Hacker Claims Oracle Cloud Data Theft, Company Refutes Breach

Hacker Claims Oracle Cloud Data Theft, Company Refutes Breach

https://www.bleepingcomputer.com/news/security/oracle-denies-data-breach-after-hacker-claims-theft-of-6-million-data-records Threat Actor Offers Stolen Data on Hacking Forum, Seeks Ransom or Zero-Day Exploits Oracle has firmly denied allegations of a data breach after...

Critical Flaw in Next.js Allows Authorization Bypass

https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware A critical vulnerability, CVE-2025-29927, has been discovered in the Next.js web development framework, enabling attackers to bypass authorization checks. This flaw allows malicious...

MyGov Passkey Adoption Surges in Australia

https://www.itnews.com.au/news/over-200000-mygov-users-disable-passwords-in-passkey-shift-615664 Over half a million myGov users have adopted passkeys as their login method since the feature launched in June 2024, with over 200,000 users exclusively relying on...
Fake “Security Alert” Phishing on GitHub Hijacks Accounts

Fake “Security Alert” Phishing on GitHub Hijacks Accounts

https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts A widespread phishing campaign is targeting GitHub users with fake “Security Alert” issues, attempting to trick them into authorizing a...

Widely Used GitHub Action Compromised, Leaking Secrets

https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066 The widely used GitHub Action “tj-actions/changed-files” was compromised before March 14, 2025, injecting malicious code that leaked secrets from affected...