Aggregator
New ‘SleepyDuck’ Malware in Open VSX Marketplace Allow Attackers to Control Windows Systems Remotely
A sophisticated remote access trojan named SleepyDuck has infiltrated the Open VSX IDE extension marketplace, targeting developers using code editors like Cursor and Windsurf. The malware disguised itself as a legitimate Solidity extension under the identifier juan-bianco.solidity-vlang, exploiting name squatting techniques to deceive unsuspecting users. Initially published on October 31st as version 0.0.7, the extension […]
The post New ‘SleepyDuck’ Malware in Open VSX Marketplace Allow Attackers to Control Windows Systems Remotely appeared first on Cyber Security News.
CVE-2025-54333 | Samsung Mobile Processor Exynos NPU get_vs4l_profiler_node null pointer dereference
CVE-2025-54332 | Samsung Mobile Processor Exynos NPU npu_vertex_profileoff null pointer dereference
CVE-2025-54331 | Samsung Mobile Processor Exynos NPU copy_ncp_header src_hdr null pointer dereference
CVE-2025-23358 | NVIDIA NVApp on Windows Installer uncontrolled search path
CVE-2025-54330 | Samsung Mobile Processor Exynos NPU __is_done_for_me out-of-bounds
CVE-2025-61431 | Infinity ZMaintenance Infinity up to 4.1 gsfr_feditorHTML.jsp pHtmlSource cross site scripting
CVE-2025-60925 | codeshare 1.0.0 information disclosure
CVE-2025-54327 | Samsung Processor and Wearable Processor Exynos 1280/1380/2200 VTS input validation
CVE-2025-61956 | Radiometrics VizAir API missing authentication (icsa-25-308-04 / EUVD-2025-37762)
CVE-2025-33176 | NVIDIA RunAI communication channel to intended endpoints
CVE-2025-64322 | Salesforce Agentforce Vibes Extension up to 3.1.x Configuration permission assignment
CVE-2025-64321 | Salesforce Agentforce Vibes Extension up to 3.1.x LLM Prompting code injection
CVE-2025-64320 | Salesforce Agentforce Vibes Extension up to 3.1.x LLM Prompting code injection
CVE-2025-64319 | Salesforce Mulesoft Anypoint Code Builder up to 1.11.5 Configuration permission assignment
CVE-2025-64318 | Salesforce Mulesoft Anypoint Code Builder up to 1.11.5 Configuration privilege escalation
CVE-2025-54334 | Samsung Mobile Processor Exynos up to 2500 NPU Driver __npu_vertex_bootup null pointer dereference
CVE-2025-10875 | Salesforce Mulesoft Anypoint Code Builder up to 1.11.5 LLM Prompting code injection
North Korean companies, people sanctioned for money laundering from cybercrime, IT worker schemes
The Treasury Department on Tuesday sanctioned eight people and two companies it accused of laundering money obtained from cybercrime and IT worker schemes to fund North Korean government objectives. According to the department, over the last three years North Korea-linked cybercriminals have stolen over $3 billion, mostly in cryptocurrency. In addition, it said, North Korean […]
The post North Korean companies, people sanctioned for money laundering from cybercrime, IT worker schemes appeared first on CyberScoop.