π΅οΈ RESEARCH & DEEP DIVES
-
Multiple Google Chrome vulnerabilities could allow arbitrary code execution
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow arbitrary code execution.- Affects users of the Google Chrome web browser.
- Multiple vulnerabilities were discovered in Chrome; the most severe could allow arbitrary code execution.
- Successful exploitation could let attackers install programs; view, change, or delete data; or create new accounts with full user rights.
- Impact depends on the privileges of the logged-on user; accounts with fewer rights are less affected than those with administrative rights.
π Coverage: cisecurity.org Β· π via CIS Advisories
-
Dropbox: ~5,000 accounts compromised via Lenovo ID sign-in flaw in August
Dropbox disclosed that attackers compromised about 5,000 user accounts in August by abusing its Lenovo ID sign-in integration.- Dropbox users who sign in via the Lenovo ID third-party identity integration were affected.
- Approximately 5,000 accounts were compromised in August; Dropbox notified affected users.
- Attackers exploited weak account-level verification when Dropbox trusted the third-party identity provider to grant access.
π Coverage: cybersecuritynews.com Β· π via Cyber Security News
π΅οΈ RESEARCH & DEEP DIVES
-
Ransomware protection for MSPs: A 6-point checklist for faster recovery β BleepingComputer
-
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure β SecurityWeek
-
A16z Says You Actually Love Social Media, Enshittification Isnβt Real β 404 Media
-
Texas Police Used AI to Write Report About Using Flock to Search for Woman Who Had Abortion β 404 Media
-
The Republican Nominee for New York Governor Made a Creepy, AI-Generated Video of Mamdani and Hochul β 404 Media
-
Cops Are Asking Axon to Make Their Cameras Look Different From Flock So People Don't Destroy Them β 404 Media
-
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code β The Hacker News
-
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages β The Hacker News
-
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks β CrowdStrike Blog
-
CrowdStrike Delivers the Next Evolution of the Agentic SOC β CrowdStrike Blog
-
CrowdStrike Announces Agentic Identity Provider β CrowdStrike Blog
-
Pegasus, NoviSpy variant spyware found on devices of Serbian activists β CyberScoop
-
Wyden seeks upgraded NSA security guidance on commercial VPN use β CyberScoop
-
Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided val... β CVE ThreatInt
-
Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens u... β CVE ThreatInt
-
OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlie... β CVE ThreatInt
-
Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and ea... β CVE ThreatInt
-
Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows ov... β CVE ThreatInt
-
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 an... β CVE ThreatInt
-
NGINX ngx_http_js_module vulnerabilityA vulnerability exists in NGINX JavaScr... β CVE ThreatInt
-
Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing ... β CVE ThreatInt
-
NGINX ngx_http_js_module vulnerablilityDescription NGINX JavaScript (njs) has... β CVE ThreatInt
-
NGINX Ingress Controller vulnerabilityWhen NGINX Ingress Controller is config... β CVE ThreatInt
-
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict... β CVE ThreatInt
-
NGF vulnerabilityDescription: When NGINX Plus is configured as the data plane... β CVE ThreatInt
-
NGINX ngx_http_js_module vulnerabilityDescription NGINX JavaScript (njs) and ... β CVE ThreatInt
-
A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier al... β CVE ThreatInt
-
BIG-IP and BIG-IQ Configuration utility vulnerabilityBIG-IP has a vulnerabili... β CVE ThreatInt
-
BIG-IP Configuration utility vulnerabilityA vulnerability exists in an undisc... β CVE ThreatInt
-
Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the ... β CVE ThreatInt
-
Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's b... β CVE ThreatInt
-
Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier all... β CVE ThreatInt
-
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL scheme... β CVE ThreatInt
-
Your DNS Is Hiding in HTTPS β This Is Why It Matters β Akamai Blog
-
GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok β Cyber Security News
-
Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse β Cyber Security News
-
Russian Hacker Indicted for Using Excel Malware to Target 80,000 Freelancers With TVRAT and DarkVNC β Cyber Security News
-
Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools β Cyber Security News
-
OWASP Top 10 CI/CD Security Risks Explained: Why Credential Hygiene Decides the Outcome β securityboulevard.com (discovered)
-
Palo Alto Acquires Console to Expand Cortex Agentic Security β securityboulevard.com (discovered)
-
What a 14-Day Federal Patch Clock Costs a Team That Isnβt a Federal Agency β securityboulevard.com (discovered)
-
Capsule Security Partners with NVIDIA to Secure AI Agents β <https://securityboulevard.com/2026/09/capsule-security-partners-with-nvidia-to-secure-ai-agents/|securityboulevard