Aggregator
CVE-2024-56602 | Linux Kernel up to 6.12.4 ieee802154_create use after free (Nessus ID 214901)
CVE-2024-56568 | Linux Kernel up to 5.10.230/5.15.173/6.1.119/6.6.65/6.12.3 of_dma_configure null pointer dereference (Nessus ID 214901)
CVE-2024-56372 | Linux Kernel up to 6.6.67/6.12.6 net/core/skbuff.c tun_napi_alloc_frags denial of service (Nessus ID 214901)
CVE-2024-56588 | Linux Kernel up to 6.12.4 hisi_sas null pointer dereference (Nessus ID 214901)
CVE-2024-55881 | Linux Kernel up to 5.15.175/6.1.121/6.6.67/6.12.6 Hypercall Page arch/x86/kvm/x86.h complete_hypercall_exit state issue (Nessus ID 214901)
CVE-2024-55639 | Linux Kernel up to 6.6.66/6.12.5 rswitch of_node_put use after free (Nessus ID 214901)
CVE-2024-53685 | Linux Kernel up to 6.6.69/6.12.6 ceph_mdsc_build_path infinite loop (Nessus ID 214901)
CVE-2024-53236 | Linux Kernel up to 6.11.10/6.12.1 xsk_build_skb iteration (Nessus ID 214901)
Beware of SmartApeSG Campaigns that Deliver NetSupport RAT
SmartApeSG, a FakeUpdate cyber threat, has emerged as a significant vector for delivering NetSupport RAT, a maliciously exploited remote administration tool. The campaign ensnares victims by tricking them into downloading fake browser updates, ultimately enabling attackers to gain unauthorized access to infected systems. A Web of Connections Recent investigations examined SmartApeSG’s command-and-control (C2) infrastructure, revealing […]
The post Beware of SmartApeSG Campaigns that Deliver NetSupport RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
New FUD Malware Targets MacOS, Evading Antivirus and Security Tools
A new strain of Fully Undetectable (FUD) macOS malware, dubbed “Tiny FUD,” has emerged, showcasing sophisticated evasion techniques capable of bypassing antivirus and macOS security frameworks, including Gatekeeper and System Integrity Protection (SIP). The malware employs advanced methods, such as process name manipulation, DYLD injection, and command-and-control (C2) communication, making it a significant threat to […]
The post New FUD Malware Targets MacOS, Evading Antivirus and Security Tools appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2015-1576 | Yuba U5cms up to 3.9.2 admin/ copy2.php newname sql injection (ID 130326 / EDB-36027)
CVE-2019-6218 | Apple tvOS up to 12.1.1 libxpc memory corruption (HT209447 / EDB-46297)
Cybercriminals Exploiting HTTP Client Tools to Hijack Microsoft 365 Accounts
A recent report by Proofpoint has revealed an alarming trend of cybercriminals exploiting HTTP client tools to target Microsoft 365 accounts. These tools, originally designed for legitimate use, are now being repurposed for large-scale account takeover (ATO) attacks, employing tactics such as brute force login attempts and Adversary-in-the-Middle (AiTM) techniques. With a growing reliance on […]
The post Cybercriminals Exploiting HTTP Client Tools to Hijack Microsoft 365 Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
G.O.S.S.I.P 2025 新春总动员(2):反编译研究的又一年
How to Root Out Malicious Employees
Malicious employees and insider threats pose one of the biggest security risks to organizations, as these users have more access and permissions than cybercriminals attacking the organization externally.
The post How to Root Out Malicious Employees appeared first on Security Boulevard.
Beware of Fake DeepSeek PyPI Packages That Delivers Malware
Researchers from the Positive Technologies Expert Security Center (PT ESC) have identified and prevented a malicious campaign targeting users of the Python Package Index (PyPI). The attack involved two fake packages named deepseeek and deepseekai, which were designed to steal sensitive user and system data. These packages were masquerading as legitimate clients for the DeepSeek […]
The post Beware of Fake DeepSeek PyPI Packages That Delivers Malware appeared first on Cyber Security News.
Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections
Nymi Band 4 delivers passwordless MFA to deskless workers in OT environments
Nymi launched next-generation wearable authenticator, the Nymi Band 4, which introduces design upgrades and expanded passwordless use cases for regulated industries, while retaining its core authentication functionality. This latest development from Nymi offers industries with complex operations a handsfree solution for passwordless, Multi-Factor Authentication (MFA) that delivers strong security, compliance, and convenience for deskless workers, including manufacturing line operators, laboratory scientists, field technicians, and other critical workers in process-intensive environments. The Nymi Band 4 is … More →
The post Nymi Band 4 delivers passwordless MFA to deskless workers in OT environments appeared first on Help Net Security.