2025-09-15 17:01 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Daniel MoghimiRowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows, leading to data corruption. This can be exploited by attackers to gain unauthorized access to data, escalate privileges, or cause denial of service. Hardware vendors have deployed various mitigations, such as ECC and Target Row Refresh (TRR) for DDR5 memory, to mitigate Rowhammer and e…
P10
2025-09-15 05:44 UTC
Other
Red Hunt Labs · Bhavarth Karmarkar · indexed 2026-09-07 17:30 UTC
In July 2025, the Tea app 🔗, a mental health and social community platform, experienced a devastating breach that spilled 72,000 images (including 13,000 driver’s license and verification selfies) and over 1.1 million private direct messages onto the internet. The leaks first surfaced on 4chan and quickly spread across forums, torrents, and underground channels. This was not “just another API key leak.” Instead, it was a story about Firebase misconfigurations, poor data retention practices, an…
P25
2025-07-21 21:34 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Matthew Suozzo, Google Open Source Security Team (GOSST)Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers.The project comprises:Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/T…
P0
2025-06-13 16:03 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is indirect prompt injections. Unlike direct prompt injections, where an attacker directly inputs malicious commands into a prompt, indirect prompt injections involve hidden malicious instructions within external data sources. These may include emails, documents, or…
P0
2024-08-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Researchers discovered critical vulnerabilities in 6 AWS services that could allow attackers to breach accounts through malicious S3 buckets. By claiming predictable bucket names, attackers could inject code, steal data, or gain admin access. AWS has since fixed the issues, but the attack vector may still apply to other services and open source projects.
P0
2024-08-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Semperis researchers discovered vulnerabilities in Microsoft applications that allowed privilege elevation in Entra ID beyond expected authorization controls. The most severe finding enabled adding users to privileged roles, including Global Administrator, without proper permissions. The issues affected Device Registration Service, Viva Engage, and Microsoft Rights Management Service. Microsoft has since resolved the vulnerabilities.
P0
2023-11-30 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Unit 42 researchers discovered a security risk in Google Workspace's domain-wide delegation feature that allows a GCP identity with necessary permissions to generate access tokens to impersonate Google Workspace users and access their data. This mismatch between GCP permissions and Google Workspace access could be exploited by malicious insiders or attackers with stolen credentials.
P0
2023-08-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Secureworks researchers discovered an Azure AD application with an abandoned reply URL related to Microsoft Power Platform. An attacker could leverage this URL to redirect authorization codes, exchange them for access tokens, and call Power Platform API via a middle-tier service to obtain elevated privileges. Microsoft quickly addressed the issue by removing the identified abandoned reply URL from the Azure AD application.
P10
2022-12-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Our team has been tracking conversations surrounding ConnectWise Control vulnerabilities and alleged exploitation. We politely disagree with the threat and criticality presented by the security researcher.
P0
2022-03-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Take a behind-the-scenes look at what our security researchers do in this Q&A session.
P0
2021-07-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Our Security Researchers discuss how hackers executed the Kaseya VSA supply chain attack—and why the blast radius of the incident was relatively limited.
P15
2020-08-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Researchers discovered vulnerabilities in Google Cloud SQL that allowed gaining unauthorized shell access to MySQL instances. By chaining SQL injection, parameter injection in mysqldump, and network spoofing, they were able to escape a Docker container and gain full access to the host VM running Cloud SQL.
P0
2019-04-25 15:16 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers discovered Illum JS-sniffers family designed to steal payment data of customers of online stores.
P0