Aggregator
CVE-2025-23100 | Samsung Mobile Processor Exynos 1280/1380/1480/2200/2400 denial of service (EUVD-2025-16784)
CVE-2025-23102 | Samsung Mobile Processor Exynos up to 9825 double free (EUVD-2025-16776)
CVE-2024-34067 | Pterodactyl Panel up to 1.11.5 cross site scripting
CVE-2018-17383 | Collection Factory 4.1.9 on Joomla filter_order/filter_order_Dir sql injection (File 149530/Joo / EDB-45474)
New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently
A sophisticated new social engineering attack campaign has emerged that exploits users’ familiarity with routine security checks to deliver malware through deceptive Cloudflare verification pages. The ClickFix attack technique represents a concerning evolution in phishing methodology, abandoning traditional file downloads in favor of manipulating users into executing malicious commands directly on their own systems. The […]
The post New ClickFix Attack Exploits Fake Cloudflare Human Check to Install Malware Silently appeared first on Cyber Security News.
CVE-2011-1996 | Microsoft Internet Explorer 6/7/8 input validation (MS11-081 / EDB-24020)
CVE-2022-2025 | Grandstream GSD3710 1.0.11.13 strcopy stack-based overflow (EDB-52313)
CVE-2000-1112 | Microsoft Windows Media Player 7 WMS File cross site scripting (MS00-090 / EDB-20424)
CVE-2025-24763 | Pascal Casier bbPress API Plugin up to 1.0.14 on WordPress authorization (EUVD-2025-17157)
CVE-2024-56805 | QNAP QTS/QuTS hero prior 5.2.4.3079 Build 20250321 buffer overflow (qsa-25-12 / EUVD-2024-54653)
CVE-2025-22484 | QNAP File Station 5.5.6.4847 allocation of resources (qsa-25-16 / EUVD-2025-17339)
CVE-2025-5761 | PHPGurukul BP Monitoring Management System 1.0 /edit-family-member.php memberage sql injection (EUVD-2025-17137)
CVE-2025-5788 | TOTOLINK X15 1.0.0-B20230714.1105 HTTP POST Request formReflashClientTbl submit-url buffer overflow (EUVD-2025-17328)
CVE-2025-48781 | Soar Cloud System HRD Human Resource Management System up to 7.3.2025.0408 file inclusion (EUVD-2025-17101)
CVE-2025-49067 | NasaTheme Nasa Core Plugin up to 6.4.0 on WordPress cross site scripting (EUVD-2025-17136)
CVE-2023-51955 | Tenda AX1803 1.0.0.1 formSetIptv stballvlans stack-based overflow (EUVD-2023-56635)
CVE-2023-49617 | MachineSense FeverWarn API missing authentication (icsa-24-025-01 / EUVD-2023-53561)
DragonForce Ransomware Claimed To Compromise Over 120 Victims in The Past Year
DragonForce, a sophisticated ransomware operation that emerged in fall 2023, has established itself as a formidable threat in the cybercriminal landscape by claiming over 120 victims across the past year. Unlike traditional ransomware-as-a-service models, this threat actor has evolved into what security experts term a “ransomware cartel,” fundamentally changing how cybercriminal operations are structured and […]
The post DragonForce Ransomware Claimed To Compromise Over 120 Victims in The Past Year appeared first on Cyber Security News.