Skip to content

Intel

  • Blog
  • About
  • Admin
  • Categories
    • X
    • Telegram
    • GitHub
    • Bluesky
  • July 31, 2025

    Love, Lies, and Long Flights: How to Avoid Romance Scams While Traveling This Summer 

    Ah, summer. The season of sun-soaked beaches, bucket list adventures, and Instagram-worthy Aperol Spritzes. For many, it’s also a time of new connections—whether it’s a whirlwind vacation romance, a flirtatious chat over sangria, or that handsome stranger who slides into your DMs while you’re posting travel pics.  But while your heart may be on holiday,…

  • July 31, 2025

    The Good, the Bad and the Ugly in Cybersecurity – Week 28

    Global authorities disrupt nation-state actors, ZuRu malware backdoors macOS, and DoNot Team spies on European targets via LoptikMod RAT. The Good | Authorities Target Two Nation State Threat Actors & Cybercriminals Linked to DragonForce Attacks A Chinese national, Xu Zewei, was arrested in Milan under a warrant for alleged ties to the PRC-backed threat group…

  • July 31, 2025

    Tea Dating Advice app has users’ private messages disclosed

    A few days after Tea Dating Advice discovered unauthorized access to one of its systems that leaked 72,000 user images, the popular mobile app faced a second issue involving a separate database, as a researcher reported to 404Media that they were able to access private conversations. Tea Dating Advice, or just Tea for short, aims…

  • July 31, 2025

    Allianz Life says majority of 1.4 million US customers’ info breached

    Insurance company Allianz Life was breached, exposing the data of most of its 1.4 million American customers. According to Allianz, an attacker gained access to a third-party, cloud-based Customer Relationship Management (CRM) system through social engineering. The company filed a data breach notification with the Attorney General of the US state of Maine on Friday…

  • July 31, 2025

    Allianz Life says majority of 1.4 million US customers’ info breached

    Insurance company Allianz Life was breached, exposing the data of most of its 1.4 million American customers. According to Allianz, an attacker gained access to a third-party, cloud-based Customer Relationship Management (CRM) system through social engineering. The company filed a data breach notification with the Attorney General of the US state of Maine on Friday…

  • July 31, 2025

    Continuous Third‑Party Risk: From SBOM Pipelines to SLA Enforcement

    Recent supply chain disasters—SolarWinds and MOVEit—serve as stark wake-up calls. These breaches didn’t originate inside corporate firewalls; they started upstream, where vendors and suppliers held the keys. SolarWinds’ Orion compromise slipped unseen through trusted vendor updates. MOVEit’s managed file transfer software opened an attack gateway to major organizations. These incidents underscore one truth: modern supply…

  • July 31, 2025

    How the FBI got everything it wanted (re-air) (Lock and Code S06E15)

    This week on the Lock and Code podcast… For decades, digital rights activists, technologists, and cybersecurity experts have worried about what would happen if the US government secretly broke into people’s encrypted communications. The weird thing, though, is that, in 2018, it already happened. Sort of. US intelligence agencies, including the FBI and NSA, have…

  • July 31, 2025

    Continuous Third‑Party Risk: From SBOM Pipelines to SLA Enforcement

    Recent supply chain disasters—SolarWinds and MOVEit—serve as stark wake-up calls. These breaches didn’t originate inside corporate firewalls; they started upstream, where vendors and suppliers held the keys. SolarWinds’ Orion compromise slipped unseen through trusted vendor updates. MOVEit’s managed file transfer software opened an attack gateway to major organizations. These incidents underscore one truth: modern supply…

  • July 31, 2025

    The Zero Trust Scorecard: Tracking Culture, Compliance & KPIs

    The Plateau: A CISO’s Zero Trust Dilemma I met with a CISO last month who was stuck halfway up the Zero Trust mountain. Their team had invested in microsegmentation, MFA was everywhere, and cloud entitlements were tightened to the bone. Yet, adoption was stalling. Phishing clicks still happened. Developers were bypassing controls to “get things…

  • July 31, 2025

    CVE-2025-27136 – LocalS3 CreateBucketConfiguration Endpoint XXE Injection

    Discover how CVE-2025-27136, a critical XXE vulnerability in LocalS3’s CreateBucketConfiguration endpoint, can be exploited to access sensitive files. Learn how the flaw works and how to mitigate it. The post CVE-2025-27136 – LocalS3 CreateBucketConfiguration Endpoint XXE Injection appeared first on OffSec. Go to Source

Previous Page
1 … 99 100 101 102 103 … 243
Next Page

Designed by Alireza Gharib