Aggregator
CVE-2024-21896 | Node.js up to 20.11.0/21.6.1 Experimental Permission Model path traversal (Nessus ID 216256)
CVE-2024-25626 | Yocto Project poky up to 3.1.30/4.0.15/4.3.1 HTTP os command injection (GHSA-75xw-78mm-72r4)
CVE-2024-25982 | Moodle prior 4.3.3/4.1.9 Language Pack cross-site request forgery (FEDORA-2024-d2f180202f)
CVE-2024-21984 | NetApp StorageGRID up to 11.7 cross site scripting (ntap-20240216-0013)
CVE-2024-21496 | greenpau caddy-security javascript URL cross site scripting (Issue 267)
CVE-2023-5190 | Liferay Portal/DXP External URL redirect
CVE-2024-25640 | dfir-iris iris-web up to 2.3.x cross site scripting (GHSA-2xq6-qc74-w5vp)
Wordpress Newsletters 后台SQL注入漏洞(CVE-2025-30921)
New Limitations Placed on DOGE’s Access to Private Social Security Information
A federal judge has issued a preliminary injunction that significantly limits the Department of Government Efficiency’s (DOGE) access to sensitive Social Security Administration (SSA) data. The ruling, handed down yesterday, found that the government had provided DOGE with access to this private information without a sufficient legal basis. The court order requires DOGE to immediately […]
The post New Limitations Placed on DOGE’s Access to Private Social Security Information appeared first on Cyber Security News.
Chinese Hackers Exploit Ivanti Connect Secure Flaw to Gain Unauthorized Access
In a sophisticated cyber-espionage operation, a group known as UNC5221, suspected to have China-nexus, has exploited a critical vulnerability in Ivanti Connect Secure VPN appliances. The exploit, identified as CVE-2025-22457, represents a stack-based buffer overflow affecting multiple Ivanti products, including Policy Secure and Zero Trust Access gateways. A Critical Flaw Initially Underestimated CVE-2025-22457 was initially […]
The post Chinese Hackers Exploit Ivanti Connect Secure Flaw to Gain Unauthorized Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2023-44308 | Liferay DXP up to 7.4.13.u92/2023.q3.5 redirect
CVE-2024-0656 | Password Protected Plugin up to 2.6.6 on WordPress cross site scripting
CVE-2024-1408 | ProfilePress Plugin up to 4.14.4 on WordPress Shortcode cross site scripting
CVE-2024-1570 | ProfilePress Plugin up to 4.14.4 on WordPress Shortcode cross site scripting
CVE-2024-1519 | ProfilePress Plugin up to 4.14.4 on WordPress cross site scripting
New Android SuperCard X Malware Uses NFC-Relay Technique for POS & ATM Transactions
A new malware strain known as SuperCard X has emerged, utilizing an innovative Near-Field Communication (NFC)-relay attack to execute unauthorized transactions at Point-of-Sale (POS) systems and Automated Teller Machines (ATMs). Detailed in a recent report by the Cleafy Threat Intelligence team, this Android-based malware has been identified as part of a sophisticated fraud campaign targeting […]
The post New Android SuperCard X Malware Uses NFC-Relay Technique for POS & ATM Transactions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
SheByte PaaS Launches $199 Subscription Service for Cybercriminals
The landscape of cyber threats targeting Canadian financial institutions saw significant shifts after LabHost, a prominent phishing-as-a-service (PhaaS) platform, was shut down. LabHost, known for its extensive Interac-branded phishing kits, was responsible for around three-fourths of such phishing attempts. Its sudden closure led to a halving of phishing attacks against Canadian banks in the subsequent […]
The post SheByte PaaS Launches $199 Subscription Service for Cybercriminals appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
恶意npm软件包伪装Telegram Bot API,在Linux系统植入SSH后门
Gorilla Android Malware Intercepts SMS to Steal One-Time Passwords
In a concerning development within the Android ecosystem, a new malware variant known as “Gorilla” has been identified, primarily targeting financial and personal information through SMS interception. Written in Kotlin, Gorilla appears to be in its developmental infancy, yet it already showcases sophisticated mechanisms for evasion, persistence, and data extraction. Gorilla’s code lacks obfuscation and […]
The post Gorilla Android Malware Intercepts SMS to Steal One-Time Passwords appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.