Aggregator
CVE-2025-56795 | hay-kot Mealie up to 3.0.1 /api/recipes/ note/text cross site scripting (Issue 5677)
CVE-2025-56234 | Nanda AT_NA2000 Sequence Number random values
CVE-2025-51495 | Mongoose up to 7.17 WebSocket integer overflow (EUVD-2025-31586)
CVE-2025-56233 | Openindiana 5.11 Sequence Number random values
CVE-2025-41244 | VMware VCF operations prior 9.0.1.0 privilege defined with unsafe actions (VMSA-2025-0015)
CVE-2025-41245 | VMware Aria Operations up to 8.18.4 insecure default initialization of resource (VMSA-2025-0015)
CVE-2025-7104 | danny-avila librechat up to 0.7.8 Request Body author/access_level/isCollaborative/projectIds dynamically-determined object attributes
CVE-2025-41246 | VMware Tools prior 12.5.4/13.0.5.0 on Windows authorization
Dutch Teens Arrested Over Alleged Spying for Pro-Russian Hackers
Interpol operation disrupts romance scam and sextortion networks in Africa
Authorities arrested 260 cybercrime suspects during a two-week operation spanning 14 African countries, Interpol announced Friday. The globally coordinated summertime crackdown dubbed “Operation Contender 3.0” targeted criminal networks that facilitated romance scams and sextortion, officials said. Interpol said total losses attributed to the scam syndicates amounted to about $2.8 million, involving almost 1,500 victims. Authorities […]
The post Interpol operation disrupts romance scam and sextortion networks in Africa appeared first on CyberScoop.
Ransomware gang sought BBC reporter’s help in hacking media giant
Меньше ладони человека на радаре, 30 тонн взлётной массы в реальности. Что стоит за китайскими утверждениями о суперстелсе J-35
Hackers Trick Users into Download Weaponized Microsoft Teams to Gain Remote Access
A sophisticated cyber campaign is exploiting the trust users place in popular collaboration software, tricking them into downloading a weaponized version of Microsoft Teams to gain remote access to their systems. Threat actors are using search engine optimization (SEO) poisoning and malicious advertisements to lure unsuspecting victims to fraudulent download pages, a tactic that closely […]
The post Hackers Trick Users into Download Weaponized Microsoft Teams to Gain Remote Access appeared first on Cyber Security News.
SunshineCTF 2025
Date: Sept. 27, 2025, 2 p.m. — 29 Sept. 2025, 14:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://sunshinectf.org/
Rating weight: 51.65
Event organizers: Knightsec
Randall Munroe’s XKCD ‘’Biology Department”
via the comic artistry and dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘’Biology Department” appeared first on Security Boulevard.
European AI company’s ‘reputation reports’ are inaccurate and illegal, watchdog claims
Bitchat против Блэкаута. Как "блютусный" мессенджер победил комендантский час и цензуру в Мадагаскаре
New Harrods Data Breach Exposes 430,000 Customer Personal Records
Luxury department store Harrods has disclosed a significant data breach affecting approximately 430,000 customer records after a third-party provider was compromised. The hackers behind the attack have contacted the retailer, but Harrods has stated it will not engage with the threat actor, suggesting a potential ransom demand was made. The breach, which Harrods first communicated […]
The post New Harrods Data Breach Exposes 430,000 Customer Personal Records appeared first on Cyber Security News.