Skip to content

Intel

  • Blog
  • About
  • Admin
  • Categories
    • X
    • Telegram
    • GitHub
    • Bluesky
  • July 31, 2025

    CVE-2024-21683 – Authenticated RCE via “Add a New Language” in Atlassian Confluence

    Critical RCE vulnerability (CVE-2024-21683) in Atlassian Confluence Data Center and Server (v5.2–8.9.0) allows authenticated users to execute arbitrary code via malicious code macros. The post CVE-2024-21683 – Authenticated RCE via “Add a New Language” in Atlassian Confluence appeared first on OffSec. Go to Source

  • July 31, 2025

    ‘Car crash victim’ calls mother for help and $15K bail money. But it’s an AI voice scam

    A woman in Florida was tricked into giving thousands of dollars to a scammer after her daughter’s voice was AI-cloned and used in a scam. Sharon Brightwell says she received a call from someone who sounded just like her daughter. The woman on the other end was sobbing and crying, telling her mom that she…

  • July 31, 2025

    Zero Trust Architecture: Essential Steps & Best Practices

      Organizations can no longer rely solely on traditional security measures. The increasing frequency and sophistication of cyberattacks underscore the urgent need for more robust defensive strategies. This is where Zero Trust Architecture emerges as a game-changing approach to cybersecurity, fundamentally challenging conventional perimeter-based defenses by asserting that no user or system should be automatically…

  • July 31, 2025

    CVE-2024-21683 – Authenticated RCE via “Add a New Language” in Atlassian Confluence

    Critical RCE vulnerability (CVE-2024-21683) in Atlassian Confluence Data Center and Server (v5.2–8.9.0) allows authenticated users to execute arbitrary code via malicious code macros. The post CVE-2024-21683 – Authenticated RCE via “Add a New Language” in Atlassian Confluence appeared first on OffSec. Go to Source

  • July 31, 2025

    Are passkeys enterprise-ready? | Kaspersky official blog

    Regulation and the evolving threat landscape are driving companies to adopt more resilient forms of employee authentication. Are passkeys a cost-effective and straightforward replacement for traditional passwords? Every major tech giant touts passkeys as an effective, convenient password replacement that can end phishing and credential leaks. The core idea is simple: you sign in with…

    #cybersecurity, #data_breaches, #infostealers, #linux, #malware, #privacy, #security, #siem
  • July 31, 2025

    CVE‑2025‑49113 – Post‑Auth Remote Code Execution in Roundcube via PHP Object Deserialization

    A critical RCE vulnerability (CVSS 9.9) in Roundcube Webmail (<1.5.10, 1.6.0–1.6.10) allows authenticated users to exploit a PHP deserialization flaw. Learn how it works and how to protect your systems. The post CVE‑2025‑49113 – Post‑Auth Remote Code Execution in Roundcube via PHP Object Deserialization appeared first on OffSec. Go to Source

  • July 31, 2025

    “Ring cameras hacked”? Amazon says no, users not so sure

    In the last week, countless Amazon Ring users on TikTok, Reddit, and X have been saying they believe their Ring cameras were hacked starting May 28. Many posted screenshots of their accounts, showing multiple unauthorized device logins, making these claims hard to ignore. Forbes looked into the issue and even the journalist found several logins…

  • July 31, 2025

    Avoid These Pitfalls: 3 Microsoft 365 Security Mistakes Companies Make

      Securing cloud services like Microsoft 365 is more crucial than ever. With millions of businesses relying on Microsoft 365 to manage their data and communication, the implementation of robust security measures is essential to protect sensitive information and maintain operational integrity. Unfortunately, many companies still fall victim to common security pitfalls that leave them…

  • July 31, 2025

    CVE‑2025‑49113 – Post‑Auth Remote Code Execution in Roundcube via PHP Object Deserialization

    A critical RCE vulnerability (CVSS 9.9) in Roundcube Webmail (<1.5.10, 1.6.0–1.6.10) allows authenticated users to exploit a PHP deserialization flaw. Learn how it works and how to protect your systems. The post CVE‑2025‑49113 – Post‑Auth Remote Code Execution in Roundcube via PHP Object Deserialization appeared first on OffSec. Go to Source

  • July 31, 2025

    CVE-2025-24893 – Unauthenticated Remote Code Execution in XWiki via SolrSearch Macro

    An RCE vulnerability in XWiki was found allowing unauthenticated attackers to execute arbitrary Groovy code remotely without authentication or prior access. The post CVE-2025-24893 – Unauthenticated Remote Code Execution in XWiki via SolrSearch Macro appeared first on OffSec. Go to Source

Previous Page
1 … 104 105 106 107 108 … 243
Next Page

Designed by Alireza Gharib