Aggregator
特朗普政府封禁了 Julianne Moore 的儿童书《Freckleface Strawberry》
Госструктуры в осаде: майнеры шифруют трафик и скрываются в системных процессах
CVE-2024-11759 | Bukza Plugin up to 2.0.0 on WordPress Shortcode bukza cross site scripting
Stealthy Malware in WordPress Sites Enables Remote Code Execution by Hackers
Security researchers have uncovered sophisticated malware targeting WordPress websites, leveraging hidden backdoors to enable remote code execution (RCE). These attacks exploit vulnerabilities in WordPress core features and plugins, allowing hackers to gain unauthorized access, execute arbitrary code, and maintain control over compromised sites. The findings highlight the critical need for robust security measures in WordPress […]
The post Stealthy Malware in WordPress Sites Enables Remote Code Execution by Hackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
8 - CVE-2024-7014
Xerox Printer Vulnerability Exposes Authentication Data Via LDAP and SMB
A critical security vulnerability in Xerox’s Versalink C7025 Multifunction Printer (MFP) has been uncovered, exposing enterprise networks to credential theft and lateral attacks. The flaw, discovered by Rapid7 Principal IoT Researcher Deral Heiland, enables malicious actors to intercept Lightweight Directory Access Protocol (LDAP) and Server Message Block (SMB) authentication data through pass-back attacks. The vulnerabilities, […]
The post Xerox Printer Vulnerability Exposes Authentication Data Via LDAP and SMB appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
New XCSSET Malware Targets macOS Users Through Infected Xcode Projects
Microsoft Threat Intelligence has identified a new variant of the XCSSET macOS malware, marking its first update since 2022. This sophisticated malware continues to target macOS users by infecting Xcode projects, a critical tool for Apple developers. The latest variant introduces advanced obfuscation techniques, updated persistence mechanisms, and novel infection strategies, making it more challenging […]
The post New XCSSET Malware Targets macOS Users Through Infected Xcode Projects appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
RansomHub Evolves To Attack Windows, ESXi, Linux and FreeBSD Operating Systems
The RansomHub ransomware group has rapidly emerged as one of the most prolific cybercrime syndicates of 2024–2025. As this ransomware group done by expanding its arsenal to target Windows, VMware ESXi, Linux, and FreeBSD systems in global attacks. RansomHub ransomware group leverages advanced evasion techniques, cross-platform encryption, and vulnerabilities in enterprise infrastructure. Group-IB analysts have […]
The post RansomHub Evolves To Attack Windows, ESXi, Linux and FreeBSD Operating Systems appeared first on Cyber Security News.
Beware! Fake Outlook Support Calls Leading to Ransomware Attacks
Telekom Security has recently uncovered a significant vishing (voice phishing) campaign targeting individuals and organizations across Germany. This operation appears to be linked to a ransomware group employing sophisticated social engineering tactics. The attackers impersonate Microsoft Outlook support personnel, aiming to trick victims into granting access to their systems, which can lead to devastating ransomware […]
The post Beware! Fake Outlook Support Calls Leading to Ransomware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
X 屏蔽 Signal.me 链接
CVE-2025-0714 | Mobatek MobaXterm up to 24.x AES weak iv
CVE-2025-26758 | RebelCode Spotlight Social Media Feeds Plugin up to 1.7.1 on WordPress exposure of sensitive system information to an unauthorized control sphere
CVE-2025-23840 | webjema Notcaptcha Plugin up to 1.3.1 on WordPress cross site scripting
【资料】美国国际开发署(USAID)人员名单(2)(含简历)
Приложение DeepSeek прекратило работу в Южной Корее
CISA Warns of Apple iOS Vulnerability Exploited in Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical zero-day vulnerability in Apple iOS and iPadOS, tracked as CVE-2025-24200, being actively exploited in targeted attacks. The flaw, an authorization bypass in Apple’s USB Restricted Mode, enables attackers with physical access to disable security protections on locked devices, potentially […]
The post CISA Warns of Apple iOS Vulnerability Exploited in Wild appeared first on Cyber Security News.
CVE-2025-23845 | ERA404 ImageMeta Plugin up to 1.1.2 on WordPress cross site scripting
CISA Warns of Active Exploitation of Apple iOS & iPadOS Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory warning of active exploitation of a critical security flaw in Apple’s iOS and iPad operating systems. Tracked as CVE-2025-24200, the vulnerability permits attackers with physical access to bypass critical security protections on locked devices, escalating risks of unauthorized data access and potential device compromise. […]
The post CISA Warns of Active Exploitation of Apple iOS & iPadOS Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Threat Actors Exploiting Modified SharpHide Tool to Conceal Registry Entries
Threat actors are leveraging a modified version of the SharpHide tool to create hidden registry entries, significantly complicating detection and removal efforts. This technique exploits vulnerabilities in Windows registry handling, using null-terminated strings to obscure malicious entries. The modified SharpHide has been integrated into sophisticated attack chains, enabling malware persistence while evading standard detection mechanisms. […]
The post Threat Actors Exploiting Modified SharpHide Tool to Conceal Registry Entries appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.