Two critical vulnerabilities (CVE-2025-25291 and CVE-2025-25292) in the ruby-saml library could allow attackers to impersonate users and execute account takeover attacks. These flaws arise from differences in parsing XML with REXML and Nokogiri. Organizations must update to ruby-saml version 1.18.0 to mitigate these risks effectively.

Infosys agrees to pay $17.5 million to settle lawsuits over McCamish cyber incident – Moneycontrol
Infosys has agreed to pay $17.5 million to settle lawsuits related to a cyber incident at McCamish Systems. The incident compromised personal information, leading to