Aggregator
Blind Eagle APT-C-36:快速利用补丁漏洞,借知名平台发动网络攻击
Terminology: it's not black and white
Telling users to ‘avoid clicking bad links’ still isn’t working
Tackling the 'human factor' to transform cyber security behaviours
Beware of North Korean Hackers DocSwap Malware Disguised As Security Document Viewer
A sophisticated malware campaign targeting mobile users in South Korea has been uncovered, with clear links to North Korean threat actors. The malicious application, masquerading as a “Document Viewing Authentication App” (문서열람 인증 앱). This malicious app was identified through VirusTotal on January 21, 2025, and has been actively stealing sensitive information from compromised devices. […]
The post Beware of North Korean Hackers DocSwap Malware Disguised As Security Document Viewer appeared first on Cyber Security News.
Mozilla Issues Urgent Firefox Update Warning to Prevent Add-on Failures
Mozilla has issued an urgent warning to all Firefox users, emphasizing the need to update their browsers before a critical root certificate expires on March 14, 2025. This certificate is used to verify signed content and add-ons across various Mozilla projects, including Firefox. Failure to update to version 128 or higher (or ESR version 115.13+ […]
The post Mozilla Issues Urgent Firefox Update Warning to Prevent Add-on Failures appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
勒索软件攻击创历史新高:2025年2月攻击量激增126%
Bitdefender Identifies Security Vulnerabilities Enabling Man-in-the-Middle Exploits
Cybersecurity firm Bitdefender has disclosed two high-severity security vulnerabilities affecting its legacy BOX v1 device, exposing users to potential remote code execution and man-in-the-middle attacks. The vulnerabilities, identified on March 12th, 2025, affect a product that is no longer sold or supported by the company, but the disclosure demonstrates Bitdefender’s ongoing commitment to security transparency […]
The post Bitdefender Identifies Security Vulnerabilities Enabling Man-in-the-Middle Exploits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
通过 YouTube 传播的 DCRat 恶意软件正攻击用户以窃取登录凭证
Meta warns of actively exploited flaw in FreeType library
Future-Proofing Business Continuity: BCDR Trends and Challenges for 2025
【安全圈】谷歌警告 Chromecast 用户不要恢复出厂设置
【安全圈】施乐打印机漏洞使攻击者能够从 LDAP 和 SMB 中获取身份验证数据
【安全圈】PHP XXE 注入漏洞让攻击者读取配置文件和私钥
New DCRat Campaign Uses YouTube Videos to Target Users
A new campaign involving the DCRat backdoor has recently been uncovered, leveraging YouTube as a primary distribution channel. Since the beginning of the year, attackers have been using the popular video-sharing platform to target users by creating fake or stolen accounts. These malicious actors upload videos that appear to offer cheats, cracks, game bots, and […]
The post New DCRat Campaign Uses YouTube Videos to Target Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Годы присутствия: Китай нашел способ погрузить Америку во тьму
不断演变的分布式拒绝服务(DDoS)攻击策略:网络专家剖析社交媒体平台X的遭袭事件
VC Investment in Cyber Startups Surges 35%
Blind Eagle Attacking Organizations With Weaponized .url Files To Extract User Hash
The cybersecurity landscape has witnessed a concerning development as the threat actor group known as Blind Eagle (also tracked as APT-C-36) has launched a sophisticated campaign targeting organizations primarily in South America with a novel attack vector. The group, known for its persistent targeting of Colombian entities, has expanded its tactical repertoire to include weaponized […]
The post Blind Eagle Attacking Organizations With Weaponized .url Files To Extract User Hash appeared first on Cyber Security News.