Security Alert: Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including…
Read More: https://t.co/K1bYAJZEUB
#CyberSecurity#ThreatIntel#InfoSec
Security Alert: Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authenticatio…
Read More: https://t.co/K1bYAJZEUB
#CyberSecurity#ThreatIntel#InfoSec
This is the AI story that actually matters, not chatbots writing phishing emails, AI collapsing the time and skill it takes to go from "here's a public CVE" to "here's a working exploit script." That shift is why exploitability has to outrank theoretical severity in every remediation queue now, PLCs included.
📢 Ransomware Alert: 🇺🇸
The Gentlemen ransomware group has added an unidentified victim (P** R***) to its dark web portal.
NB: They intend to publish the data within 9–10 days.
🔍 Key Details:
🛡️ Threat Actor: The Gentlemen
📅 Reported on: 20/08/26
‼️ Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions
Source: https://t.co/oUtkj2xB0h
A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft 365 users to complete their regular login process before covertly stealing the authenticated session.
The Adversary-in-the-Middle (AiTM) framework generated thousands of potential compromise events from late 2024 through 2026, with the overwhelming majority resulting in hijacked session cookies rather than isolated password theft. Instead of attempting to break MFA algorithms directly, Mirage2FA positions itself between the user and legitimate authentication endpoints.
#cybersecuritynews
69% of ransomware victims refused to pay in 2025 — the highest rate ever recorded.
The reason wasn’t luck. It was preparation: tested backups, incident response plans, stronger controls, and businesses doing the unglamorous work before the attack arrived.
The fight against ransomware is winnable.
Read more: https://t.co/rUbHgZu0Lx
#Cybersecurity #Ransomware #CyberRisk #SMB #IncidentResponse #DataProtection
Security Alert: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
Read More: https://t.co/K1bYAJZEUB
#CyberSecurity#ThreatIntel#InfoSec
Security Alert: The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthe…
Read More: https://t.co/K1bYAJZEUB
#CyberSecurity#ThreatIntel#InfoSec
Security Alert: An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated w…
Read More: https://t.co/K1bYAJZEUB
#CyberSecurity#ThreatIntel#InfoSec
Security Alert: The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all ver…
Read More: https://t.co/K1bYAJZEUB
#CyberSecurity#ThreatIntel#InfoSec
Security Alert: A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based A…
Read More: https://t.co/K1bYAJZEUB
#CyberSecurity#ThreatIntel#InfoSec
Security Alert: Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-sn��
Read More: https://t.co/K1bYAJZEUB
#CyberSecurity #ThreatIntel #InfoSec
Security Alert: A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument ti…
Read More: https://t.co/K1bYAJZEUB
#CyberSecurity#ThreatIntel#InfoSec