Vulnerabilities
-
Chess.com discloses data breach linked to third-party file-transfer app; around 4,500 users affected
Chess.com says a data breach tied to a third-party file-transfer app affected about 4,500 of its 100 million users, with potential exposure of names and other PII but no financial data, and says law enforcement was notified and monitoring continues.
-
Misissued TLS certificates tied to Cloudflare’s 1.1.1.1 DNS service raise internet-security concerns
Security researchers disclosed mis-issued TLS certificates tied to Cloudflare’s 1.1.1.1 DNS service, a flaw that could enable impersonation and traffic interception. With the issuer and responsible parties not fully disclosed, the episode underscores ongoing vulnerabilities in the certificate authority system and the role of Certificate Transparency in detecting mis-issuances.
-
Threat actors weaponize HexStrike AI to exploit recently disclosed vulnerabilities, Check Point warns
Threat actors are weaponizing HexStrike AI, an AI-driven offensive security tool, to exploit recently disclosed vulnerabilities, prompting Check Point to urge immediate patching and hardening of affected systems.
-
Public appsettings.json leak exposes Azure AD credentials, enabling potential cloud access
Researchers from Resecurity’s HUNTER team warn that a publicly accessible appsettings.json file leaked Azure AD credentials (ClientId and ClientSecret), potentially enabling attackers to authenticate via OAuth 2.0 and access an organization’s Azure cloud resources; the incident underscores the ongoing risk of cloud-secret exposure and the need for strong secret-management practices.
-
Jaguar Land Rover says cyberattack severely disrupted production; no evidence of customer data theft yet
Jaguar Land Rover said a weekend cyberattack severely disrupted production and retail operations, but there is no evidence yet that customer data was stolen. The company is restarting affected systems and did not specify a timeline for full recovery.
-
NIST Revamps Security Controls to Tighten Software Updates and Patch Management
NIST has revised its Security and Privacy Control Catalog to strengthen software update and patch management, introducing changes aimed at better incident response, root-cause analysis, and cyber resiliency to reduce the window of exposure in software supply chains.
-
WhatsApp patches high-severity vulnerability tied to Apple zero-day in targeted attacks on iOS and macOS
WhatsApp has patched a high-severity vulnerability in its iOS and macOS apps (CVE-2025-55177) that could allow an attacker to process content from an arbitrary URL on a target device, potentially in conjunction with a separate Apple zero-day. Affected versions include iOS and Mac apps; targeted individuals have been notified and advised to reset devices and…
-
TamperedChef information stealer emerges in malvertising campaign promoting AppSuite PDF Editor
Cybersecurity researchers have identified a malvertising campaign delivering a backdoored PDF editor, AppSuite PDF Editor, that drops a new information stealer dubbed TamperedChef. The operation leverages Windows Registry persistence, a C2-enabled backdoor, and widespread Google ad campaigns to maximize downloads.
-
High-severity authentication bypass patched in Passwordstate credential manager, vendor says
Click Studios has released a patch for Passwordstate to fix a high-severity authentication bypass vulnerability that could allow attackers to access the emergency access page and the admin area. The vulnerability affects Passwordstate deployments used by thousands of customers and security professionals, with a CVE identifier not yet assigned. The company has published a forum…










