in Citrix Netscaler is raising concerns that hackers will launch a wave of attacks rivaling or even…

Matt Kapko
25
Jun
2025

Stealth China-linked ORB network gaining footholds in US, East Asia

A recently discovered operational relay box (ORB) network controlled by a China-linked threat group already exceeds 1,000 devices and is…

Threat Actors Distribute Compromised SonicWall SSL VPN NetExtender to Steal Sensitive Data
25
Jun
2025

Threat Actors Distribute Compromised SonicWall SSL VPN NetExtender to Steal Sensitive Data

Threat actors were discovered disseminating a malicious, altered version of SonicWall’s SSL VPN NetExtender application in a complex cyberattack that…

Rubrik acquires AI startup Predibase to boost agentic AI offerings 
25
Jun
2025

Rubrik acquires AI startup Predibase to boost agentic AI offerings 

Data management company Rubrik announced plans Wednesday to acquire artificial intelligence startup Predibase, a move aimed at accelerating the adoption…