Aggregator
Attackers Leverage Weaponized CAPTCHAs to Execute PowerShell and Deploy Malware
In a recent surge of sophisticated cyberattacks, threat actors have been utilizing fake CAPTCHA challenges to trick users into executing malicious PowerShell commands, leading to malware infections. This tactic, highlighted in the HP Wolf Security Threat Insights Report for March 2025, involves directing potential victims to malicious websites where they are prompted to complete verification […]
The post Attackers Leverage Weaponized CAPTCHAs to Execute PowerShell and Deploy Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Researchers Uncover FIN7’s Stealthy Python-Based Anubis Backdoor
Researchers have recently discovered a sophisticated Python-based backdoor, known as the Anubis Backdoor, deployed by the notorious cybercrime group FIN7. This advanced threat actor, active since at least 2015, has been responsible for billions of dollars in damages globally, primarily targeting the financial and hospitality sectors. The Anubis Backdoor represents a significant evolution in FIN7’s […]
The post Researchers Uncover FIN7’s Stealthy Python-Based Anubis Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Researchers Reveal macOS Vulnerability Exposing System Passwords
A recent article by Noah Gregory has highlighted a significant vulnerability in macOS, identified as CVE-2024-54471, which was patched in the latest security updates for macOS Sequoia 15.1, macOS Sonoma 14.7.1, and macOS Ventura 13.7.1. This vulnerability could potentially expose system passwords, emphasizing the importance of updating macOS devices to the latest versions. Background and […]
The post Researchers Reveal macOS Vulnerability Exposing System Passwords appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Ex-Michigan, Ravens Football Coach Charged with Hacking Athlete Accounts
Matthew Weiss, former football coach for the University of Michigan and the Baltimore Ravens, for almost 10 years accessed the social media and other online accounts of thousands of student athletes and downloaded personal information and intimate images, said prosecutors who indicted for illegal computer access and identity theft.
The post Ex-Michigan, Ravens Football Coach Charged with Hacking Athlete Accounts appeared first on Security Boulevard.
JumpServer Flaws Allow Attackers to Bypass Authentication and Gain Full Control
JumpServer, a widely used open-source Privileged Access Management (PAM) tool developed by Fit2Cloud, has been found to have critical security vulnerabilities. These flaws, recently highlighted by SonarSource’s vulnerability research team, allow attackers to bypass authentication and potentially gain full control over the JumpServer infrastructure. JumpServer acts as a centralized gateway to internal networks, offering features […]
The post JumpServer Flaws Allow Attackers to Bypass Authentication and Gain Full Control appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2001-0038 | Metaproducts Offline Explorer 1.3 Drive Letter privileges management (EDB-20488 / XFDB-5728)
CVE-2017-20093 | Download Manager Plugin 2.8.99 on WordPress cross-site request forgery
CVE-2022-0828 | Download Manager Plugin up to 3.2.38 on WordPress Master Key uniqid inadequate encryption
CVE-2022-1985 | Download Manager Plugin up to 3.2.42 on WordPress shortcode-iframe.php frameid cross site scripting
CVE-2022-2101 | Download Manager Plugin up to 3.2.46 on WordPress file[files][] cross site scripting (ID 167573)
CVE-2022-2362 | Download Manager Plugin up to 3.2.44 on WordPress Restrictions cross site scripting
CVE-2022-34347 | W3 Eden Download Manager Plugin up to 3.2.48 on WordPress cross-site request forgery
CVE-2022-34658 | W3 Eden Download Manager Plugin up to 3.2.48 on WordPress cross site scripting
CVE-2022-36288 | W3 Eden Download Manager Plugin up to 3.2.48 on WordPress cross-site request forgery
CVE-2022-2431 | Download Manager Plugin up to 3.2.50 on WordPress Packages.php deleteFiles file inclusion (Patch 167920)
CVE-2022-2436 | Download Manager Plugin up to 3.2.49 on WordPress file[package_dir] deserialization
CVE-2022-4476 | Download Manager Plugin up to 3.2.61 on WordPress cross site scripting
俄罗斯零日漏洞经纪公司Operation Zero悬赏400万美元收购Telegram漏洞
Hackers Use Fake Meta Emails to Steal Ad Account Credentials
A recent phishing campaign uncovered by the Cofense Phishing Defense Center (PDC) has been exploiting fake Meta emails to deceive users into surrendering their Meta Business account credentials. The attackers initiate the phishing attempt by sending fraudulent emails disguised as official Instagram notifications, alerting users that their advertising accounts have been temporarily suspended due to […]
The post Hackers Use Fake Meta Emails to Steal Ad Account Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.