2026-07-15 13:14 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Scott Caveza · indexed 2026-08-15 18:55 UTC
SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators o…
P100
2026-07-14 08:53 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
P0
2026-06-05 19:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: AWS-2025-016 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/07/25 6:00 PM PDT Description: AWS CodeBuild is a fully managed on-demand continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy. Security researchers reported a CodeBuild issue that could be leveraged for unapproved code modification absent sufficient repository controls and credential scoping. The researchers demonstrat…
P5
2026-05-29 14:19 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues…
P0
2026-05-29 13:56 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically craf…
P0
2026-05-14 09:38 UTC
Other
Red Hunt Labs · Sudhanshu Chauhan · indexed 2026-09-07 17:30 UTC
Why Mythos (and other AI models) Make Continuous Exposure Visibility Critical For years, vulnerability discovery was naturally constrained by expertise, time, and scale. Finding meaningful security issues often required experienced researchers spending days or weeks understanding codebases, testing assumptions, reviewing implementations, and validating exploitability. That dynamic is changing rapidly. Recent developments around systems like Anthropic’s Project Glasswing 🔗 and Mythos, OpenAI’s …
P50
2026-05-11 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a so…
P60
2026-04-23 21:38 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting th…
P20
2026-04-10 15:12 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities. For Pixel 10, Google is advancing its proactive security measures further. Following our previous discussion on "Deploying Rust in Existing…
P20
2026-04-02 16:00 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user’s query. This may even be possible without any input directly from the user.IPI is not the kind of technical proble…
P0
2026-03-31 16:55 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerability reward program (VRP) has seen constant additions and expansions over the past decade and a half, clearly indicating the value the programs under this umbrella contribute to the safety and security of Google and its users, but also highlighting…
P0
2026-03-18 07:04 UTC
Other
Red Hunt Labs · Sudhanshu Chauhan · indexed 2026-09-07 17:30 UTC
Prepared by: Sudhanshu Chauhan 🔗 (Director, RedHunt Labs) and Devang Solanki 🔗 (Security Researcher, RedHunt Labs) There is a loop in cybersecurity. A new technology enters the enterprise. Adoption moves faster than governance. Security teams hear about it during incident response instead of during planning. And the exposure window, that gap between deployment and visibility, gets exploited before anyone realizes it even existed. We saw it with open cloud storage buckets. We saw it with expos…
P15
2025-12-18 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions
P0
2025-10-30 16:59 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse; Vijay Pareek, Manager, Android Messaging Trust and Safety As Cybersecurity Awareness Month wraps up, we’re focusing on one of today's most pervasive digital threats: mobile scams. In the last 12 months, fraudsters have used advanced AI tools to create more convincing schemes, resulting in over $400 billion in stolen funds globally.¹ For years, Android …
P0
2025-09-15 17:01 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized access to data, escalate privileges, or cause denial of service. Hardware vendors have deployed various mitigations, such as ECC and Target Row Refresh (TRR) for DDR5 memory, to mitigate Rowhammer and e…
P10
2025-09-15 05:44 UTC
Other
Red Hunt Labs · Bhavarth Karmarkar · indexed 2026-09-07 17:30 UTC
In July 2025, the Tea app 🔗, a mental health and social community platform, experienced a devastating breach that spilled 72,000 images (including 13,000 driver’s license and verification selfies) and over 1.1 million private direct messages onto the internet. The leaks first surfaced on 4chan and quickly spread across forums, torrents, and underground channels. This was not “just another API key leak.” Instead, it was a story about Firebase misconfigurations, poor data retention practices, an…
P25
2025-07-21 21:34 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Matthew Suozzo, Google Open Source Security Team (GOSST)Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers.The project comprises:Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/T…
P0
2025-06-13 16:03 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…
P0
2024-08-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Researchers discovered critical vulnerabilities in 6 AWS services that could allow attackers to breach accounts through malicious S3 buckets. By claiming predictable bucket names, attackers could inject code, steal data, or gain admin access. AWS has since fixed the issues, but the attack vector may still apply to other services and open source projects.
P0
2024-08-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Semperis researchers discovered vulnerabilities in Microsoft applications that allowed privilege elevation in Entra ID beyond expected authorization controls. The most severe finding enabled adding users to privileged roles, including Global Administrator, without proper permissions. The issues affected Device Registration Service, Viva Engage, and Microsoft Rights Management Service. Microsoft has since resolved the vulnerabilities.
P0
2023-11-30 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Unit 42 researchers discovered a security risk in Google Workspace's domain-wide delegation feature that allows a GCP identity with necessary permissions to generate access tokens to impersonate Google Workspace users and access their data. This mismatch between GCP permissions and Google Workspace access could be exploited by malicious insiders or attackers with stolen credentials.
P0
2023-08-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Secureworks researchers discovered an Azure AD application with an abandoned reply URL related to Microsoft Power Platform. An attacker could leverage this URL to redirect authorization codes, exchange them for access tokens, and call Power Platform API via a middle-tier service to obtain elevated privileges. Microsoft quickly addressed the issue by removing the identified abandoned reply URL from the Azure AD application.
P10
2022-12-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Our team has been tracking conversations surrounding ConnectWise Control vulnerabilities and alleged exploitation. We politely disagree with the threat and criticality presented by the security researcher.
P0
2022-03-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Take a behind-the-scenes look at what our security researchers do in this Q&A session.
P0
2021-07-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Our Security Researchers discuss how hackers executed the Kaseya VSA supply chain attack—and why the blast radius of the incident was relatively limited.
P15
2020-08-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Researchers discovered vulnerabilities in Google Cloud SQL that allowed gaining unauthorized shell access to MySQL instances. By chaining SQL injection, parameter injection in mysqldump, and network spoofing, they were able to escape a Docker container and gain full access to the host VM running Cloud SQL.
P0
2019-04-25 15:16 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers discovered Illum JS-sniffers family designed to steal payment data of customers of online stores.
P0