23andMe Settles Data Privacy Claims
A coalition of attorneys general has secured an $18 million settlement from 23andMe regarding a 2023 genetic data breach.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A coalition of attorneys general has secured an $18 million settlement from 23andMe regarding a 2023 genetic data breach.
A persistent security researcher has unveiled a local privilege escalation bug for Windows 11, raising questions about severity.
A critical server-side request forgery vulnerability in stoatchat allows unauthenticated attackers to access internal network infrastructure.
CISA has confirmed active exploitation of an OS command injection vulnerability in Fortinet FortiSandbox, mandating urgent remediation for federal agencies.
A deserialization vulnerability in Microsoft SharePoint is currently being exploited in the wild, prompting an urgent remediation deadline for federal agencies.
A critical server-side request forgery vulnerability in Stoatchat versions prior to 0.13.5 allows unauthenticated access to networks.
A critical account lockout vulnerability in KNX Association products is now under active exploitation, requiring immediate remediation by federal agencies.
An improper privilege management flaw in Oracle E-Business Suite is being actively exploited, potentially allowing unauthorized access to Oracle Payments.
A threat actor successfully leveraged Google's Gemini CLI to manage a botnet by manipulating the AI into performing malicious tasks.
Security experts are grappling with the unique, often catastrophic vulnerabilities embedded in aging industrial control hardware.
A cyberattack on TriWest Healthcare compromised sensitive personal information belonging to approximately 12,000 TRICARE beneficiaries.
A registry-level suspension of t.me links reveals how quickly infrastructure can be shuttered under OFAC sanction enforcement.
Nation-state actors are weaponizing generative AI to bypass traditional hiring filters and secure roles within high-value organizations.
A critical vulnerability identified as CVE-2023-49900 allows unauthenticated remote attackers to execute arbitrary code due to improper input sanitization.
A critical account lockout vulnerability in the KNX Protocol Connection Authorization Option 1 is currently being exploited in the wild.
An improper privilege management vulnerability in Oracle E-Business Suite is currently being exploited in the wild, risking full takeover of Oracle Payments.
Rapid expansion of AI-specific infrastructure is outpacing security protocols, leaving massive compute clusters vulnerable to risk.
Migration inertia leaves nearly one in six Windows devices exposed as security vulnerabilities mount for legacy operating systems.
A single master password granted unrestricted access to sensitive client files and employee impersonation at a law firm.
Freshly emerged from stealth, Oak secures $60 million to tackle identity fragmentation across human, AI, and machine vectors.