Aggregator
TransUnion Hack Exposes 4M+ Customers Personal Information
TransUnion, one of the nation’s three major credit reporting agencies, has disclosed a significant data breach that exposed the personal information of more than four million U.S. customers. The company is now alerting affected individuals about the cyber incident, which involved unauthorized access to data stored on a third-party application. On July 28, 2025, TransUnion […]
The post TransUnion Hack Exposes 4M+ Customers Personal Information appeared first on Cyber Security News.
围猎银狐 -- 终端安全能力建设共享第1期|基于 YARA 的特征检测与银狐追踪
TransUnion Data Breach Impacts 4.5 Million US Customers
DPRK Remote Work Tactics: Leveraging Code-Sharing Platforms
DPRK IT workers have leveraged popular code-sharing platforms such as GitHub, CodeSandbox, and Medium to cultivate convincing developer portfolios and land remote positions under fabricated identities. Investigations reveal approximately 50 active GitHub profiles operated by North Korean actors, supplemented by dozens of profiles across niche freelancing and forum sites. These operatives employ deepfake profile photos, […]
The post DPRK Remote Work Tactics: Leveraging Code-Sharing Platforms appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-9669 | Jinher OA 1.0 GetTreeDate.aspx ID sql injection
Silver Fox APT Hackers Leveraging Vulnerable driver to Attack Windows 10 and 11 Systems by Evading EDR/AV
Emerging in mid-2025, a sophisticated campaign attributed to the Silver Fox APT has begun exploiting a previously unreported vulnerable driver to compromise modern Windows environments. This campaign leverages the WatchDog Antimalware driver (amsdk.sys, version 1.0.600), a Microsoft-signed component built on the Zemana Anti-Malware SDK. By abusing its arbitrary process termination capability, threat actors bypass endpoint […]
The post Silver Fox APT Hackers Leveraging Vulnerable driver to Attack Windows 10 and 11 Systems by Evading EDR/AV appeared first on Cyber Security News.
Submit #637413: Jinhe OA V1.0 SQL Injection [Accepted]
Google и Zed запускают ACP, чтобы освободить ИИ-агентов от монополии VS Code
CVE-2024-13987 | Synology RADIUS Server prior 3.0.27-0139 cross site scripting (SA_25_10)
Submit #637297: Prain 1.3.3 code injection [Duplicate]
Submit #637292: PHP Directory Management System V2.0 SQL Injection [Duplicate]
诚邀渠道合作伙伴共启新征程
【火绒安全周报】抖音曝光“字节跳动”等多款山寨App/5万余条学生个人信息遭非法倒卖
2025数博会 | 中国电信安全:构建多层次立体化大模型安全动态防护体系
报告发布:2025中国数字安全价值图谱(8月)更新
Rage Against the Authentication State Machine
Nx Packages With Millions of Weekly Downloads Hacked With Credential Stealer Malware
A sophisticated supply chain attack has compromised the popular Nx build platform, affecting millions of weekly downloads and resulting in widespread credential theft. The attack, dubbed “s1ngularity,” represents one of the most comprehensive credential harvesting campaigns targeting the developer ecosystem in 2025. GitGuardian observed that malicious actors infiltrated multiple Nx package versions (20.9.0 through 21.8.0) […]
The post Nx Packages With Millions of Weekly Downloads Hacked With Credential Stealer Malware appeared first on Cyber Security News.