Aggregator
Without Federal Help, Cyber Defense Is Up to the Rest of Us
K2 Think AI Model Jailbroken Within Hours After The Release
Within mere hours of its public unveiling, the K2 Think model experienced a critical compromise that has sent ripples throughout the cybersecurity community. The newly launched reasoning system, developed by MBZUAI in partnership with G42, was designed to offer unprecedented transparency by exposing its internal decision-making process for compliance and audit purposes. However, this very […]
The post K2 Think AI Model Jailbroken Within Hours After The Release appeared first on Cyber Security News.
«От странной ошибки PHP до полного взлома». История нулевого дня в FreePBX
CISA official calls on lawmakers to extend cyber info-sharing law
Attackers Adopt Novel LOTL Techniques to Evade Detection
HybridPetya Exploits UEFI Vulnerability to Bypass Secure Boot on Legacy Systems
ESET Research has uncovered a sophisticated new ransomware variant called HybridPetya, discovered on the VirusTotal sample sharing platform. This malware represents a dangerous evolution of the infamous Petya/NotPetya ransomware family, incorporating advanced capabilities to compromise UEFI-based systems and exploit CVE-2024-7344 to bypass UEFI Secure Boot protections on vulnerable systems. Unlike its predecessors, HybridPetya demonstrates significant […]
The post HybridPetya Exploits UEFI Vulnerability to Bypass Secure Boot on Legacy Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-10318 | JeecgBoot up to 3.8.2 WebSocket Message sendWebSocketMsg userIds improper authorization
CVE-2025-9296 | Emlog Pro up to 2.5.18 blogger.php?action=update_avatar image unrestricted upload (EUVD-2025-25414)
CVE-2025-9300 | saitoha libsixel up to 1.10.3 img2sixel src/encoder.c sixel_debug_print_palette stack-based overflow (Issue 200 / Nessus ID 260187)
CVE-2004-1945 | Kinesphere eXchange POP3 4.0 Mail From memory corruption (EDB-24028 / XFDB-15922)
CVE-2004-2501 | MailEnable Professional Edition/Enterprise Edition IMAP Service memory corruption (EDB-658 / Nessus ID 15852)
CVE-2004-1908 | McAfee Freescan ActiveX Object mcfreescan.comcfreescan.1 getspecialfolderlocation information disclosure (EDB-23926 / XFDB-15782)
CVE-2004-0292 | Karjasoft Sami HTTP Server 1.0.4 HTTP GET Request memory corruption (EDB-23714 / Nessus ID 12073)
CVE-2004-1883 | IPSwitch WS FTP Server 4.0.2 memory corruption (EDB-165 / Nessus ID 14598)
CVE-2004-2114 | Internetnow Proxynow 2.6/2.75 Proxy stack-based overflow (EDB-23608 / XFDB-14955)
Холостые пули и сломанный транспорт. Новый античит Call of Duty в реальном времени издевается над читерами
Nitrogen
You must login to view this content
New HybridPetya Weaponizing UEFI Vulnerability to Bypass Secure Boot on Outdated Systems
In late July 2025, a series of ransomware samples surfaced on VirusTotal under filenames referencing the notorious Petya and NotPetya attacks. Unlike its predecessors, this new threat—dubbed HybridPetya by ESET analysts—exhibited capabilities that extended beyond conventional userland execution, directly targeting UEFI firmware on vulnerable systems. Through a specially crafted cloak.dat archive and the exploitation of […]
The post New HybridPetya Weaponizing UEFI Vulnerability to Bypass Secure Boot on Outdated Systems appeared first on Cyber Security News.