Aggregator
GHNA is Claiming to Sell Access to an Unidentified South Korean Dating App
CVE-2025-22207 | Joomla CMS up to 4.4.10/5.2.3 com_scheduler sql injection (Nessus ID 216413)
Sorb Claims to be Selling Data of TOT Public Company Limited
2024 Vulnerability Scanning Surges 91%
2024 Vulnerability Scanning Surges 91%
CVE-2024-12325 | Waymark Plugin up to 1.4.1 on WordPress content cross site scripting
CVE-2024-12503 | ClassCMS 4.8 Model Management Page /index.php/admin URL cross site scripting
CVE-2024-50585 | Numerix License Server Administration System 1.1_596 HTTP POST Request nlslogin.jsp cross site scripting
CVE-2024-12004 | WPC Order Notes for WooCommerce Plugin up to 1.5.2 on WordPress cross-site request forgery
CVE-2024-10182 | Cognito Forms Plugin up to 2.0.6 on WordPress id cross site scripting
CVE-2024-12526 | Arena.IM Plugin up to 0.3.0 on WordPress Setting cross-site request forgery
CVE-2024-12463 | Arena.IM Plugin up to 0.3.0 on WordPress Shortcode arena_embed_amp cross site scripting
CVE-2024-11384 | Arena.IM Plugin up to 0.3.0 on WordPress cross site scripting
CVE-2024-11723 | kvCORE IDX Plugin up to 2.3.35 on WordPress cross site scripting
Highly Obfuscated .NET sectopRAT Mimic as Chrome Extension
SectopRAT, also known as Arechclient2, is a sophisticated Remote Access Trojan (RAT) developed using the .NET framework. This malware is notorious for its advanced obfuscation techniques, making it challenging to analyze and detect. Recently, cybersecurity researchers uncovered a new campaign where sectopRAT disguises itself as a legitimate Google Chrome extension named “Google Docs,” further amplifying […]
The post Highly Obfuscated .NET sectopRAT Mimic as Chrome Extension appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
6 considerations for 2025 cybersecurity investment decisions
Cybersecurity professionals may be concerned about the constantly shifting threat landscape. From the increased use of artificial intelligence (AI) by malicious actors to the expanding attack surface, cybersecurity risks evolve, and defenders need to mitigate them. Despite a period of cybersecurity budget growth between 2021 and 2022, this growth has slowed in the last few years, meaning that cybersecurity leaders need to carefully consider how their purchases improve their current security and compliance posture. To … More →
The post 6 considerations for 2025 cybersecurity investment decisions appeared first on Help Net Security.
Threat Actors Trojanize Popular Games to Evade Security and Infect Systems
A sophisticated malware campaign was launched by cybercriminals, targeting users through trojanized versions of popular games. Exploiting the holiday season’s heightened torrent activity, the attackers distributed compromised game installers via torrent trackers. The campaign, which lasted for a month, primarily delivered the XMRig cryptominer to unsuspecting users in Russia, Brazil, Germany, Belarus, and Kazakhstan. Popular […]
The post Threat Actors Trojanize Popular Games to Evade Security and Infect Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
OpenSSH Flaws Expose Systems to Critical Attacks
New Research Aims to Strengthen MITRE ATT&CK for Evolving Cyber Threats
A recent study by researchers from the National University of Singapore and NCS Cyber Special Ops R&D explores how the MITRE ATT&CK framework can be enhanced to address the rapidly evolving landscape of cyber threats. The research synthesizes findings from 417 peer-reviewed publications to evaluate the framework’s applications across various cybersecurity domains, including threat intelligence, […]
The post New Research Aims to Strengthen MITRE ATT&CK for Evolving Cyber Threats appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.