GLOBAL SITUATIONMONITORING
482 published briefsUTCMon, Apr 6 01:58:26
Intelligence Domain

Cyber News & Updates

Breaking news, security alerts, and trending stories from across the cybersecurity landscape.

234 intelligence briefs← Intelligence Hub
  • Google: Data of two hundred Salesforce customers stolen via Gainsight apps

    Google: Data of two hundred Salesforce customers stolen via Gainsight apps

    A major cyberattack has resulted in the theft of data from over 200 Salesforce customers, stemming from compromised Gainsight applications. The group claiming responsibility is known as “Scattered Lapsus$ Hunters,” also identified as UNC6040 by Google’s Mandiant team.

    1–2 minutes
  • Bugcrowd Buys Mayhem Security for AI Hacking

    Bugcrowd Buys Mayhem Security for AI Hacking

    Bugcrowd acquires Mayhem Security, an AI and cyber scaleup. This merger boosts ethical hacking with AI-powered testing. Mayhem’s AI platform offers continuous security testing. The collaboration aims to shrink attack surfaces and pre-empt risks.

    2–3 minutes
  • Cloudflare Outage Disrupts X, ChatGPT

    Cloudflare Outage Disrupts X, ChatGPT

    Cloudflare outage on November 18 disrupted major internet platforms globally. X (formerly Twitter) and ChatGPT were affected. Cloudflare investigated and resolved the widespread issue.

    1–2 minutes
  • AI-Based Obfuscated Malware Evades AV Detection

    AI-Based Obfuscated Malware Evades AV Detection

    Malicious Android applications use AI-powered obfuscation to bypass antivirus detection. These apps mimic delivery services, steal user data, and employ sophisticated evasion techniques. Security analysts identified advanced obfuscation, making reverse engineering difficult.

    1–2 minutes
  • Grafana Patches Critical SCIM Flaw

    Grafana Patches Critical SCIM Flaw

    Grafana has patched a critical security flaw, CVE-2025-41115, in its SCIM component. This vulnerability could lead to user impersonation or privilege escalation in affected Grafana Enterprise versions. Users are advised to update immediately.

    1–2 minutes
  • ThinPLUS OS Command Injection Vulnerability (CVE-2025-13284)

    ThinPLUS OS Command Injection Vulnerability (CVE-2025-13284)

    A critical OS Command Injection vulnerability (CVE-2025-13284) in ThinPLUS allows unauthenticated remote attackers to execute arbitrary commands, posing significant risks to system integrity. TWCERT/CC urges immediate patching.

    2–3 minutes
  • CVE-2025-8855: 2FA Bypass in Brokerage Automation

    CVE-2025-8855: 2FA Bypass in Brokerage Automation

    CVE-2025-8855 is a critical 2FA bypass vulnerability in Optimus Software’s Brokerage Automation platform. It combines authorization bypass, weak password recovery, and authentication bypass flaws, leading to high-severity risks and unauthorized access.

    3–4 minutes
  • Fortinet FortiWeb Zero-Day Actively Exploited

    Fortinet FortiWeb Zero-Day Actively Exploited

    A severe security vulnerability in Fortinet’s FortiWeb web application firewall is actively exploited, allowing attackers to bypass authentication. This zero-day flaw impacts FortiWeb versions 8.0.1 and earlier. Update to 8.0.2 or later to protect against this vulnerability.

    2–3 minutes
  • IndonesianFoods-worm Floods NPM Registry

    IndonesianFoods-worm Floods NPM Registry

    A sophisticated self-replicating ‘IndonesianFoods-worm’ has flooded the npm registry with tens of thousands of malicious packages. This aggressive campaign, documented by SourceCodeRed and JFrog, poses a significant threat to the software supply chain.

    2–3 minutes
  • What is OpenID Connect (OIDC)? — Explainer tied to CVE-2025-54603

    What is OpenID Connect (OIDC)? — Explainer tied to CVE-2025-54603

    A concise explainer of OpenID Connect (OIDC) and how product-level OIDC misimplementations (as in CVE-2025-54603) can lead to authentication bypasses.

    2–3 minutes