Aggregator
CVE-2021-23210 | SoX File voc.c read_samples divide by zero
CVE-2021-23159 | SoX File formats_i.c lsx_read_w_buf buffer overflow
CVE-2021-23172 | SoX hcomn File hcom.c startread heap-based overflow
CVE-2023-0917 | SourceCodester Simple Customer Relationship Management System 1.0 /php-scrm/login.php Password sql injection
Slavery, torture, human trafficking discovered at 53 Cambodian online scamming compounds
Pig butchering scams were the most common activity carried out at the facilities identified in the Amnesty International investigation.
The post Slavery, torture, human trafficking discovered at 53 Cambodian online scamming compounds appeared first on CyberScoop.
Taking over millions of developers exploiting an Open VSX Registry flaw
Microsoft security updates address CrowdStrike crash, kill ‘Blue Screen of Death’
Third-party antivirus software will no longer have access to the Windows kernel as Microsoft rolls out changes to reduce IT downtime from unexpected crashes or disruptions.
The post Microsoft security updates address CrowdStrike crash, kill ‘Blue Screen of Death’ appeared first on CyberScoop.
Threat Actors Leverage Windows Task Scheduler to Embed Malware and Maintain Persistence
A comprehensive follow-up analysis to the FortiGuard Incident Response Team’s (FGIR) investigation titled “Intrusion into Middle East Critical National Infrastructure” has revealed a protracted cyberattack that targeted critical national infrastructure (CNI) in the Middle East. This is a startling revelation. The report, part of the 2025 Global Threat Landscape Report, exposes how threat actors exploited […]
The post Threat Actors Leverage Windows Task Scheduler to Embed Malware and Maintain Persistence appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Scattered Spider strikes again? Aviation industry appears to be next target for criminal group
Hawaiian Airlines announced a cybersecurity incident Friday as security experts warned of a sector-wide threat.
The post Scattered Spider strikes again? Aviation industry appears to be next target for criminal group appeared first on CyberScoop.
MongoDB security advisory (AV25-380)
Exploitation of Microsoft 365 Direct Send to Deliver Phishing Emails as Internal Users
A sophisticated phishing campaign targeting over 70 organizations, predominantly in the US, has been uncovered by Varonis’ Managed Data Detection and Response (MDDR) Forensics team. This campaign, active since May 2025, exploits a lesser-known feature of Microsoft 365 called Direct Send, which allows devices and applications within a tenant to send emails without authentication. Designed […]
The post Exploitation of Microsoft 365 Direct Send to Deliver Phishing Emails as Internal Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.