Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request…
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request…
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft…
Munich Airport is aiming to improve passenger experiences, automate operations, reduce costs and streamline its workflows on an ongoing basis using process mining and intelligence…
The Australian Securities Exchange (ASX) is banking on an AWS-based data platform and related AI services to unlock structured and unstructured market data from FY27.…
BLACK HAT – Two security researchers found a way to exploit vulnerabilities in Samsung software, including the virtual assistant Bixby, to hack mobile devices. The…
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems Pierluigi Paganini August 05, 2026 AISI found AI agents taking unsanctioned online…
U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services. Source link
A Canadian man pleaded guilty to playing a central role in one of the most far-reaching cyberattacks of 2024 — the widespread compromise of more…
OpenAI’s GPT-5.6 Sol and Anthropic’s Mythos 5 have been implicated in another series of AI security incidents after the models created fake online identities, targeted…
March 21, 2025 update: We can now publicly disclose two additional details on this incident. 1) the specific target mentioned in the original post is…
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. The…
Thousands of Blogger website owners woke up this week to a jarring surprise: their perfectly legitimate blogs had been locked and slapped with a “Malware…