A wave of product vulnerabilities hits security vendors and enterprise software
Numerous vendors disclosed severe flaws across the security and enterprise software stack, including Zoom, FortiSandbox, FreeRDP, NGINX, SAP, Adobe, Siemens, Schneider Electric, an
Google and Microsoft are tightening identity and OAuth telemetry after stealthy account attacks
Attackers have started abusing OAuth client ID behavior in Microsoft Entra ID to enumerate accounts and evade normal sign-in logging. Proofpoint showed that spoofed client IDs can
RedHook, LabubaRAT, and other mobile malware families widen Android abuse
Several mobile malware reports this week showed attackers expanding their Android tradecraft. RedHook was observed using Wireless ADB to gain shell access without a computer connec
U-Boot and old Secure Boot shims expose a long-lived firmware trust problem
Researchers disclosed six vulnerabilities in U-Boot and separately showed that 11 Microsoft-signed UEFI shim bootloaders can still undermine Secure Boot. These boot-chain problems
Lidl and EY both disclosed third-party support and service-provider data breaches
Lidl notified customers in Germany, Belgium, and the Netherlands that a breach at an external IT service provider exposed customer data stored in a separate file. The retailer said
Google and Microsoft move decisively toward passkeys and stronger sign-in defaults
Microsoft announced major changes to Entra ID that make passkeys the default authentication experience in the public cloud, with SMS and voice gradually being phased down. The comp
A rash of CMS and Joomla flaws is being actively exploited for webshell and file-upload attacks
Australia's Signals Directorate warned that attackers are mounting a broad campaign against content management systems, including WordPress and Joomla, by exploiting known fla
CISA pushes vendors toward more disciplined coordinated vulnerability disclosure
CISA and allied agencies published new coordinated vulnerability disclosure guidance aimed at helping vendors handle reports more consistently. The guidance arrived shortly after C
ClickFix becomes a scalable social-engineering platform for malware delivery
ClickFix moved from a novelty to a widely used attack pattern that tricks users into running commands themselves, bypassing many endpoint defenses. Researchers said the technique n
CrashStealer malware abuses signed apps and fake crash-reporting prompts on macOS
CrashStealer is a new macOS infostealer that disguises itself as Apple's crash-reporting tool and uses signed or notarized components to get past Gatekeeper checks. The malwar

