#Vulnerabilities

Cyberattacks by AI agents are coming
Agents could make it easier and cheaper for criminals to hack systems at scale. We need to be ready.
technologyreview.com/2025/04/0
#cybersecurity #AI #agenticAI #cyberattacks #vulnerabilities #honeypots #LLMhoneypots

Alexandre Dulaunoyadulau@infosec.exchange
2025-05-29

The VLAI Severity model is accessible via API. Here is a simple example from a recent Ivanti vulnerability description from their vulnerability webpage.

The VLAI Security model for vulnerabilities is accessible via vulnerability-lookup and the public instance operated by CIRCL.

So, if you have a vulnerability description, you can quickly assess it to get a general idea of its severity.

curl -X 'POST' \
'https://vulnerability.circl.lu/api/vlai/severity-classification' \
-H 'accept: application/json' \
-H 'Content-Type: application/json' \
-d '{ "description": "Ivanti has released updates for Ivanti Neurons for ITSM (on-prem only) which addresses one critical severity vulnerability. Depending on system configuration, successful exploitation could allow an unauthenticated remote attacker to gain administrative access to the system. We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure. We have included an environmental score to provide customers with additional context on the adjusted risk of this vulnerability with typical use cases. Customers who have followed Ivanti guidance on securing the IIS website and restricted access to a limited number of IP addresses and domain names have a reduced risk to their environment. Customers who have users log into the solution from outside their company network also have a reduced risk to their environment if they ensure that the solution is configured with a DMZ." }'

and the result

{
"severity": "Critical",
"confidence": 0.9256
}

#cve #ivanti #vulnerability #vulnerabilitymanagement #vulnerabilities

For more details: vulnerability-lookup.org/2025/

@circl @gcve

Christoffer S.nopatience@swecyb.com
2025-05-27

Targeted attacks against MSP:s, NATO and Ukraine. Two stories from Sophos and Microsoft published today.

The MSP-attack involved abusing vulnerabilities in SimpleHelp chaining a number of vulnerabilities. A little bit of a more advanced attack IMHO.

Then you have the NATO and Ukraine attacks as detailed by Microsoft, involving password spraying and likely bought credentials from criminal ecosystems.

Funny. Ransomware attackers are more advanced than APTs ๐Ÿ™‚

References:
news.sophos.com/en-us/2025/05/

microsoft.com/en-us/security/b

#Cybersecurity #ThreatIntel #PasswordSpray #Password #StolenCredentials #APT #LAUNDRYBEAR #VoidBlizzard #Russia #NATO #Ukraine #SimpleHelp #Vulnerabilities #Vulnerability

Rene Robichaudnerowild
2025-05-22
N-gated Hacker Newsngate
2025-05-22

๐Ÿš€ Oh joy! Another Linux GUI that promises to make performance analysis as fun as watching paint dry. ๐Ÿคช Because we all know developers just love drowning in a sea of menus and toggles while hunting down those pesky with AI magic. ๐Ÿง™โ€โ™‚๏ธโœจ
github.com/KDAB/hotspot

Teddy / Domingo (๐Ÿ‡จ๐Ÿ‡ต/๐Ÿ‡ฌ๐Ÿ‡ง)TeddyTheBest@framapiaf.org
2025-05-20

'Operation RoundPress' Targets #Ukraine in #XSS #Webmail Attacks. A cyber-espionage campaign is targeting Ukrainian government entities with a series of sophisticated spear-#phishing #attacks that exploit XSS #vulnerabilities.
darkreading.com/threat-intelli

Sam Stepanyan :verified: ๐Ÿ˜securestep9@infosec.exchange
2025-05-17

#Ivanti: Ivanti Endpoint Mobile Manager (#EPMM) #Vulnerabilities CVE-2025-4427 and CVE-2025-4428 Allow Remote Code Execution and being actively exploited in the wild - patch your systems now!
๐Ÿ‘‡
cybersecuritynews.com/ivanti-e

Rene Robichaudnerowild
2025-05-16
2025-05-15

Curious what happens if the #vulnerabilities in your software change? Our experts cover that and much more in this on-demand webinar that dives into SBOMs and how they can help your organization in a zero-day moment.
get.anchore.com/rapid-incident #SBOM

2025-05-15

ENISA has recently launched the European Vulnerability Database #EUVD to bolster EU digital security. This database consolidates data on critical, exploited and coordinated #vulnerabilities, making it readily accessible to the public๐Ÿ›ก๏ธ๐Ÿ‘ฉโ€๐Ÿ’ป #threatintel

helpnetsecurity.com/2025/05/14

Teddy / Domingo (๐Ÿ‡จ๐Ÿ‡ต/๐Ÿ‡ฌ๐Ÿ‡ง)TeddyTheBest@framapiaf.org
2025-05-14

#Windows #ZeroDay #Bug Exploited for Browser-Led RCE. #Microsoft's May 2025 Patch Tuesday update also contains four other actively exploited zero-day #security #vulnerabilities, two publicly known bugs, and 12 critical patches.
darkreading.com/vulnerabilitie
Well, simply don't use Microsoft products. Use #freesoftware, much less sensible to vulnerabilities, and more respecting your #privacy and your #personaldata
#Linux #Distro are the best

Negative PID Inc.negativepid
2025-05-13

๐ŸŽฎ๐Ÿ” Do you remember the infamous Sony PlayStation Network hack? As a pivotal case study, this attack highlights the advancements in cybersecurity following one of history's most significant cyberattacks on cloud platforms.

negativepid.blog/the-sony-play

knoppixknoppix95
2025-05-13

The has launched its Vulnerability Database (EUVD) to enhance management, providing reliable data on exploited vulnerabilities and integrating information from various sources.

Manufacturers must report actively exploited vulnerabilities by September 2026.

While a significant step forward, it lacks RSS feeds for real-time updates.

Once again, a good move from the EU.

thecyberexpress.com/eu-vulnera

Brian Slettenbsletten
2025-05-13

European vulnerability database opens in case the dumbass Americans cut funding again.

infosecurity-magazine.com/news

2025-05-13

Researchers at ETH Zurich identified new #Vulnerabilities in Intel #Processors that enable users to bypass barriers and access the entire processor memory through quick, repeated attacks. ethz.ch/en/news-and-...

ETH Zurich researchers discove...

Marcus "MajorLinux" Summersmajorlinux@toot.majorshouse.com
2025-05-13

This time I'm begging you to update yo shit!

PSA: iOS 18.5 patches over 30 iPhone security vulnerabilties - 9to5Mac

9to5mac.com/2025/05/12/ios-18-

#iOS #Patching #iPhone #Security #InfoSec #Vulnerabilities #Apple #Tech

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst