Skip to content

Intel

  • Blog
  • About
  • Admin
  • Categories
    • X
    • Telegram
    • GitHub
    • Bluesky
  • July 31, 2025

    Victoria’s Secret Hit by Cyberattack — Here’s What They’re Not Telling You

    Victoria’s Secret, the globally recognized lingerie and fashion retailer, has taken its U.S. e-commerce website offline and limited some in-store services following a confirmed cybersecurity incident. While details remain sparse, the nature and scale of the response strongly suggest a potential data breach or cyberattack affecting both digital and physical retail operations. On the evening…

    Cybersecurity, Security, Vulnerabilities
  • July 31, 2025

    UAC-0001 (APT28) Attack Detection: The russia-Backed Actor Uses LLM-Powered LAMEHUG Malware to Target Security and Defense Sector 

    The notorious russian state-sponsored threat group UAC-0001 (also tracked as APT28) has once again surfaced in the cyber threat landscape. After CERT-UA’s late June alert exposing the group’s use of the COVENANT framework and the BEARDSHELL backdoor, UAC-0001 has maintained its focus on Ukraine. CERT-UA now reports a new wave of cyber-attacks targeting the security…

    Cybersecurity, Security
    #cybersecurity, #security, #soc
  • July 31, 2025

    You Trust Your Helm Charts — Here’s Why That’s a Huge Mistake That Could Lead to a Cloud Breach

    Helm has revolutionized how Kubernetes applications are deployed. A single helm install can launch a fully functioning stack in seconds. But a new report by Microsoft Defender for Cloud reveals a disturbing truth: many Helm charts are insecure by default, and their convenience often comes at the cost of exposure. The report, The Risk of…

    Cybersecurity, Security, Vulnerabilities
  • July 31, 2025

    CVE-2025-6558 Vulnerability: Google Chrome Zero-Day Under Active Exploitation

    As the summer heat continues to climb, so does the surge of critical vulnerabilities in popular software products, intensifying the global cyber threat landscape. Hot on the heels of the disclosure of CVE-2025-25257, a critical flaw in Fortinet’s FortiWeb web application firewall, another high-impact vulnerability has emerged. Adversaries are exploiting a critical zero-day vulnerability in…

    Cybersecurity, Security
    #cybersecurity, #security, #soc
  • July 31, 2025

    WhatsApp’s Latest Bug Could Be the Gateway to a Full System Takeover

    Meta has disclosed a critical security vulnerability in WhatsApp for Windows—tracked as CVE-2025-30401—which could allow remote attackers to execute arbitrary code on victim systems. The flaw affects all versions prior to WhatsApp 2.2450.6 and has since been patched. The issue stems from an improper handling of file type spoofing, where WhatsApp’s interface misrepresents the nature…

    Cybersecurity, Security, Vulnerabilities
  • July 31, 2025

    Interlock Ransomware Detection: Adversaries Deploy a Novel PHP-Based RAT Variant via FileFix

    Threat actors operating the Interlock ransomware, known for executing high-impact double-extortion attacks across various global industries, have re-emerged in the cyber threat landscape. Attackers have recently deployed a new PHP-based version of its custom RAT in a large-scale campaign, leveraging a modified ClickFix variant known as FileFix to target organizations across multiple sectors. Detect Interlock…

    Cybersecurity, Security
    #cybersecurity, #security, #soc
  • July 31, 2025

    Oracle Cloud Was Hacked — But They Didn’t Tell You Everything

    Oracle has privately acknowledged to select customers that it suffered a security breach impacting its legacy Oracle Cloud infrastructure (Gen 1, aka Oracle Cloud Classic). While Oracle publicly maintains that “Oracle Cloud was not breached,” leaked data, threat actor claims, and third-party verifications indicate that a significant compromise occurred involving sensitive identity data. What Actually…

    Cybersecurity, Security, Vulnerabilities
  • July 31, 2025

    CVE-2025-25257 Vulnerability: Critical SQL Injection in Fortinet FortiWeb Enables Unauthenticated Remote Code Execution

    Following the recent disclosure of CVE-2025-47981, a critical heap-based buffer overflow in Windows SPNEGO Extended Negotiation, security teams now face another major threat, this time affecting Fortinet’s FortiWeb web application firewall. Designated as CVE-2025-25257 and assigned a CVSS score of 9.6, this vulnerability is an unauthenticated SQL injection flaw that allows attackers to execute arbitrary…

    Cybersecurity, Security
    #cybersecurity, #security, #soc
  • July 31, 2025

    Antivirus Kiosks: Enhancing Security at the Physical-Digital Boundary

    In today’s complex cybersecurity landscape, organizations face an evolving array of threats that target the intersection of physical and digital domains. One technology gaining significant adoption in security-conscious environments is the antivirus kiosk – a dedicated physical station designed to scan, analyze, and sanitize external media before it connects to an organization’s network infrastructure. The…

    Cybersecurity, Security, Vulnerabilities
  • July 31, 2025

    CVE-2025-47981: Critical Heap-Based Buffer Overflow Vulnerability in Windows SPNEGO Extended Negotiation Leads to RCE

    With over 1.4 billion devices running Windows and widespread adoption of Microsoft 365 and Azure, Microsoft technologies continue to form the foundation of modern enterprise infrastructure. However, this ubiquity also makes them an attractive target for threat actors. According to the 2025 BeyondTrust Microsoft Vulnerabilities Report findings, 2024 saw a record-breaking 1,360 Microsoft-related vulnerabilities —…

    Cybersecurity, Security
    #cybersecurity, #security, #soc
Previous Page
1 … 110 111 112 113 114 … 243
Next Page

Designed by Alireza Gharib