-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity security flaw impacting TP-Link TL-WA855RE Wi-Fi Ranger Extender products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, CVE-2020-24363 (CVSS score: 8.8), concerns a case of missing authentication that could be abused to obtain
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cloudflare has disclosed a significant data breach affecting customer information following a sophisticated supply chain attack targeting its Salesforce integration with Salesloft Drift. The incident, which occurred between August 12-17, 2025, resulted in the exposure of customer support case data and potentially sensitive credentials shared through support channels. The Breach Details The cybersecurity company became […]
The post Cloudflare Confirms Data Breach – Customer Data Exposed via Salesforce Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated malware operation that combines multiple attack vectors to steal cryptocurrency and deliver additional malicious payloads to Windows systems. A recently discovered TinyLoader malware campaign is actively targeting Windows users through a multi-pronged attack strategy involving network share exploitation, USB propagation, and deceptive shortcut files. The malware, which serves as a delivery mechanism for […]
The post TinyLoader Malware Spreads via Network Shares and Malicious Shortcut Files on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Salesloft on Tuesday announced that it’s taking Drift temporarily offline “in the very near future,” as multiple companies have been ensnared in a far-reaching supply chain attack spree targeting the marketing software-as-a-service product, resulting in the mass theft of authentication tokens. “This will provide the fastest path forward to comprehensively review the application and build
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cloudflare has confirmed a data breach where a sophisticated threat actor accessed and stole customer data from the company’s Salesforce instance.
The breach was part of a wider supply chain attack that exploited a vulnerability in the Salesloft Drift chatbot integration, affecting hundreds of organizations globally.
In a detailed disclosure, Cloudflare explained that the threat actor, which its intelligence team has named GRUB1, gained unauthorized access to its Salesforce environment between August 12 and August 17, 2025.
The company uses Salesforce for customer support and internal case management. The hackers successfully exfiltrated data from Salesforce “cases,” which are primarily customer support tickets.
The compromised information was limited to the text fields within these support cases. This data includes customer contact information, case subject lines, and the body of the correspondence.
Cloudflare emphasized that while they do not request customers to share sensitive information in support tickets, any credentials, API keys, logs, or passwords that customers may have pasted into the text fields should now be considered compromised.
No attachments to the cases were accessed, and no Cloudflare services or core infrastructure were breached as a result of this incident.
As part of its response, Cloudflare conducted a search through the stolen data and discovered 104 of its own API tokens. While no suspicious activity was associated with them, these tokens have been rotated as a precaution. All customers whose data was compromised have been directly notified by Cloudflare as of September 2, 2025.
The investigation revealed that the attack began with reconnaissance on August 9, with the initial compromise occurring on August 12. The threat actor used the stolen credentials from the Salesloft Drift integration to access and systematically explore Cloudflare’s Salesforce tenant before exfiltrating the support case data on August 17.
Cloudflare was officially notified of the vulnerability by Salesforce and Salesloft on August 23, at which point it launched a full-scale security incident response.
The company’s remediation efforts included immediately disabling the compromised Drift integration, rotating credentials for all third-party services connected to Salesforce, and analyzing the stolen data to identify customer impact.
In a statement, Cloudflare took responsibility for the incident, saying, “We are responsible for the choice of tools we use in support of our business. This breach has let our customers down.
For that, we sincerely apologize.” The company is urging all customers to rotate any credentials they may have shared through the support channel as a matter of urgency. The incident underscores the growing risks associated with third-party integrations in the SaaS ecosystem.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
The post Cloudflare Confirms Data Breach, Hackers Stole Customer Data from Salesforce Instances appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Less than 10 weeks after the State Department laid off hundreds of Foreign Service Officers, citing bureaucratic bloat, it is beginning to bring nearly 100 new ones on.
Last week, the Office of Talent Acquisition began notifying new employees that their orientation class will begin Sept. 22, according to an email obtained by Government Executive. About 99 new employees will join the Foreign Service class, according to people involved in or familiar with the plans.
In July, State issued reduction-in-force notices to 1,350 employees, including about 250 FSOs.
Current and laid-off employees wonder why cuts were made if State planned to begin hiring again so soon. Foreign Service Officers are flexible; most work as generalists, switching roles and locations every few years.
“The optics are terrible," said one State employee familiar with the hiring plans.
A Foreign Service Officer affected by the layoffs said the new hiring demonstrates a lack of consistent thinking. “They indiscriminately fired hundreds only to turn around and start hiring almost immediately,” the soon-to-be-former officer said.
Another laid-off Foreign Service Officer called the approach wasteful because State has invested in training each diplomat throughout their career.
“So the idea of firing 250 FSOs only to bring in more people in their wake is totally inefficient and the definition of wasteful government spending,” the laid-off staffer said.
That person added the approach will open the door to the Trump administration intimidating new employees “who don’t know the rules of the road or when and how to push back.”
A department spokesperson said State "welcomes a new class" of FSOs, calling the process standard.
"This new class will be filling entry-level positions throughout the department that were maintained in the reorganization," the spokesperson said.
State officials said ahead of the July layoffs that the department’s reorganization was meant to “refocus” its mission on core objectives and modern needs. The department was not saying those affected by the layoffs “weren't doing a good job or weren't valuable members of the State Department family,” one official said, but the administration had an obligation to “do what's right for the mission and what's right for the American people.”
While the duties and areas in which FSOs serve shift regularly, State said it was targeting staff because of the offices in which they were serving in that moment. Some of those laid off have subsequently been awarded promotions for outstanding performance, though their RIFs remain in effect.
Under President Biden, the Foreign Service grew by 6% at State and the department last year brought on 235 people in its largest class size ever. In May, the Trump administration welcomed another cohort of 104 Foreign Service personnel.
While the Trump administration has ushered hundreds of thousands of employees out of government since January, State is just the latest example of an agency seeking to unwind some of that work. The departments of Treasury, Health and Human Services and Labor have rescinded layoffs to fill staffing needs, while the Agriculture Department, Justice Department, Social Security Administration and other agencies have moved employees around to ensure continuity of critical functions.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Securing APIs is a critical cybersecurity challenge in 2025 as they are the backbone of modern applications and a prime target for attackers. API penetration testing is no longer an optional check; it’s a necessity for finding business logic flaws, authorization bypasses, and other complex vulnerabilities that automated tools can’t detect. The best companies in […]
The post Top 10 Best API Penetration Companies In 2025 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
President Donald Trump’s move to send National Guard troops and U.S. Marines to quell immigration protests in Los Angeles this summer violated a federal law against military members conducting domestic law enforcement, a federal judge in California ruled early Tuesday.
The ruling from Senior U.S. District Judge Charles R. Breyer represents an obstacle to any further use of National Guard troops to assist local police in more cities. Following deployments to LA and Washington, D.C., Trump has openly mused about federalizing other state National Guard troops and sending them to major cities like Chicago and Baltimore he says are overwhelmed with crime.
Breyer, whom Democratic President Bill Clinton appointed in 1997, said Trump could not use the National Guard for a wide array of police activities in California. His order goes into effect Sept. 12.
Breyer said the roughly 4,700 Guard members and Marines engaged in police activity in violation of the Posse Comitatus Act of 1878, which he said built on the constitutional framers’ wariness of a centralized military force conducting police work.
“Contrary to Congress’s explicit instruction, federal troops executed the laws,” Breyer wrote in a 52-page opinion. “Defendants systematically used armed soldiers (whose identity was often obscured by protective armor) and military vehicles to set up protective perimeters and traffic blockades, engage in crowd control, and otherwise demonstrate a military presence in and around Los Angeles. In short, Defendants violated the Posse Comitatus Act.”
National Guard expanded
The judge expressed concern about Trump and Defense Secretary Pete Hegseth’s statements they wanted to expand the role of National Guard troops for law enforcement.
“President Trump and Secretary Hegseth have stated their intention to call National Guard troops into federal service in other cities across the country… thus creating a national police force with the President as its chief,” he wrote.
The issue itself dates much further back in U.S. history, forming part of the basis for the country’s break from the English monarchy, Breyer noted.
“Indeed, resentment of Britain’s use of military troops as a police force was manifested in the Declaration of Independence, where one of the American colonists’ grievances was that the King had ‘affected to render the Military independent of and superior to the Civil power,’” he wrote.
California Gov. Gavin Newsom, a Democrat who sued to block Trump’s federalization of the state’s National Guard, said the ruling “sided with democracy and the Constitution” and echoed Breyer’s warning about Trump leading a national police force.
“No president is a king — not even Trump — and no president can trample a state’s power to protect its people,” Newsom said. “Trump’s attempt to use federal troops as his personal police force is illegal, authoritarian, and must be stopped in every courtroom across this country.”
Los Angeles Mayor Karen Bass also cheered the decision.
“The White House tried to invade the second largest city in the country,” she wrote. “That’s illegal. Los Angeles will not buckle and we will not break. We will not be divided and we will not be defeated.”
Spokespeople for the White House did not immediately return a message seeking comment.
Return to appeals court likely
Trump is likely to appeal the ruling to the U.S. 9th Circuit Court of Appeals, where he won a victory early in the case.
After Breyer issued a temporary restraining order in June calling on Trump to return control of the state’s National Guard to Newsom, a 9th Circuit panel unanimously blocked it from going into effect, ruling that U.S. Supreme Court precedent allowed Trump to make the determination that the proper circumstances existed to federalize National Guard troops.
That appeals ruling dealt with Breyer’s finding that Trump likely violated the president’s legal authority to federalize National Guard troops.
The appeal did not consider potential Posse Comitatus Act violations, Breyer said Tuesday.
This report was originally published by Stateline.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
President Donald Trump’s move to send National Guard troops and U.S. Marines to quell immigration protests in Los Angeles this summer violated a federal law against military members conducting domestic law enforcement, a federal judge in California ruled early Tuesday.
The ruling from Senior U.S. District Judge Charles R. Breyer represents an obstacle to any further use of National Guard troops to assist local police in more cities. Following deployments to LA and Washington, D.C., Trump has openly mused about federalizing other state National Guard troops and sending them to major cities like Chicago and Baltimore he says are overwhelmed with crime.
Breyer, whom Democratic President Bill Clinton appointed in 1997, said Trump could not use the National Guard for a wide array of police activities in California. His order goes into effect Sept. 12.
Breyer said the roughly 4,700 Guard members and Marines engaged in police activity in violation of the Posse Comitatus Act of 1878, which he said built on the constitutional framers’ wariness of a centralized military force conducting police work.
“Contrary to Congress’s explicit instruction, federal troops executed the laws,” Breyer wrote in a 52-page opinion. “Defendants systematically used armed soldiers (whose identity was often obscured by protective armor) and military vehicles to set up protective perimeters and traffic blockades, engage in crowd control, and otherwise demonstrate a military presence in and around Los Angeles. In short, Defendants violated the Posse Comitatus Act.”
National Guard expanded
The judge expressed concern about Trump and Defense Secretary Pete Hegseth’s statements they wanted to expand the role of National Guard troops for law enforcement.
“President Trump and Secretary Hegseth have stated their intention to call National Guard troops into federal service in other cities across the country… thus creating a national police force with the President as its chief,” he wrote.
The issue itself dates much further back in U.S. history, forming part of the basis for the country’s break from the English monarchy, Breyer noted.
“Indeed, resentment of Britain’s use of military troops as a police force was manifested in the Declaration of Independence, where one of the American colonists’ grievances was that the King had ‘affected to render the Military independent of and superior to the Civil power,’” he wrote.
California Gov. Gavin Newsom, a Democrat who sued to block Trump’s federalization of the state’s National Guard, said the ruling “sided with democracy and the Constitution” and echoed Breyer’s warning about Trump leading a national police force.
“No president is a king — not even Trump — and no president can trample a state’s power to protect its people,” Newsom said. “Trump’s attempt to use federal troops as his personal police force is illegal, authoritarian, and must be stopped in every courtroom across this country.”
Los Angeles Mayor Karen Bass also cheered the decision.
“The White House tried to invade the second largest city in the country,” she wrote. “That’s illegal. Los Angeles will not buckle and we will not break. We will not be divided and we will not be defeated.”
Spokespeople for the White House did not immediately return a message seeking comment.
Return to appeals court likely
Trump is likely to appeal the ruling to the U.S. 9th Circuit Court of Appeals, where he won a victory early in the case.
After Breyer issued a temporary restraining order in June calling on Trump to return control of the state’s National Guard to Newsom, a 9th Circuit panel unanimously blocked it from going into effect, ruling that U.S. Supreme Court precedent allowed Trump to make the determination that the proper circumstances existed to federalize National Guard troops.
That appeals ruling dealt with Breyer’s finding that Trump likely violated the president’s legal authority to federalize National Guard troops.
The appeal did not consider potential Posse Comitatus Act violations, Breyer said Tuesday.
This report was originally published by Stateline.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical security vulnerability discovered in ESPHome’s web server component has exposed thousands of smart home devices to unauthorized access, effectively nullifying basic authentication protections on ESP-IDF platform implementations.
The flaw, designated CVE-2025-57808 with a CVSS score of 8.1, affects ESPHome version 2025.8.0 and allows attackers to bypass authentication mechanisms without any knowledge of legitimate credentials.
The vulnerability stems from a fundamental logic error in the HTTP basic authentication check within ESPHome’s
web_server_idfcomponent.When processing authentication requests, the system’s
AsyncWebServerRequest::authenticatefunction only compares bytes up to the length of the client-supplied authorization value, rather than validating the complete credential string.This implementation flaw creates two distinct attack vectors that completely compromise device security.
The most severe aspect of this vulnerability involves empty authorization headers, where attackers can gain full access by simply sending a request with
Authorization: Basicfollowed by an empty string.GitHub analysts identified that this attack vector requires no prior knowledge of usernames or passwords, making it particularly dangerous for network-adjacent attackers.
Additionally, the flaw accepts partial password matches, meaning an attacker who discovers even a substring of the correct password can successfully authenticate.
Attack Mechanism and Technical Exploitation
The vulnerability’s technical foundation lies in the improper string comparison logic that processes base64-encoded credentials.
When a legitimate device is configured with credentials like
user:somereallylongpass(encoded asdXNlcjpzb21lcmVhbGx5bG9uZ3Bhc3M=), the flawed authentication check accepts shorter strings such asdXNlcjpz(representinguser:s) as valid credentials.Practical exploitation requires minimal technical sophistication. Attackers can utilize simple curl commands to demonstrate the vulnerability:-
curl -D- -H 'Authorization: Basic ' http://target.local/This command bypasses authentication entirely, returning HTTP 200 responses instead of the expected 401 Unauthorized status.
The vulnerability becomes particularly concerning when Over-The-Air (OTA) update functionality is enabled, as attackers gain complete control over device firmware and configuration settings.
ESPHome addressed this critical flaw in version 2025.8.1, implementing proper credential validation that compares complete authorization strings rather than partial matches.
Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.The post ESPHome Web Server Authentication Bypass Vulnerability Exposes Smart Devices appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


