Aggregator
CVE-2025-11840 | GNU Binutils 2.45 ldmisc.c vfinfo out-of-bounds (Bug 33455 / ID 16357)
CVE-2025-12105 | libsoup HTTP/2 use after free (Nessus ID 271688)
CVE-2025-43995 | Dell Storage Manager up to 2020 R1.20 DSM Data Collector improper authentication (dsa-2025-393 / EUVD-2025-35853)
瑞典国家电网运营商确认遭勒索团伙声称的数据泄露事件
Удар по кибер-армии Ирана? Взломана школа хакеров, атакующих мир от имени MuddyWater
俄罗斯黑客宣称攻陷都柏林机场系统
CVE-2025-4106 | WatchGuard Fireware OS up to 12.11.1 Management WebUI/Command Line Interface Parser debug code (wgsa-2025-00010 / EUVD-2025-35898)
CVE-2025-55752 | Apache Tomcat up to 8.4.x/8.5.100/9.0.108/10.1.44/11.0.10 Query Parameter /WEB-INF/ path traversal (EUVD-2025-36224 / Nessus ID 271693)
X warns users to re-enroll passkeys and YubiKeys for 2FA by Nov 10
澳大利亚就微软对 Microsoft 365 订阅费用涨价提起诉讼
新书推荐《云攻击向量:构建有效的网络防御策略》
OpenVPN Vulnerability Exposes Linux, macOS Systems to Script Injection Attacks
A new vulnerability in early versions of OpenVPN has been disclosed, potentially allowing malicious servers to execute arbitrary commands on client machines. The flaw affects OpenVPN releases from 2.7_alpha1 to 2.7_beta1, enabling script-injection attacks on POSIX-based systems such as Linux, macOS, and BSD variants. The issue stems from inadequate sanitization of the –dns and –dhcp-option […]
The post OpenVPN Vulnerability Exposes Linux, macOS Systems to Script Injection Attacks appeared first on Cyber Security News.
CVE-2023-25184 | Seiko SkyBridge/SkySpider weak password (EUVD-2023-29148)
CVE-2023-25134 | McAfee Total Protection up to 16.0.49 Component Object Model privilege escalation (EUVD-2023-29113)
CVE-2023-25133 | CyberPower PowerPanel Business/PowerPanel Business Management default.cmd privileges management (EUVD-2023-29112)
CVE-2023-25132 | CyberPower PowerPanel Business/PowerPanel Business Management default.cmd unrestricted upload (EUVD-2023-29111)
Behind MuddyWater’s Phoenix v4: The Malware Toolkit Compromising Global Entities
The Iran-linked Advanced Persistent Threat group MuddyWater has launched an aggressive phishing operation that compromised over 100 government entities and […]
The post Behind MuddyWater’s Phoenix v4: The Malware Toolkit Compromising Global Entities appeared first on HawkEye.
Gamaredon Phishing Campaign Exploits WinRAR Vulnerability to Target Government Agencies
Cybersecurity researchers have uncovered a sophisticated phishing campaign orchestrated by the notorious Gamaredon threat group, specifically targeting government entities through exploitation of a critical WinRAR vulnerability. The attack leverages CVE-2025-8088, a path traversal vulnerability in the popular file compression software, to deliver weaponized RAR archives that silently deploy malicious payloads without requiring user interaction beyond […]
The post Gamaredon Phishing Campaign Exploits WinRAR Vulnerability to Target Government Agencies appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.