Aggregator
CVE-2025-58809 | Nick Ciske To Lead for Salesforce Plugin up to 2.7.3.9 on WordPress cross-site request forgery
CVE-2025-58807 | Dsingh Purge Varnish Cache Plugin up to 2.6 on WordPress cross-site request forgery
Hackers Weaponize Fake Microsoft Teams Site to Deploy Odyssey macOS Stealer
A sophisticated cyber campaign is targeting macOS users by distributing the potent “Odyssey” information stealer through a deceptive website impersonating the official Microsoft Teams download page. The attack, identified by researchers at CloudSEK’s TRIAD, leverages a social engineering technique known as a “Clickfix” attack to trick victims into executing malicious code that systematically harvests sensitive […]
The post Hackers Weaponize Fake Microsoft Teams Site to Deploy Odyssey macOS Stealer appeared first on Cyber Security News.
Chess.com Hit by Limited Data Breach Linked to 3rd-Party File Transfer Tool
The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows
On September 5, 2025, GitGuardian discovered GhostAction, a massive supply chain attack affecting 327 GitHub users across 817 repositories. Attackers injected malicious workflows that exfiltrated 3,325 secrets, including PyPI, npm, and DockerHub tokens via HTTP POST requests to a remote endpoint.
The post The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows appeared first on Security Boulevard.