Public proof-of-concept exploit code demonstrates practical exploitation through the Tomcat Tribes communication channel, increasing risk where clustering is enabled and network exposure exists.
More than 80% of incidents our team investigated last year stemmed from cloud identity compromise, highlighting a growing shift in how adversaries are gaining access to corporate environments. Get more cybersecurity data, trends, and analysis here: https://t.co/29GbDKNtbc
Escalating conflict following coordinated U.S. and Israeli strikes on Iranian military and nuclear sites has raised concerns about potential cyber spillover.
Researchers have observed a rise in opportunistic hacktivist activity and unverified claims of DDoS attacks, defacements, and data leaks targeting Iran’s adversaries.
🚨 AWS reports groups are actively exploiting the #React2Shell RCE in the wild. Attackers are using exposed RSC endpoints for unauthenticated RCE → webshells → cloud pivoting. Patch React/Next.js immediately. No Field Effect systems are affected.
More: https://t.co/HiyBniTqlc
Researchers found the Recent Links feature on online code-formatters leaks private snippets via predictable URLs, exposing API keys, DB creds, & tokens at scale. More details here: https://t.co/QpSgwV2e8B
From our security experts 👇
A high-severity RCE vulnerability (CVE-2025-62518) impacts Rust-based archive libraries like async-tar, used across cloud-native & containerized systems.
Multiple patches avail, check our writeup for full mitigation details: https://t.co/HTNbDRbHy0
If you run #Oracle#EBS (v12.2.3-12.2.14) or have internet-exposed modules:
- Patch immediately
- Lock down/reset access paths
- Hunt for IoCs (reverse shells, HTTP anomalies, unusual outbound activity)
Full breakdown: https://t.co/6h5d6y0662
An exec-targeted extortion campaign is claiming theft of Oracle EBS data. Since then, a critical flaw in Oracle EBS (CVE-2025-61882) has been confirmed.
What started as a potentially unwanted application (PUA) flagged as malicious by Microsoft Defender led our analysts to uncover a broader malware campaign using trojanized apps, signed binaries, and deceptive 7-Zip packaging.
Read the full breakdown: https://t.co/G5ORdhcwRF
🚨 New patch alert: SolarWinds has released a hotfix for CVE-2025-26399, a critical Web Help Desk flaw enabling RCE. The company urged customers yesterday to upgrade to Web Help Desk version 12.8.7 Hotfix 1 to mitigate the issue. Details: https://t.co/8pKrHBvzvp
Field Effect is actively monitoring a supply chain attack involving hijacked npm packages. Researchers say hackers planted malicious code in open source software packages with 2B+ weekly updates. None of Field Effect's services are affected and our internal review confirms...
...no exposure to the compromised components. Field Effect's onboarding process for 3rd-party libraries includes validation steps that would've identified affected packages & updates are performed only after a review of their current security posture.