1
0
1
0
1
0
1
0
0
1
1
0
1
0
VulnHub

AI-Powered Cybersecurity Intelligence

Latest Intelligence

The Hacker News
Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44

Cybersecurity researchers have identified a critical security flaw in the Base44 vibe coding platform that could enable unauthorized access to user-built private applications. The vulnerability was easy to exploit, requiring only a non-secret app_id value to access undocumented endpoints. Read Original »


Impact: Base44

Remediation: The vulnerability has been patched.

ExploitVulnerability

Added:

The Hacker News
PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain

The Python Package Index (PyPI) has alerted users about a phishing campaign that involves fake verification emails sent from a lookalike domain. These emails aim to mislead users into visiting fraudulent PyPI sites. Read Original »


Impact: PyPI

Remediation: Users should verify the sender's email address and avoid clicking on links in suspicious emails.

Phishing

Added:

darkreading
The Hidden Threat of Rogue Access

The article emphasizes the importance of implementing Identity Governance and Administration (IGA) tools along with effective governance policies to identify and mitigate rogue access in enterprises. By setting appropriate risk thresholds, organizations can proactively detect and respond to potential security threats before they are exploited by attackers. Read Original »


Impact: Not specified

Remediation: Utilize IGA tools, establish governance policies, and define risk thresholds.

Added:

darkreading
Critical Flaw in Vibe-Coding Platform Base44 Exposed Apps

A critical authentication flaw on the Base44 vibe-coding platform allowed unauthorized users to access private applications. This vulnerability has since been patched, but it raised significant security concerns for users of the platform. Read Original »


Impact: Base44

Remediation: The issue has been patched.

Vulnerability

Added:

SecurityWeek
Seal Security Raises $13 Million to Secure Software Supply Chain

Seal Security, an open source security firm, has secured $13 million in funding to bolster its market presence and expedite the expansion of its platform. This investment aims to enhance efforts in securing the software supply chain. Read Original »


Impact: Not specified

Remediation: Not specified

Added:

The Hacker News
Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims

A new ransomware-as-a-service group called Chaos has emerged, likely composed of former members of the BlackSuit crew following a law enforcement takedown. This group is engaging in big-game hunting and double extortion attacks, demanding $300K from victims in the U.S. Read Original »


Impact: Not specified

Remediation: Not specified

Ransomware

Added:

SecurityWeek
Promptfoo Raises $18.4 Million for AI Security Platform

Promptfoo has successfully raised $18.4 million in Series A funding to enhance security measures for large language models (LLMs) and generative AI applications. This funding aims to assist organizations in safeguarding their AI technologies against potential vulnerabilities. Read Original »


Impact: Not specified

Remediation: Not specified

Added:

darkreading
Supply Chain Attacks Spotted in GitHub Actions, Gravity Forms, npm

Researchers have identified serious security vulnerabilities, including backdoors and malicious code, in popular development tools, which pose a significant risk to software supply chains. These findings highlight the ongoing threats within the software development ecosystem. Read Original »


Impact: GitHub Actions, Gravity Forms, npm

Remediation: Not specified

Added:

All CISA Advisories
CISA Releases Part One of Zero Trust Microsegmentation Guidance

CISA has released guidance on microsegmentation as part of its efforts to assist Federal Civilian Executive Branch agencies in implementing zero trust architectures. This guidance highlights the importance of microsegmentation in reducing attack surfaces and enhancing network security while providing a foundation for future technical implementation resources. Read Original »


Impact: Not specified

Remediation: Not specified

Added:

All CISA Advisories
CISA Releases Five Industrial Control Systems Advisories

CISA has released five advisories addressing security vulnerabilities in various Industrial Control Systems (ICS), providing critical updates and mitigation strategies. These advisories aim to inform users and administrators about the current security landscape affecting ICS products. Read Original »


Impact: Johnson Controls, Fuji Electric, National Instruments, Samsung, Delta Electronics

Remediation: Review newly released ICS advisories for technical details and mitigations.

Update

Added:

All CISA Advisories
National Instruments LabVIEW

National Instruments LabVIEW has vulnerabilities related to improper restriction of operations within the bounds of a memory buffer, affecting versions 2025 Q1 and prior. Successful exploitation could lead to arbitrary code execution and invalid memory reads. Read Original »


Impact: LabVIEW: 2025 Q1 and prior versions

Remediation: National Instruments has released patches for the affected products. Users are advised to minimize network exposure and use secure remote access methods.

PhishingCVEVulnerabilityUpdate

Added:

All CISA Advisories
Delta Electronics DTN Soft

Delta Electronics' DTN Soft has a vulnerability related to deserialization of untrusted data, allowing attackers to execute arbitrary code using specially crafted project files. The vulnerability affects versions 2.1.0 and prior, and a CVE identifier has been assigned. Read Original »


Impact: Delta Electronics DTN Soft: Versions 2.1.0 and prior

Remediation: Update DTN Soft to version 2.1.0 or later; update DTM Soft to version 1.6.0.0 or later.

PhishingCVEVulnerabilityUpdate

Added:

All CISA Advisories
Samsung HVAC DMS

The article details multiple vulnerabilities in Samsung's HVAC DMS software, which could allow unauthenticated remote code execution and unauthorized file access. These vulnerabilities include execution after redirect, deserialization of untrusted data, and various path traversal issues, posing significant risks to users. Read Original »


Impact: Samsung HVAC DMS: Versions 2.0.0 to 2.3.13.0, Versions 2.5.0.17 to 2.6.14.0, Versions 2.7.0.15 to 2.9.3.5

Remediation: Contact a Samsung call center or installer for a software update; disconnect the product from the Internet.

PhishingCVEVulnerabilityUpdate

Added:

All CISA Advisories
CISA Releases Part One of Zero Trust Microsegmentation Guidance

CISA has released guidance on microsegmentation as part of its Zero Trust architecture implementation for Federal Civilian Executive Branch agencies. This guidance outlines the importance of microsegmentation in enhancing network security by reducing attack surfaces and limiting lateral movement within networks. Read Original »


Impact: Not specified

Remediation: Recommended actions to modernize network security and advance zero trust principles

Added:

All CISA Advisories
CISA and Partners Release Updated Advisory on Scattered Spider Group

CISA and its partners have released an updated advisory on the Scattered Spider cybercriminal group, which targets commercial facilities using various tactics, including ransomware and social engineering techniques. The advisory outlines the group's tactics, techniques, and procedures (TTPs) and provides recommendations for organizations to enhance their cybersecurity defenses. Read Original »


Impact: Not specified

Remediation: Recommendations to fortify defenses for critical infrastructure organizations and commercial facilities.

RansomwarePhishing

Added: