Aggregator
巴基斯坦2024年恐怖主义态势与安全架构脆弱性深度分析
俄罗斯对外人力情报渗透机制与2025年最新趋势分析
SideWinder APT Deploys New Tools in Attacks on Military & Government Entities
The SideWinder Advanced Persistent Threat (APT) group has been observed intensifying its activities, particularly targeting military and government entities across various regions. This group, known for its aggressive expansion beyond traditional targets, has recently updated its toolset to include sophisticated malware designed for espionage. SideWinder’s primary targets have historically included entities in Pakistan, Sri Lanka, […]
The post SideWinder APT Deploys New Tools in Attacks on Military & Government Entities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
瑞士NCSC要求关键基础设施遭受网络攻击后24小时内报告
Без обнаружения не будет реагирования: как развиваются продукты для анализа трафика
Apache Pinot Vulnerability Allows Attackers to Bypass Authentication
A significant security vulnerability affecting Apache Pinot, an open-source distributed data store designed for real-time analytics, has been publicly disclosed. The flaw, identified as CVE-2024-56325, allows remote attackers to bypass authentication on vulnerable installations, posing a critical threat to affected systems. Vulnerability Details The vulnerability stems from improper neutralization of special elements in URIs handled by […]
The post Apache Pinot Vulnerability Allows Attackers to Bypass Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Lazarus Hackers Exploit 6 NPM Packages to Steal Login Credentials
North Korea’s Lazarus Group has launched a new wave of attacks targeting the npm ecosystem, compromising six packages designed to steal login credentials and deploy backdoors. The malicious packages is-buffer-validator, yoojae-validator, event-handle-package, array-empty-validator, react-event-dependency, and auth-validator have collectively been downloaded over 330 times. These packages mimic the names of widely trusted libraries, employing a typosquatting […]
The post Lazarus Hackers Exploit 6 NPM Packages to Steal Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
【安全圈】Apache Tomcat 中的 CVE-2025-24813 漏洞导致服务器遭受 RCE 和数据泄露:立即更新
【安全圈】幽灵插件困扰超过一百万终端,劫持搜索结果和用户数据
【安全圈】马斯克将 X 宕机归咎于大规模网络攻击,IP源自乌克兰
Record Number of Girls Compete in CyberFirst Contest
CISA Added 3 Ivanti Endpoint Manager Bugs to Wildly Exploited Vulnerabilities Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog with the addition of three high-risk security flaws affecting Ivanti Endpoint Manager (EPM). These vulnerabilities, which involve absolute path traversal issues, have been observed being actively exploited in the wild, prompting federal agencies and organizations to implement remediation measures before […]
The post CISA Added 3 Ivanti Endpoint Manager Bugs to Wildly Exploited Vulnerabilities Catalog appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers Compromise Windows Systems Using 5000+ Malicious Packages
A recent analysis by FortiGuard Labs has revealed a significant increase in malicious software packages, with over 5,000 identified since November 2024. These packages employ sophisticated techniques to evade detection and exploit system vulnerabilities, posing a substantial threat to Windows systems and other software environments. The tactics used by attackers include low-file-count packages, suspicious install […]
The post Hackers Compromise Windows Systems Using 5000+ Malicious Packages appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
360携手清微智能DeepSeek一体机 拟推动“国产算力+大模型安全+AI应用”协同发展
Telecom Giant NTT Confirms Data Breach Affecting 18,000 Corporate Customers
Japanese telecom giant NTT Communications (NTT Com) has confirmed a data breach that compromised the information of nearly 18,000 corporate customers. The breach, which occurred in February, involved unauthorized access to an internal system used for managing service orders. Details of the Breach The breached data includes customer names, contract numbers, phone numbers, email addresses, […]
The post Telecom Giant NTT Confirms Data Breach Affecting 18,000 Corporate Customers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Apache Camel RCE Vulnerability PoC Exploit Released in GitHub
A Proof of Concept (PoC) exploit for the Apache Camel vulnerability CVE-2025-27636 has been released on GitHub. This vulnerability affects Apache Camel versions 4.10.0-4.10.1, 4.8.0-4.8.4, and 3.10.0-3.22.3, allowing attackers to inject arbitrary headers and potentially execute internal Camel methods, including Remote Code Execution (RCE) via the Camel Exec component. Vulnerability Details The vulnerability arises from […]
The post Apache Camel RCE Vulnerability PoC Exploit Released in GitHub appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.