■■□□□ Microsoft Bounty Program year in review: $17 million in rewards. This is in 12 month’s time. https://msrc.microsoft.com/blog/2025/08/microsoft-bounty-program-year-in-review-17-million-in-rewards/
All posts in Uncategorized
August 8, 2025 at 06:45PM
■□□□□ The CVE Scoring Trap — Why “Critical” Doesn’t Always Mean Critical A recent analysis shows CVSS ratings often exaggerate real risk: 📊 33,000+ CVEs in 2024 — only ~12% of “critical” ones truly critical in practice. 🔍 Review of 140 major CVEs → 88% of “Critical” & 57% of “High” labels misleading. ⚠️ Example:…
August 8, 2025 at 06:23PM
■■■□□ SonicWall: Attackers did not exploit zero-day vulnerability to compromise Gen 7 firewalls. SonicWall: Attackers did not exploit zero-day vulnerability to compromise Gen 7 firewalls
August 8, 2025 at 06:22PM
■■■□□ German security researchers say ‘Windows Hell No’ to Microsoft biometrics for biz. https://www.theregister.com/2025/08/07/windows_hello_hell_no/
August 7, 2025 at 11:50PM
■■■■■ 🔍 Google says the group behind last year’s Snowflake attack slurped data from one of its Salesforce instances. ShinyHunters suspected in rash of intrusions. https://www.theregister.com/2025/08/06/google_salesforce_attacks/
August 7, 2025 at 10:16PM
■■□□□ Microsoft warns of high-severity flaw in hybrid Exchange deployments. https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-high-severity-flaw-in-hybrid-exchange-deployments/
August 7, 2025 at 09:16AM
■□□□□ 📱 OpenAI 20B model realeased a few days ago jail-broken by System-Context injection 💉 https://www.linkedin.com/embed/feed/update/urn:li:ugcPost:7358918839981551617?compact=1
August 6, 2025 at 12:02PM
■■□□□ UAE 🇦🇪 Cyber-Crime: Apparent account takeover on a financial site results in 20K AED burn on the victim. https://gulfnews.com/living-in-uae/banking/buy-now-pay-later-bnpl-fraud-causes-dh20000-loss-for-uae-resident-1.500222951
August 6, 2025 at 11:26AM
■■■■□ Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction. Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction
August 6, 2025 at 12:32AM
■■■□□ ChatGPT Agent Bypasses Cloudflare “I am not a robot” Verification Checks. ChatGPT Agent Bypasses Cloudflare “I am not a robot” Verification Checks
