2026-06-05 19:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: AWS-2025-031 Scope: AWS Content Type: Informational Publication Date: 2025/12/15 11:45 AM PST Description: Harmonix on AWS is an open source reference architecture and implementation of a Developer Platform that extends the CNCF Backstage project. We identified CVE-2025-14503 where an overly-permissive IAM trust policy in the Harmonix on AWS framework may allow authenticated users to escalate privileges via role assumption. The sample code for the EKS environment provisioning role …
P5
2026-06-05 19:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: AWS-2025-016 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/07/25 6:00 PM PDT Description: AWS CodeBuild is a fully managed on-demand continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy. Security researchers reported a CodeBuild issue that could be leveraged for unapproved code modification absent sufficient repository controls and credential scoping. The researchers demonstrat…
P5
2026-06-05 19:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/07/23 6:00 PM PDT Updated Date: 2025/07/25 6:00 PM PDT Description: Amazon Q Developer for Visual Studio Code (VS Code) Extension is a development tool that integrates Amazon Q's AI-powered coding assistance directly into the VS Code integrated development environment (IDE). AWS is aware of and has addressed an issue in the Amazon Q Developer for VS Code Extension, which is assigned to CVE-2025-8217. AWS Security has…
P5
2026-06-05 19:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Scope: Amazon/AWS Content Type: Important (requires attention) Publication Date: 2025/07/23 8:30 AM PDT Description: AWS Client VPN is a managed client-based VPN service that enables secure access to AWS and on-premises resources. The AWS Client VPN client software runs on end-user devices, supporting Windows, macOS, and Linux and provides the ability for end users to establish a secure tunnel to the AWS Client VPN Service. We identified CVE-2025-###, an issue in AWS Client VPN. During the AWS …
P15
2026-06-05 19:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Scope: Amazon Content Type: Informational Publication Date: 2025/06/12 10:30 AM PDT Description Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. When a user powers on the Amazon Cloud Cam, the device attempts to connect to a remote service infrastructure that has been deprecated due to end-of-life status. The device defaults to a pairing status in which an arbitrary user can bypass SSL pinning to associate t…
P5
2026-06-05 19:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: AWS-2025-019 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/10/07 01:30 PM PDT Description: We are aware of blog posts by Embrace The Red (“The Month of AI Bugs”) describing prompt injection issues in Amazon Q Developer and Kiro. Amazon Q Developer: Remote Code Execution with Prompt Injection” and “Amazon Q Developer for VS Code Vulnerable to Invisible Prompt Injection. These issues require an open chat session and intentional access to a malicious f…
P15
2026-06-05 19:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: AWS-2025-018 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/08/14 09:15 PM PDT Description: Amazon Elastic Container Service (Amazon ECS) is a fully managed container orchestration service that enables customers to deploy, manage, and scale containerized applications. Amazon ECS container agent provides an introspection API that provides information about the overall state of the Amazon ECS agent and the container instances. We identified CVE-2025-90…
P5
2026-06-05 19:19 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: AWS-2025-017 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/08/13 10:00 PM PDT Description: Amazon EMR is a managed cluster platform that simplifies running big data frameworks on AWS to process and analyze vast amounts of data. We identified CVE-2025-8904, an issue in the Amazon EMR Secret Agent component. The Secret Agent component securely stores secrets and distributes secrets to other Amazon EMR components and applications. When using Amazon EMR…
P5
2026-06-05 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Defense contractors can achieve CMMC compliance without the expense or delays of FedRAMP-authorized cloud services. Discover how Huntress uses Sensitive Data Mode for logical separation and cost-effective security.
P0
2026-06-05 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception tech…
P0
2026-06-04 17:18 UTC
Other
Black Lantern Security · Jack Pas · indexed 2026-09-07 17:30 UTC
Osnexus Quantastor 9.8 Unauthenticated SQL Injection
P5
2026-06-04 06:15 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Los investigadores de Group-IB exponen una operación de smishing y phishing a gran escala que suplanta más de 260 marcas en 72 países, utilizando páginas de error 524 falsas para evadir el análisis.
P0
2026-06-03 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed. This vulnerability existed because of insufficient validation of user input. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to follow a malicious lin…
P5
2026-06-03 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A malspam campaign abusing Google's DoubleClick delivers the loader through a five-stage chain that evades detection and blinds Windows telemetry before persisting
P0
2026-06-03 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.
P0
2026-06-03 07:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers expose a large-scale smishing and phishing operation impersonating 260+ brands across 72 countries, using fake Cloudflare error pages, geofencing, and encrypted WebSocket channels for real-time credit card theft.
P0
2026-06-02 18:38 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
SolarWinds Web Help Desk Unauthenticated File Upload SolarWinds Web Help Desk contains an unauthenticated file upload vulnerability. A remote attacker can submit arbitrary file uploads to the affected host without authentication, allowing the attacker to consume all available disk space on the volume hosting the application and induce a denial-of-service condition. Ben Smith Tue, 06/02/2026 - 14:38
P0
2026-06-02 18:00 UTC
Vendor Research
Google Security Blog · Eric Lynch · indexed 2026-08-15 18:55 UTC
Warning that says 'someone may be pretending to call from your contact's number'
P0
2026-06-02 16:00 UTC
Government
CERT-EU Threat Intelligence · indexed 2026-08-15 18:50 UTC
Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
P0
2026-06-02 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The same NTLM leakage primitive that got patched in the Snipping Tool exists in Windows Explorer's search: handler. No CVE. No fix. If your patching relies on CVE coverage, you have a blind spot.
P0
2026-06-01 08:23 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn the most common crypto scam types and how they work in practice. Understand how financial institutions can detect fraud earlier and prevent losses at the fiat-to-crypto boundary.
P0
2026-06-01 07:15 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Merchants face $53B in card fraud losses but lack access to compromised card data. Discover the three barriers keeping merchants in the dark — and the solution.
P0
2026-05-29 14:19 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Amazon Cognito 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered a 1-click open redirection technique in Amazon Cognito that can be triggered by abusing the OAuth error-handling mechanism. The vulnerability stems from AWS's OAuth implementation validation sequence: if validation fails due to an unsupported scope, mismatched PKCE parameters, or an unsupported response type, the error handling processes the failure and automatically issues…
P0
2026-05-29 13:56 UTC
Vendor Research
Tenable Research Advisories · Ben Smith · indexed 2026-08-15 18:55 UTC
Microsoft Entra ID 1-Click Open Redirection via OAuth Error Handling Abuse Researchers associated with Tenable have discovered new techniques to trigger 1-click open redirection attacks in Microsoft Entra ID by abusing the OAuth error-handling mechanism. The attack relies on an initial setup phase where a threat actor registers an OAuth application in an actor-controlled tenant and configures its redirect_uri to point to an attacker-controlled domain. When a victim clicks on a specifically craf…
P0
2026-05-29 07:30 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit
P25
2026-05-28 16:00 UTC
Vendor Research
Google Security Blog · Tim Feeley · indexed 2026-08-15 18:55 UTC
Two dashboard side by side
P0
2026-05-28 08:45 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
P0
2026-05-28 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Your social media profiles are an attacker's dossier. Learn how attackers use public data to build attack playbooks and what you can do to give them less to work with.
P0
2026-05-27 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
CMMC is an operating model, not a checklist. Before chasing defense work, audit your MSP's internal operations, including access controls and data handling, to ensure you’re ready for the scrutiny.
P0
2026-05-27 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.
P0