React2Shell flaw (CVE-2025-55182) exploited for remote code execution
The availability of exploit code will likely lead to more widespread opportunistic attacks
Cybersecurity researchers have disclosed a critical flaw impacting Salesforce Agentforce, a platform for building artificial intelligence (AI) agents, that could allow attackers to potentially exfiltrate sensitive data from its customer relationship management (CRM) tool by means of an indirect prompt injection. The vulnerability has been codenamed ForcedLeak (CVSS score: 9.4) by Noma Security,
A sea change in available data fuels fresh insights from the first half of 2024
Substance abuse treatment provider BayMark Health Services says patient personal information was compromised in a data breach. The post Major Addiction Treatment Firm BayMark Confirms Ransomware Attack Caused Data Breach appeared first on SecurityWeek.
In the fourth of our five-part series, Sophos X-Ops explores threat actors’ real-world criminal business interests
In cybersecurity, speed isn’t just a win — it’s a multiplier. The faster you learn about emerging threats, the faster you adapt your defenses, the less damage you suffer, and the more confidently your business keeps scaling. Early threat detection isn’t about preventing a breach someday: it’s about protecting the revenue you’re supposed to earn…
There’s an update to a case reported previously on this site. From the U.S. Attorney’s Office for the Western District of Missouri: KANSAS CITY, Mo. – A Kansas City, Mo., man has pleaded guilty for hacking into the computer system at an area nonprofit. Nicholas Michael Kloster, 32, admitted during his plea that he caused…