Aggregator
CVE-2008-7021 | AvailScript Jobs Portal Script File Upload editlogo.php memory corruption (EDB-6514 / XFDB-45335)
Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files
Researchers warn of ongoing spear-phishing attacks by Russian threat actor Midnight Blizzard targeting individuals in various sectors. The attacks involve sending signed RDP configuration files to thousands of targets, aiming to compromise systems for intelligence gathering. The actor impersonates Microsoft employees and references other cloud providers to increase credibility, so users are advised to be […]
The post Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Sophisticated Phishing Attack Targeting Ukraine Military Sectors
The Ukrainian Cyber Emergency Response Team discovered a targeted phishing campaign launched by UAC-0215 against critical Ukrainian infrastructure, including government agencies, key industries, and military entities. Phishing emails promoting integration with Amazon, Microsoft, and ZTA contained malicious .rdp files. Upon opening, these files connected devices to attacker-controlled servers, compromising security. The sophisticated attack leveraged a […]
The post Sophisticated Phishing Attack Targeting Ukraine Military Sectors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Chinese Hackers Attacking Microsoft Customers With Sophisticated Password Spray Attacks
Researchers have identified a network of compromised devices, CovertNetwork-1658, used by Chinese threat actors to launch highly evasive password spray attacks, successfully stealing credentials from multiple Microsoft customers. The stolen credentials are then leveraged by threat actors like Storm-0940 to gain unauthorized access to systems. Storm-0940 has been an active threat actor since 2021 and […]
The post Chinese Hackers Attacking Microsoft Customers With Sophisticated Password Spray Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2015-8971 | Terminology 0.7.0 Escape Sequence command injection (Nessus ID 94744 / ID 175882)
New Windows Zero-Day Vulnerability Let Attackers Steal Credentials From Victim’s Machine
A security researcher discovered a vulnerability in Windows theme files in the previous year, which allowed malicious actors to steal Windows users’ credentials. When a theme file specifies a network path for specific properties, like the brand image or wallpaper, Windows automatically sends authenticated network requests to remote hosts, including the user’s NTLM credentials. This […]
The post New Windows Zero-Day Vulnerability Let Attackers Steal Credentials From Victim’s Machine appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Карнавал-призрак: ИИ превратил улицы дублина в хэллоуинский хаос
CVE-2015-8972 | GNU Chess up to 6.2.3 frontend/move.cc ValidateMove memory corruption (Nessus ID 95310 / ID 169536)
CVE-2024-20107 | MediaTek MT8676 Da out-of-bounds (MSV-1823 / ALPS09124360)
CVE-2024-20104 | MediaTek MT8676 Da out-of-bounds write (MSV-1772 / ALPS09073261)
CVE-2024-20106 | MediaTek MT8678 type confusion (MSV-1590 / ALPS08960505)
CVE-2024-20108 | MediaTek MT8798 Atci out-of-bounds write (MSV-1774 / ALPS09082988)
CVE-2024-20109 | MediaTek MT8195 Ccu out-of-bounds write (MSV-1763 / ALPS09065928)
CVE-2024-20110 | MediaTek MT8195 Ccu out-of-bounds write (MSV-1762 / ALPS09065887)
CVE-2024-20112 | MediaTek MT6878/MT6886/MT6897/MT6985/MT8676 Isp out-of-bounds (MSV-1730 / ALPS09071481)
INC
Microsoft confirms Windows Server 2025 blue screen, install issues
Z-lib - 9,737,374 breached accounts
SYS01 InfoStealer Malware Attacking Meta Business Page To Steal Logins
The ongoing Meta malvertising campaign, active for over a month, employs an evolving strategy to distribute the SYS01 InfoStealer through ElectronJs applications disguised as legitimate software like video editors, productivity tools, and streaming services. The campaign leverages nearly a hundred malicious domains for distribution and C2 operations, targeting a global audience, especially males aged 45 […]
The post SYS01 InfoStealer Malware Attacking Meta Business Page To Steal Logins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.