Aggregator
OnDemand | Cyberchondria: Surviving the Panic of AI-Powered Phishing
Interlock Begins Leaking Kettering Health's Stolen Data
Cybercrime group Interlock has begun publishing some of the 941-gbytes of data the gang claims to have stolen in a disruptive May attack on Kettering Health. The Ohio-based healthcare organization is making IT system restoration progress and cyber enhancements, but is still recovering.
Mind Gets $30M to Boost AI for Endpoint Data Loss Prevention
Backed by Paladin and Crosspoint, Seattle-based data security startup Mind aims to double its team and develop small language models that power endpoint classification. The company is carving a niche in data loss prevention by prioritizing unstructured data and actionable enforcement.
Iranian Espionage Group Caught Spying on Kurdish Officials
An Iranian state espionage group stayed hidden for more than half-a-decade until security researchers spotted it in 2023, researchers said Thursday in a report detailing a growing arsenal of hacking tools it deployed against Kurdish and Iraqi government officials.
Salesforce, Okta Targeted by Telephone-Wielding Hackers
A hacking collective linked to recent British retailer attacks is targeting cloud companies through or voice phishing scams for data theft from European hospitality, retail and education sectors. Hackers impersonate IT support staff.
看雪@你,多场直播快来充电
欢迎投递简历~
多款 Chrome 扩展 “翻车”,存在密钥暴露问题
Redis漏洞分析,ACL篇
Critical FreeRTOS-Plus-TCP Flaw Allows Code Execution or System Crash
A critical memory corruption vulnerability, tracked as CVE-2025-5688, has been disclosed in FreeRTOS-Plus-TCP, Amazon’s open-source TCP/IP stack widely used in embedded and IoT devices. The flaw, rated 8.4 (High) on the CVSS scale, is rooted in how the stack processes Link-Local Multicast Name Resolution (LLMNR) and Multicast DNS (mDNS) queries containing excessively long DNS names, […]
The post Critical FreeRTOS-Plus-TCP Flaw Allows Code Execution or System Crash appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-5726 | SourceCodester Student Result Management System 1.0 Division System Page division-system cross site scripting
CVE-2025-4964 | WP Online Users Stats Plugin up to 1.0.0 on WordPress table_name sql injection (EUVD-2025-17074)
CVE-2025-2935 | Anti-Spam Plugin up to 2024.7 on WordPress ss_option_maint.php ss_option_maint cross-site request forgery (EUVD-2025-17072)
CVE-2025-5019 | Hive Support Plugin up to 1.2.2/1.2.4 on WordPress Setting hs_update_ai_chat_settings cross-site request forgery (EUVD-2025-17081)
CVE-2025-4966 | WP Online Users Stats Plugin up to 1.0.0 on WordPress hk_dataset_results cross-site request forgery
CVE-2025-1777 | BM Content Builder Plugin up to 3.16.2.1 on WordPress ux_cb_page_options_save cross site scripting (EUVD-2025-17053)
CVE-2025-1778 | Art Theme Plugin up to 3.12.2.3 on WordPress arttheme_theme_option_restore authorization (EUVD-2025-17054)
145 criminal domains linked to BidenCash Marketplace seized
Approximately 145 darknet and conventional internet domains, along with cryptocurrency funds linked to the BidenCash marketplace, have been seized by the U.S. Attorney’s Office for the Eastern District of Virginia. The operators of the BidenCash marketplace use the platform to simplify the process of buying and selling stolen credit cards and associated personal information. BidenCash seized after $17 million in illicit sales BidenCash commenced operations in March 2022. BidenCash administrators charged a fee for every … More →
The post 145 criminal domains linked to BidenCash Marketplace seized appeared first on Help Net Security.