FortiGate Exploit Opens Broadband Provider to Credential Theft and Network Pivoting
Researchers uncovered infrastructure indicating that attackers exploited a FortiGate SSL-VPN weakness during an intrusion targeting Thailand’s 3BB broadband provider. The operation combined perimeter access, privilege escalation, credential theft...
Cisco Email Gateway Zero-Day Gives Remote Attackers Root Control
Cisco is warning that attackers are exploiting a critical Secure Email Gateway zero-day to execute commands as root without authentication. Organizations should isolate management interfaces, apply Cisco’s remediation...
Malicious Twitch Extension Leaks OAuth Tokens From 30,000 Browser Users
A Twitch helper extension installed by about 30,000 Chrome and Firefox users was found sending active account tokens through operator-controlled servers. The incident shows how a seemingly convenient...
Mass Scanning of Exposed Vite Servers Targets AWS and Azure Secrets
Attackers are automatically probing internet-accessible Vite development servers for environment files, cloud credentials and infrastructure secrets. F5 telemetry recorded about 32,000 raw events in August, highlighting the risk...
StyleSmuggler Zero-Day Leaves Every Current Magento and Adobe Commerce Store Exposed to Takeover
A newly disclosed zero-day dubbed StyleSmuggler lets attackers hijack Magento Open Source and Adobe Commerce stores by smuggling PHP code through routine GraphQL requests and triggering it via...
Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure
This week’s security picture is dominated by exploited Windows and Chrome zero-days, dangerous flaws in perimeter products and increasingly automated attack operations. Defenders need risk-based patch sequencing, exposure...
Fraudulent Government Request Exposes Revolut KYC Records and Transaction Histories
Revolut disclosed that a fraudulent request sent from an official government email domain led to the release of highly sensitive customer records. The incident shows why authenticated email...
Dell ObjectScale CVSS 10 Flaw Exposes Enterprise Storage to Remote Takeover
Dell has fixed a maximum-severity ObjectScale vulnerability that could let an unauthenticated remote attacker execute code on exposed storage systems. Organizations should upgrade quickly, reduce management-plane exposure and...