Skip to content

Intel

  • Blog
  • About
  • Admin
  • Categories
    • X
    • Telegram
    • GitHub
    • Bluesky
  • July 31, 2025

    A week in security (July 21 – July 27)

    A list of topics we covered in the week of July 21 to July 27 of 2025 Last week on Malwarebytes Labs: Steam games abused to deliver malware once again Watch out: Instagram users targeted in novel phishing campaign Age verification: Child protection or privacy risk? iPhone vs. Android: iPhone users more reckless, less protected…

  • July 31, 2025

    The Zero Trust Scorecard: Tracking Culture, Compliance & KPIs

    The Plateau: A CISO’s Zero Trust Dilemma I met with a CISO last month who was stuck halfway up the Zero Trust mountain. Their team had invested in microsegmentation, MFA was everywhere, and cloud entitlements were tightened to the bone. Yet, adoption was stalling. Phishing clicks still happened. Developers were bypassing controls to “get things…

  • July 31, 2025

    CVE-2025-27136 – LocalS3 CreateBucketConfiguration Endpoint XXE Injection

    Discover how CVE-2025-27136, a critical XXE vulnerability in LocalS3’s CreateBucketConfiguration endpoint, can be exploited to access sensitive files. Learn how the flaw works and how to mitigate it. The post CVE-2025-27136 – LocalS3 CreateBucketConfiguration Endpoint XXE Injection appeared first on OffSec. Go to Source

  • July 31, 2025

    How to Secure Your SOC’s AI Agents: A Practical Guide to Orchestration and Trust

    Automation Gone Awry: Can We Trust Our AI Agents? Picture this: it’s 2 AM, and your SOC’s AI triage agent confidently flags a critical vulnerability in your core application stack. It even auto-generates a remediation script to patch the issue. The team—running lean during the night shift—trusts the agent’s output and pushes the change. Moments…

  • July 31, 2025

    How OffSec Certifications Help You Hire With Confidence

    Hire cyber talent with confidence: OffSec certifications prove candidates can perform under pressure, not just talk the talk. The post How OffSec Certifications Help You Hire With Confidence appeared first on OffSec. Go to Source

  • July 31, 2025

    Steam games abused to deliver malware once again

    A cybercriminal known as EncryptHub (aka Larva-208) has reportedly abused the online game platform Steam to distribute information stealers. EncryptHub managed to sneak malicious files into the Chemia game files hosted on Steam. Chemia is an adventurous survival type of game that puts the player in a world ravaged by a catastrophic natural disaster… which…

  • July 31, 2025

    How to Secure Your SOC’s AI Agents: A Practical Guide to Orchestration and Trust

    Automation Gone Awry: Can We Trust Our AI Agents? Picture this: it’s 2 AM, and your SOC’s AI triage agent confidently flags a critical vulnerability in your core application stack. It even auto-generates a remediation script to patch the issue. The team—running lean during the night shift—trusts the agent’s output and pushes the change. Moments…

  • July 31, 2025

    How OffSec Certifications Help You Hire With Confidence

    Hire cyber talent with confidence: OffSec certifications prove candidates can perform under pressure, not just talk the talk. The post How OffSec Certifications Help You Hire With Confidence appeared first on OffSec. Go to Source

  • July 31, 2025

    New TISAX Guide Now Available

    Unlock the power of strategic compliance with The Common Sense Guide to TISAX Compliance—a practical, no-nonsense roadmap designed for automotive industry players who need to get smart about information security, fast. Created by MicroSolved, Inc., this guide strips away the jargon and delivers real-world advice for mastering TISAX—from initial gap analysis to audit preparation and continuous…

  • July 31, 2025

    CVE-2024-12029 – InvokeAI Deserialization of Untrusted Data vulnerability

    CVE-2024-12029: A critical deserialization vulnerability in InvokeAI’s /api/v2/models/install endpoint allows remote code execution via malicious model files. Exploit risk for AI art servers. The post CVE-2024-12029 – InvokeAI Deserialization of Untrusted Data vulnerability appeared first on OffSec. Go to Source

Previous Page
1 … 100 101 102 103 104 … 243
Next Page

Designed by Alireza Gharib