Aggregator
CVE-2025-6425 | Mozilla Firefox up to 139 WebCompat Extension information disclosure (Nessus ID 240338)
CVE-2025-39205 | Hitachi Energy MicroSCADA X SYS600 up to 10.6 TLS Protocol certificate validation (EUVD-2025-19012)
WhatsApp клянётся: мы надёжные. Конгресс пожимает плечами: «Не смешите»
Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via Keyloggers
Critical Convoy Vulnerability Let Attackers Execute Remote Code on Affected Servers
A critical security vulnerability has been discovered in Performave Convoy that allows unauthenticated remote attackers to execute arbitrary code on affected servers. The vulnerability, identified as CVE-2025-52562, affects all versions from 3.9.0-rc.3 through 4.4.0 of the ConvoyPanel/panel package. Security researcher AnushK-Fro reported the vulnerability five days ago, receiving a critical severity rating with a perfect […]
The post Critical Convoy Vulnerability Let Attackers Execute Remote Code on Affected Servers appeared first on Cyber Security News.
EagleSpy v5 RAT Promoted by Hacker for Stealthy Android Access
A notorious threat actor known as “xperttechy” is actively promoting a new version of the EagleSpy remote access Trojan (RAT), dubbed EagleSpy v5, on a prominent dark web forum. Marketed as a “lifetime activated” tool, EagleSpy v5 is raising alarms within the cybersecurity community due to its extensive feature set and its ability to operate […]
The post EagleSpy v5 RAT Promoted by Hacker for Stealthy Android Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Магазины — открыты. Продаж — нет. Убытки — сотни миллионов. И это только разминка
Militaire versie Scout-onderwaterdrone in zicht
Russia releases REvil members after convictions for payment card fraud
Application and API Security Can’t Rely Solely on Perimeter Defenses or Scanners | Notes on Gartner AppSec Research | Contrast Security
Contrast Security launched Application Detection and Response (ADR) in August of 2024, and now, in a new Gartner research note, ADR is a topic. The 2025 Gartner® Implement Effective Application and API Security Controls (accessible to Gartner clients only)*, by William Dupre, discusses today’s complex problem:
The post Application and API Security Can’t Rely Solely on Perimeter Defenses or Scanners | Notes on Gartner AppSec Research | Contrast Security appeared first on Security Boulevard.
Cryptominers’ Anatomy: Shutting Down Mining Botnets
奇安信荣膺NVDB-CAVD2025汽车信息安全春季赛第一名
Zimbra Classic Web Client Vulnerability Allows Arbitrary JavaScript Execution
A critical security flaw has been discovered and patched in the Zimbra Collaboration Suite (ZCS) Classic Web Client, exposing millions of business users to the risk of arbitrary JavaScript execution through stored cross-site scripting (XSS). Tracked as CVE-2025-27915, this vulnerability affects ZCS versions 9.0, 10.0, and 10.1 prior to the latest patch releases, and is […]
The post Zimbra Classic Web Client Vulnerability Allows Arbitrary JavaScript Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
How to Spot Registry Abuse by Malware: Examples in ANY.RUN Sandbox
When malware infiltrates a system, it doesn’t always make noise. In fact, some of the most dangerous threats operate quietly embedding themselves deep within the system and ensuring they come back even after a reboot. One of the most common ways they achieve this is by abusing the Windows Registry. In this article, we’ll walk […]
The post How to Spot Registry Abuse by Malware: Examples in ANY.RUN Sandbox appeared first on ANY.RUN's Cybersecurity Blog.
Russia-linked APT28 use Signal chats to target Ukraine official with malware
Half of Security Pros Want GenAI Deployment Pause
HPE security advisory (AV25-366)
Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns
The Department of Homeland Security has issued a critical advisory warning of escalating cyber threats from pro-Iranian hacktivist groups targeting United States networks, as tensions between Iran and the US reach a dangerous new peak following recent military exchanges. The warning comes in the aftermath of Iran’s Islamic Revolutionary Guard Corps firing missiles at US […]
The post Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns appeared first on Cyber Security News.