Aggregator
CVE-2024-13478 | enituretechnology LTL Freight Quotes Plugin up to 3.6.4 on WordPress dropship_edit_id/edit_id sql injection
CISA and Partners Release Advisory on Ghost (Cring) Ransomware
Today, CISA—in partnership with the Federal Bureau of Investigation (FBI) and Multi-State Information Sharing and Analysis Center (MS-ISAC)—released a joint Cybersecurity Advisory, #StopRansomware: Ghost (Cring) Ransomware. This advisory provides network defenders with indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods associated with Ghost ransomware activity identified through FBI investigations.
Ghost actors conduct these widespread attacks targeting and compromising organizations with outdated versions of software and firmware on their internet facing services. These malicious ransomware actors are known to use publicly available code to exploit Common Vulnerabilities and Exposures (CVEs) where available patches have not been applied to gain access to internet facing servers. The known CVEs are CVE-2018-13379, CVE-2010-2861, CVE-2009-3960, CVE-2021-34473, CVE-2021-34523, CVE-2021-31207.
CISA encourages network defenders to review this advisory and apply the recommended mitigations. See #StopRansomware and the #StopRansomware Guide for additional guidance on ransomware protection, detection, and response. Visit CISA’s Cross-Sector Cybersecurity Performance Goals for more information on the CPGs, including added recommended baseline protections.
Cyber Investor Insight Partners Suffers Security Breach
Russian phishing campaigns exploit Signal's device-linking feature
New IRS and Tax-Themed Cyber Attacks Fueled With New Domain Registrations
As the 2025 U.S. tax season reaches its peak, cybersecurity analysts report a dramatic escalation in phishing campaigns exploiting IRS and federal tax themes. Between January 1 and February 18, threat actors registered 158 unique domains mimicking official IRS subdomains like “irs.gov.*”, deploying advanced social engineering tactics through SMS phishing (smishing) and social media platforms. […]
The post New IRS and Tax-Themed Cyber Attacks Fueled With New Domain Registrations appeared first on Cyber Security News.
Обмани себя сам: как ИИ-трейдеры ведут подписчиков к финансовому краху
На грани двух физик: что такое квантовое вращение и как его измерить
CVE-2025-1075 | Checkmk up to 2.1.0p50/2.2.0p39/2.3.0p26 log file
CVE-2025-1075 | Checkmk up to 2.1.0p50/2.2.0p39/2.3.0p26 log file
CVE-2021-47222 | Linux Kernel up to 4.14.237/4.19.195/5.4.127/5.10.45/5.12.12 bridge include/net/dst.h dst_clone use after free (Nessus ID 216454)
CVE-2024-53209 | Linux Kernel up to 6.11.10/6.12.1 bnxt_set_rx_skb_mode null pointer dereference (Nessus ID 216460)
CVE-2024-53177 | Linux Kernel up to 6.6.63/6.11.10/6.12.1 smb open_cached_dir use after free (Nessus ID 216460)
CVE-2024-53166 | Linux Kernel up to 6.6.63/6.11.10/6.12.1 bfq_limit_depth use after free (Nessus ID 216460)
Apache Ignite 现高危漏洞(CVE-2024-52577),可致任意代码执行
Fog
Вирус в заявке: как Zhong Stealer «ломает» компании через службу поддержки
AI安全助手杀疯了!误报率直降40%!
AI安全助手杀疯了!误报率直降40%!
SecMap - Flask
SecMap 系列之 Flask,本篇介绍 flask 相关的攻击手法。