CISA Warns of Exploited Oracle WebLogic Vulnerability

CISA Sounds Alarm on Widely Exploited Oracle WebLogic Vulnerability A critical vulnerability in Oracle’s WebLogic servers has left thousands of organizations exposed to cyber attacks, prompting CISA to issue a high-priority alert. The flaw, known as CVE-2026-21962, can be exploited by hackers without authentication, allowing them to gain remote code execution and potentially take control … Read more

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Cybersecurity experts are sounding the alarm about a serious vulnerability in Oracle’s WebLogic platform, which is currently being actively exploited by hackers. The flaw, dubbed CVE-2023-21707, allows unauthenticated attackers to access sensitive data and potentially take control of vulnerable systems. The issue lies in Oracle’s implementation of the “Cross-Domain Privilege Escalation” (CDPE) feature, which enables … Read more

Rethinking Application Security for the AI Era

As AI continues to transform the way we develop and use software applications, the threat landscape is evolving at an alarming rate. Attackers are leveraging AI and other technologies to rapidly identify, exploit, and patch vulnerabilities, leaving organizations struggling to keep up. In just eight years, the average time it takes for attackers to weaponize … Read more

Personal Information Exposed in Apollo Global Data Breach

A major private equity firm has fallen victim to a sophisticated social engineering attack that exposed sensitive personal information. Apollo Global Management, which manages over $1 trillion in assets, has disclosed a data breach that compromised names, contact details, and Social Security numbers of its clients. The breach is believed to have been carried out … Read more

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

Uber Fined $1 Billion Over Automated Account Suspensions Dutch data protection authorities have slapped ride-hailing giant Uber with a nearly $1 billion fine for using automated software to suspend driver accounts without human oversight. The decision marks the fourth time the company has faced penalties from European regulators over its handling of sensitive data. At … Read more

Hired for One Job, Judged on Another: The CISO’s Real Problem

CISOs Face Double Standard in Performance Evaluation and Business Value Contribution A double standard exists when it comes to evaluating the performance of Chief Information Security Officers (CISOs). During recruitment, potential CISOs are typically expected to possess a strong technical background, extensive security experience, and leadership skills. However, once they take on the role and … Read more

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

A Notorious Hackers’ Group Targeted ReliaQuest, but the Impact Was Minimal, According to the Company Cybersecurity firm ReliaQuest has confirmed that it was targeted by hackers affiliated with the notorious ShinyHunters group. The attackers attempted to gain unauthorized access to ReliaQuest’s systems using a sophisticated social engineering tactic. However, in a rare instance of good … Read more

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts Dutch data protection authorities have slapped a massive fine on Uber, worth nearly $1 billion, for using automated software to suspend driver accounts without human review. The ride-hailing company is accused of violating the EU’s General Data Protection Regulation (GDPR), which … Read more

Hired for One Job, Judged on Another: The CISO’s Real Problem

The Double Standard Facing CISOs: Where Technical Expertise Meets Business Acumen Chief Information Security Officers (CISOs) are often hired for their technical prowess and security experience, but when it comes time to evaluate their performance, they’re judged on a different set of criteria entirely. The disconnect between these two expectations can be particularly challenging for … Read more

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest, a cybersecurity firm, has confirmed that it was targeted by hackers affiliated with the notorious ShinyHunters group. However, despite the sophistication of the attack, the company claims that its impact was limited to gaining view-only access to one employee’s Okta dashboard. The incident began when ReliaQuest noticed a widespread phishing campaign launched by ShinyHunters … Read more