[HIGH] – UK and Allies Detail Iranian CHOSEN BRICK Spyware Campaign
UK, U.S., and Dutch agencies detailed Iranian spyware targeting dissidents, activists, and journalists.
Cybersecurity, AI, etc.
Cybersecurity (breaches, incidents, vulnerabilities, ransomware, supply chain attacks)
UK, U.S., and Dutch agencies detailed Iranian spyware targeting dissidents, activists, and journalists.
A Twitch browser extension with over 30,000 installs exposed OAuth tokens through proxy requests.
CenterPoint Energy confirmed an unauthorized party obtained some customer personal information through an external-facing system.
Oracle's September Critical Security Patch Update delivers 673 security fixes across product families.
JFrog disclosed a local Parallels Desktop flaw allowing unprivileged macOS users to execute code as root.
Attackers are exploiting an unauthenticated file-upload flaw in WooCommerce Wholesale Lead Capture.
Google patched an actively exploited Pixel modem privilege-escalation flaw in its September update.
cPanel urges LiteSpeed Enterprise administrators to update to 6.3.7 for a shared-hosting privilege-escalation flaw.
DDRop researchers demonstrate a DDR5 interposer attack against Intel and AMD confidential-computing technologies.
CISA added an actively exploited Cisco Secure Email Gateway SQL-injection flaw to KEV.