When you click on the Studios patch, password state authentication bypass vulnerability on emergency access page

August 29, 2025Ravi LakshmananVulnerability/Enterprise Security Click Studios, developer of the enterprise-centric password management solution PasswordState, said it has released a security update to address a software authentication bypass vulnerability. An issue that has not yet been assigned a CVE identifier has been addressed in PasswordState 9.9 (Build 9972), released on August 28, 2025. The Australian […]
Emergency patches are now available for FreePBX server targeting zero-day defects

August 29, 2025Ravi LakshmananZero Day/Vulnerability The Sangoma FreepBX Security team has issued an advisory warning about actively exploited FreepBX Zero Day vulnerabilities affecting systems through the Administrator Control Panel (ACP) exposed to the public Internet. FreepBX is an open source private branch exchange (PBX) platform widely used by businesses, call centres and service providers to […]
The federal government seizes $6.4 million veriftools fake-id marketplace, but operators reboot new domains

August 29, 2025Ravi LakshmananCryptocurrency/Cybercrime Dutch and US authorities have announced that they have used fraudulent identity documents to cybercriminals around the world to demolish illegal markets called Veriftools. To do this, two marketplace domains (Verif)[.]Tools and Veriftools[.]Net) and one blog have been deleted and redirected to a splash page where visitors to the site say […]
Google warns that SalesLoft Oauth breaches will extend beyond Salesforce and affect all integrations

August 29, 2025Ravi LakshmananData Breach / Salesforce Google has revealed that the recent wave of attacks targeting Salesforce instances via SalesLoft Drift is much broader than previously thought, and that will affect all integrations. Google Threat Intelligence Group (GTIG) and Mandiant state in their updated advisory. The tech giant accessed emails from a small number […]
TamperedChef malware disguised as a fake PDF editor steals credentials and cookies

August 29, 2025Ravi LakshmananMalware/Windows Security Cybersecurity researchers have discovered a cybercrime campaign that uses tricks to direct victims to fraudulent sites to provide a new information steeler called TamperedChef. “The goal is to invite victims to download and install the Trojanized PDF editor, including information-stolen malware called TamperedChef.” “Malware is designed to harvest sensitive data […]
Researchers find code flaws and code flaws that allow attackers to reissue deleted extensions with the same name

August 28, 2025Ravi LakshmananMalware/Ransomware Cybersecurity researchers have discovered a loophole in the Visual Studio Code Marketplace that allows threat actors to reuse names of previously deleted extensions. Software Supply Chain Security Costume ReverSingLabs said it had discovered after identifying a malicious extension named “Ahbanc.shiba,” which works similarly to two other extensions flagged in early March […]
Salt Typhoon exploits defects in Cisco, Ivanti and Palo Alto infringing 600 organizations around the world

The China-related Advanced Persistent Threat (APT) actor known as Salt Typhoon continues attacks targeting networks around the world, including organizations in the telecommunications, government, transportation, accommodation and military infrastructure sectors. “These actors focus on major telecommunications providers’ large backbone routers, as well as provider edge (PE) and customer edge (CE) routers, but refer to other […]
Why Top Teams Prioritize Code-to-Cloud Mapping in 2025 AppSec

August 28, 2025Hacker NewsCloud Security/Generated AI Imagine this: your team has deployed some new code and thinks everything is fine. However, there are small flaws hidden there, and when hit in the cloud it explodes into a big problem. The next thing you know is that there are hackers and your company deals with millions […]
Hidden Vulnerabilities in Project Management Tools and How FluentPro Backups Protect them

Every day, companies, teams and project managers trust platforms like Trello, Asana, and more to collaborate and manage tasks. But what happens when that trust is broken? According to a recent report by Statista, the average cost of data breaches worldwide was around $4.88 million. Additionally, in 2024, personal data from over 15 million Trello […]
Malicious NX packages for “S1ngularity” attack leaked 2,349 Github, Cloud, and AI credentials

Maintainers of NX build systems are warning users of supply chain attacks to allow attackers to expose malicious versions of popular NPM packages and other auxiliary plugins with data collection capabilities. “Malicious versions of the NX packages, along with some supporting plugin packages, will be published to NPM, scan the file system, collect credentials, and […]