Aggregator
Space Bears
APT32 Turns GitHub into a Weapon Against Security Teams and Enterprise Networks
Southeast Asian Advanced Persistent Threat (APT) group OceanLotus, also known as APT32, has been identified as employing GitHub to conduct a sophisticated poison attack against Chinese cybersecurity professionals. The ThreatBook Research and Response Team has meticulously analyzed this incident, which began its nefarious spread in mid-September 2024, resulting in a targeted assault on various Chinese […]
The post APT32 Turns GitHub into a Weapon Against Security Teams and Enterprise Networks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
AI is Reshaping Cyber Threats: Here’s What CISOs Must Do Now
Assess the risks posed by AI-powered attacks and adopt AI-driven defense capabilities to match. Automate where possible. Use AI to prioritise what matters. Invest in processes and talent that enable real-time response and build long-term trust.
The post AI is Reshaping Cyber Threats: Here’s What CISOs Must Do Now appeared first on Security Boulevard.
AkiraBot Floods 80,000 Sites After Outsmarting CAPTCHAs and Slipping Past Network Defenses
AkiraBot, identified by SentinelLABS, represents a sophisticated spam bot framework that targets website chats and contact forms to promote low-quality SEO services. Since its inception in September 2024, AkiraBot has impacted over 420,000 unique domains, successfully spamming at least 80,000 websites. It leverages both CAPTCHA evasion techniques and network detection evasion to elude website security […]
The post AkiraBot Floods 80,000 Sites After Outsmarting CAPTCHAs and Slipping Past Network Defenses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-25632 | Tenda AC15 15.03.05.19 /goform/telnet handler command injection
CVE-2025-1768 | cifi SEO Plugin up to 12.4.05 on WordPress sql injection
CVE-2025-2193 | MRCMS 3.1.2 org.marker.mushroom.controller.FileController /admin/file/delete.do delete path/name path traversal
CVE-2025-2194 | MRCMS 3.1.2 org.marker.mushroom.controller.FileController /admin/file/list.do list path cross site scripting
CVE-2025-3102 | SureTriggers Plugin up to 1.0.78 on WordPress autheticate_user secret_key authorization
CVE-2024-13909 | Accredible Certificates & Open Badges Plugin up to 1.4.9 on WordPress orderby sql injection
CVE-2024-10894 | Payment Forms for Paystack Plugin up to 4.0.2 on WordPress Shortcode cross site scripting
CVE-2025-3489 | Nababur Simple-User-Management-System 1.0 /register.php name/username cross site scripting
CVE-2023-40159 | Philips Vue PACS prior 12.2.8.410 information disclosure (icsma-24-200-01)
CVE-2023-40223 | Philips Vue PACS prior 12.2.8.410 Actor privileges management (icsma-24-200-01)
CVE-2023-40539 | Philips Vue PACS prior 12.2.8.410 weak password (icsma-24-200-01)
CVE-2023-40704 | Philips Vue PACS prior 12.2.8.410 default credentials (icsma-24-200-01)
Set_password, и вуаля: FortiSwitch сам отдаёт ключи
Microsoft Identity Web Flaw Exposes Sensitive Client Secrets and Certificates
A new vulnerability has been discovered in the Microsoft.Identity.Web NuGet package under specific conditions, potentially exposing sensitive information such as client secrets and certificate details in service logs. The flaw, identified as CVE-2025-32016, has been rated as moderate, prompting developers to urgently address the issue to prevent unintended data exposure. Overview of the Vulnerability: The vulnerability […]
The post Microsoft Identity Web Flaw Exposes Sensitive Client Secrets and Certificates appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CatB Ransomware Abuses Microsoft Distributed Transaction Coordinator for Stealthy Payload Execution
The cybersecurity realm has encountered a formidable adversary with the emergence of CatB ransomware, also known as CatB99 or Baxtoy. First identified in late 2022, this strain has caught the eye of security analysts due to its sophisticated evasion techniques and its potential connection to established ransomware families. There’s speculation within the security community that […]
The post CatB Ransomware Abuses Microsoft Distributed Transaction Coordinator for Stealthy Payload Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.