Aggregator
CVE-2024-5462 | Brocade Fabric OS 9.2.0 cleartext transmission
CVE-2025-69210 | NeoRazorX facturascripts up to 2025.6 XML File Parser cross site scripting (GHSA-2267-xqcf-gw2m / EUVD-2025-205844)
CVE-2026-23476 | NeoRazorX facturascripts up to 2025.7 Error Message cross site scripting (GHSA-g6w2-q45f-xrp4)
CVE-2026-23997 | NeoRazorX facturascripts up to 2025.71 Observations cross site scripting (GHSA-4v7v-7v7r-3r5h)
CVE-2026-25513 | NeoRazorX facturascripts up to 2025.80 REST API ModelClass::getOrderBy sort sql injection (GHSA-cjfx-qhwm-hf99 / EUVD-2026-6094)
CVE-2026-25514 | NeoRazorX facturascripts up to 2025.80 Autocomplete CodeModel::all input validation (GHSA-pqqg-5f4f-8952 / EUVD-2026-6094)
CVE-2025-70296 | Mealie 3.3.1 Recipe Notes Rendering cross site scripting (Issue 6690)
CVE-2025-70297 | Mealie 3.3.1 SVG File Parser cross site scripting (Issue 6319)
CVE-2026-26007 | pyca cryptography up to 46.0.4 data authenticity (GHSA-r6ph-v2qm-q3c2 / Nessus ID 298585)
North Korean Threat Actors Leverage Fake IT Worker Campaigns and Contagious Interview Tactics
North Korean nation-state threat actors have been running a two-part operation — posing as job recruiters while embedding fake workers inside real companies. Since at least 2022, these actors have tricked software developers into running malicious code during fake technical interviews, using the malware families BeaverTail and OtterCookie to steal credentials, take remote control of […]
The post North Korean Threat Actors Leverage Fake IT Worker Campaigns and Contagious Interview Tactics appeared first on Cyber Security News.
Новый игрок в даркнете. Рассказываем, как форум LegionNull стал центром торговли данными
Fraud Investigation Reveals Sophisticated Python Malware
2025: The Untold Stories of Check Point Research
Introduction Check Point Research (CPR) continuously tracks threats, following the clues that lead to major players and incidents in the threat landscape. Whether it’s high-end financially-motivated campaigns or state-sponsored activity, our focus is to figure out what the threat is, report our findings to the relevant parties, and make sure Check Point customers stay protected. […]
The post 2025: The Untold Stories of Check Point Research appeared first on Check Point Research.
Fake troubleshooting tip on ClawHub leads to infostealer infection
A new malware delivery campaign has hit ClawHub, the official online repository for “skills” that augment the capabilities of the popular OpenClaw AI agent. Unlike previous ones, this campaign does not aim to trick users into downloading a bogus, malicious skill. Instead, the threat actor is leaving this particular comment on popular legitimate skills published by others: The malicious troubleshooting comment “At first glance, this appears to be a troubleshooting suggestion. It is not. It … More →
The post Fake troubleshooting tip on ClawHub leads to infostealer infection appeared first on Help Net Security.