#zero-day-vulnerability

[ follow ]
fromSecuritymagazine
1 week ago

Logitech Confirms Data Breach, Security Leaders Respond

Logitech believes that the unauthorized third party used a zero-day vulnerability in a third-party software platform and copied certain data from the internal IT system. The zero-day vulnerability was patched by Logitech following its release by the software platform vendor. The data likely included limited information about employees and consumers and data relating to customers and suppliers. Logitech does not believe any sensitive personal information, such as national ID numbers or credit card information, was housed in the impacted IT system.
Information security
fromZDNET
1 week ago

Update Chrome ASAP - attackers are already exploiting this nasty zero-day flaw

Another day, another zero-day, at least for Google Chrome. In an advisory released Monday, Google warned of a dangerous new security vulnerability affecting its popular browser. Fortunately, the latest update squashes the bug. Here are the details. Rated as a high security flaw, the zero day labeled CVE-2025-13223 is described as: "Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page."
Information security
Information security
fromIT Pro
1 week ago

Logitech says zero-day attack saw hackers copy 'certain data' from internal IT systems

Logitech experienced a cyberattack exploiting a zero-day in a third-party platform, resulting in limited exfiltration of employee, customer, and supplier data while operations remain unaffected.
fromTheregister
1 week ago

Logitech leaks data after zero-day attack

The continued suppression of a report identifying serious vulnerabilities of the U.S. telecommunications sector undermines the public's understanding of these threats and stymies an important public debate on a path forward,
Information security
Information security
fromSecurityWeek
1 month ago

Chinese Hackers Breached Law Firm Williams & Connolly via Zero-Day

State-sponsored hackers breached Williams & Connolly and accessed a small number of attorneys' email accounts by exploiting an unspecified zero-day vulnerability.
fromDataBreaches.Net
1 month ago

US law firm with major political clients hacked in spying spree linked to China - DataBreaches.Net

Suspected Chinese government-backed hackers have breached computer systems of U.S. law firm Williams & Connolly, which has represented some of America's most powerful politicians, as part of a larger spying campaign against multiple law firms, according to a letter the firm sent clients and a source familiar with the hack. The cyber intrusions have hit the email accounts of select attorneys at these law firms, as Beijing continues a broader effort to gather intelligence to support its multi-front competition with the U.S.
Information security
fromTechCrunch
3 months ago

SonicWall urges customers to disable SSLVPN amid reports of ransomware attacks | TechCrunch

SonicWall has observed an increase in security incidents affecting its Generation 7 firewalls with VPN enabled, signaling potential exploitation of a new vulnerability.
Information security
#cybersecurity
fromHackernoon
5 months ago
Information security

Microsoft Just Confirmed a SharePoint Bug Under Attack-And It's Worse Than You Think | HackerNoon

Information security
fromTechCrunch
4 months ago

Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day | TechCrunch

Hackers backed by China are exploiting a zero-day vulnerability in Microsoft SharePoint, affecting organizations globally.
fromHackernoon
5 months ago
Information security

Microsoft Just Confirmed a SharePoint Bug Under Attack-And It's Worse Than You Think | HackerNoon

fromTechCrunch
4 months ago
Information security

Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day | TechCrunch

#microsoft
Bootstrapping
fromThe Hacker News
5 months ago

Microsoft Patches 67 Vulnerabilities Including WEBDAV Zero-Day Exploited in the Wild

Microsoft patched 67 security flaws, including a critical zero-day vulnerability in WEBDAV exploited in active attacks.
fromTechzine Global
6 months ago

SAP releases patch for second zero-day vulnerability in NetWeaver

SAP has released security updates addressing CVE-2025-42999, a zero-day vulnerability in NetWeaver, to ensure customer protection against ongoing attacks.
Information security
[ Load more ]