Aggregator
Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33
It is no secret that passwords are highly susceptible to phishing and brute force attacks. This led to the mass adoption of passkeys, a passwordless authentication method leveraging cryptographic key pairs that allows users to log in with biometrics or a hardware key. According to FIDO, over 15 billion accounts have been passkey-enabled, with 69% […]
The post Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-49790 | IBM Watson Studio on Cloud Pak for Data 4.0/5.0 Web UI cross site scripting
押注平台、价值腾飞,派拓网络背后的“SASE”力量
27 миллионов против триллионов: крошечный ИИ уничтожил GPT‑5 и Claude в тестах интеллекта
Trump administration setting the stage for elections power grab, voting rights group warns
A new report from the Brennan Center for Justice says the Trump administration has foreshadowed plans to meddle with mail-in voting, voter rolls and much more.
The post Trump administration setting the stage for elections power grab, voting rights group warns appeared first on CyberScoop.
UTG-Q-1000 Group Weaponizing Subsidy Schemes to Exfiltrate Sensitive Data
The emergence of sophisticated cybercriminal organizations continues to pose significant threats to individuals and institutions worldwide, with the UTG-Q-1000 group representing one of the most concerning developments in recent cybersecurity history. This highly organized criminal network has demonstrated exceptional technical prowess by exploiting China’s national childcare subsidy policy, transforming what should be a beneficial government […]
The post UTG-Q-1000 Group Weaponizing Subsidy Schemes to Exfiltrate Sensitive Data appeared first on Cyber Security News.
Weaponized ScreenConnect RMM Tool Deceives Users into Installing Xworm RAT
The SpiderLabs Threat Hunt Team recently discovered a cyber campaign in which threat actors used the genuine ScreenConnect remote management application as a weapon to spread the Xworm Remote Access Trojan (RAT) through a multi-phase infection chain. The attack begins with social engineering tactics, including phishing, malvertising, and deceptive social media posts, luring users to […]
The post Weaponized ScreenConnect RMM Tool Deceives Users into Installing Xworm RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-55621 | Reolink Web and Mobile App Services 4.54.0.4.20250526 authorization
CVE-2025-55619 | Reolink App 4.54.0.4.20250526 on Android initialization
CVE-2025-55622 | Reolink App 4.54.0.4.20250526 on Android Setting public cloneable() method without final ('object hijack')
CVE-2025-55623 | Reolink App 4.54.0.4.20250526 on Android ADB improper authentication
CVE-2025-55620 | Reolink App 4.54.0.4.20250526 on Android valuateJavascript cross site scripting
CVE-2025-55624 | Reolink App 4.54.0.4.20250526 on Android intent by broadcast receiver (EUVD-2025-25606)
CVE-2025-9140 | Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7 tabdetail_moduleSave.php getvaluestring sql injection (EDB-52420)
CVE-2025-8908 | Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4 event.php openid sql injection
CVE-2025-8528 | Exrick xboot up to 3.3.4 getMenuList sensitive information in a cookie (Issue 69)
CVE-2024-13273 | Drupal Open Social up to 12.3.7/12.4.4 cross site scripting
XCon x HG 国际黑马会议圆满成功 | 安全锚定 智守未来
Farmers Insurance Breach Exposes Data of 1.1 Million Customers via Salesforce Compromise
Farmers Insurance has disclosed a data breach stemming from unauthorized access to a third-party vendor’s database, potentially compromising the personal information of approximately 1.1 million customers. The breach, detected on May 30, 2025, involved an unauthorized actor infiltrating a system managed by the vendor, which housed sensitive customer data. Farmers, encompassing Farmers Insurance Exchange, Farmers […]
The post Farmers Insurance Breach Exposes Data of 1.1 Million Customers via Salesforce Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.