Critical SAML Vulnerabilities Found in SimpleSAMLphp
Multiple high-severity flaws in SimpleSAMLphp expose systems to impersonation and data leaks. Organizations using older Ubuntu LTS versions should act immediately.
Read moreSecurity insights, vulnerability roundups, and updates from the Agent Breach team.
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Multiple high-severity flaws in SimpleSAMLphp expose systems to impersonation and data leaks. Organizations using older Ubuntu LTS versions should act immediately.
Read moreState-backed actors are using a Windows malware controlled through Telegram to conduct surveillance on journalists, activists, and dissidents worldwide. The malware can capture communications, take screenshots, and activate microphones.
Read moreA new Brazilian banking trojan named KREMLIN hijacks Chrome and Edge to steal credentials. Researchers link the campaign to threat actor REF9334.
Read moreA high-severity JWT validation bypass in WSO2 API Manager is under active attack, allowing threat actors to forge admin tokens. Organizations using the platform should take immediate action to mitigate the risk.
Read moreA critical vulnerability in WooCommerce Wholesale Lead Capture is being exploited to upload PHP backdoors. Unauthenticated attackers can achieve remote code execution on affected sites.
Read moreA new hardware attack called DDRop undermines memory protections in Intel TDX and AMD SEV-SNP. It allows attackers to manipulate encrypted data by dropping memory writes.
Read moreMultiple high-severity flaws in ImageMagick affect several Ubuntu LTS versions, potentially leading to DoS, remote code execution, and data leaks.
Read moreA critical flaw in dracut's boot process allows attackers to execute commands as root during system failures. Organizations using Ubuntu should apply patches immediately.
Read moreA Chinese threat actor exploited recently patched vulnerabilities in Chrome and Windows to deploy the GRIMWEDGE backdoor. The campaign targeted NGOs in a spear-phishing operation.
Read moreA critical zero-day in Cisco Secure Email Gateway is being exploited to gain root access. Organizations using the platform should act immediately.
Read more