Aggregator
利用微软工具击败windows自带的防御系统
利用微软工具击败windows自带的防御系统
openRxiv: крупнейшие научные архивы получили свободу и миллионы Цукерберга
CISA Warns of Microsoft Windows Management Console (MMC) Vulnerability Exploited in Wild
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding an actively exploited vulnerability in Microsoft Windows Management Console (MMC), tracked as CVE-2025-26633. This improper neutralization flaw (CWE-707) enables remote attackers to execute arbitrary code over a network, posing significant risks to unpatched systems. While its association with ransomware campaigns remains unconfirmed, […]
The post CISA Warns of Microsoft Windows Management Console (MMC) Vulnerability Exploited in Wild appeared first on Cyber Security News.
Meta 开始测试其自研 AI 训练芯片
USB-шпион и 7 Zero Day: как прошел мартовский Patch Tuesday у Microsoft
CVE-2024-13430 | softaculous Page Builder Plugin up to 1.9.8 on WordPress Pagelayer pagelayer_builder_posts_shortcode access control
Cactus
空气污染与生物衰老正相关,而绿地负相关
CVE-2024-6927 | Viral Signup Plugin up to 2.1 on WordPress Setting cross site scripting
CVE-2024-7132 | Page Builder Gutenberg Blocks Plugin up to 3.1.12 on WordPress Block cross site scripting
CVE-2024-5417 | Gutentor Plugin up to 3.3.5 on WordPress Block Option cross site scripting
CVE-2024-8043 | Vikinghammer Tweet Plugin up to 0.2.4 on WordPress cross-site request forgery
CVE-2024-43965 | Smackcoders SendGrid for WordPress Plugin up to 1.4 on WordPress sql injection
CVE-2024-43986 | MagePeople Team Taxi Booking Manager for WooCommerce Plugin up to 1.0.9 on WordPress cross site scripting
CVE-2024-44919 | SeaCMS 12.9 admin_ads.php description cross site scripting
Chinese Hackers New Malware Dubbed ‘Squidoor’ Attacking Global Organizations
A sophisticated backdoor malware called “Squidoor” being deployed by suspected Chinese threat actors against organizations across South America and Southeast Asia. The malware, designed for exceptional stealth, offers attackers multiple methods to maintain persistent access to compromised networks while evading detection from advanced security systems. Initial access is gained primarily through exploiting vulnerabilities in Internet […]
The post Chinese Hackers New Malware Dubbed ‘Squidoor’ Attacking Global Organizations appeared first on Cyber Security News.
Морские перевозки и ядерные объекты: SideWinder меняет правила кибершпионажа
Apple WebKit Zero-Day Vulnerability Actively Exploit in High Profile Cyber Attacks
Apple has released emergency security updates addressing a critical zero-day vulnerability in its WebKit browser engine, identified as CVE-2025-24201, which has been actively exploited in targeted attacks. The flaw, described as an out-of-bounds write issue, could enable attackers to craft malicious web content capable of breaking out of the Web Content sandbox, potentially leading to […]
The post Apple WebKit Zero-Day Vulnerability Actively Exploit in High Profile Cyber Attacks appeared first on Cyber Security News.