Aggregator
Kill
Qilin
New Snake Keylogger Variant Leverages AutoIt Scripting to Evade Detection
OpenSSH bugs allows Man-in-the-Middle and DoS Attacks
Qilin
CVE-2025-0916 | yaycommerce YaySMTP and Email Logs Plugin up to 2.6.2 on WordPress Any SMTP Service wp_kses_post cross site scripting
CVE-2024-13534 | enituretechnology Small Package Quotes Plugin up to 5.2.18 on WordPress edit_id/dropship_edit_id sql injection
CVE-2024-13533 | enituretechnology Small Package Quotes Plugin up to 1.3.5 on WordPress edit_id sql injection
CVE-2025-0968 | xpeedstudio ElementsKit Elementor Addons Plugin up to 3.4.0 on WordPress get_megamenu_content access control
CVE-2024-13491 | enituretechnology Small Package Quotes Plugin up to 4.3.1 on WordPress edit_id/dropship_edit_id sql injection
CVE-2024-13485 | enituretechnology LTL Freight Quotes Plugin up to 3.3.7 on WordPress edit_id/dropship_edit_id sql injection
CVE-2024-13483 | enituretechnology LTL Freight Quotes Plugin up to 2.2.10 on WordPress edit_id/dropship_edit_id sql injection
CVE-2024-13481 | enituretechnology LTL Freight Quotes Plugin up to 3.3.4 on WordPress edit_id/dropship_edit_id sql injection
CVE-2024-13479 | enituretechnology LTL Freight Quotes Plugin up to 3.2.4 on WordPress dropship_edit_id/edit_id sql injection
CVE-2024-13478 | enituretechnology LTL Freight Quotes Plugin up to 3.6.4 on WordPress dropship_edit_id/edit_id sql injection
CISA and Partners Release Advisory on Ghost (Cring) Ransomware
Today, CISA—in partnership with the Federal Bureau of Investigation (FBI) and Multi-State Information Sharing and Analysis Center (MS-ISAC)—released a joint Cybersecurity Advisory, #StopRansomware: Ghost (Cring) Ransomware. This advisory provides network defenders with indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with Ghost ransomware activity identified through FBI investigations.
Ghost actors conduct these widespread attacks targeting and compromising organizations with outdated versions of software and firmware on their internet facing services. These malicious ransomware actors are known to use publicly available code to exploit Common Vulnerabilities and Exposures (CVEs) where available patches have not been applied to gain access to internet facing servers. The known CVEs are CVE-2018-13379, CVE-2010-2861, CVE-2009-3960, CVE-2021-34473, CVE-2021-34523, CVE-2021-31207.
CISA encourages network defenders to review this advisory and apply the recommended mitigations. See #StopRansomware and the #StopRansomware Guide for additional guidance on ransomware protection, detection, and response. Visit CISA’s Cross-Sector Cybersecurity Performance Goals for more information on the CPGs, including added recommended baseline protections.
Cyber Investor Insight Partners Suffers Security Breach
Russian phishing campaigns exploit Signal's device-linking feature
New IRS and Tax-Themed Cyber Attacks Fueled With New Domain Registrations
As the 2025 U.S. tax season reaches its peak, cybersecurity analysts report a dramatic escalation in phishing campaigns exploiting IRS and federal tax themes. Between January 1 and February 18, threat actors registered 158 unique domains mimicking official IRS subdomains like “irs.gov.*”, deploying advanced social engineering tactics through SMS phishing (smishing) and social media platforms. […]
The post New IRS and Tax-Themed Cyber Attacks Fueled With New Domain Registrations appeared first on Cyber Security News.