Aggregator
CVE-2024-57412 | SunOS Omnios 5.11 TCP Packet denial of service
CVE-2025-61659 | magicmonty bash-git-prompt up to 2.7.1 /tmp/git-index-private$$ temp file (Issue 561)
CVE-2025-56795 | hay-kot Mealie up to 3.0.1 /api/recipes/ note/text cross site scripting (Issue 5677)
CVE-2025-56234 | Nanda AT_NA2000 Sequence Number random values
CVE-2025-51495 | Mongoose up to 7.17 WebSocket integer overflow (EUVD-2025-31586)
CVE-2025-56233 | Openindiana 5.11 Sequence Number random values
CVE-2025-41244 | VMware VCF operations prior 9.0.1.0 privilege defined with unsafe actions (VMSA-2025-0015)
CVE-2025-41245 | VMware Aria Operations up to 8.18.4 insecure default initialization of resource (VMSA-2025-0015)
CVE-2025-7104 | danny-avila librechat up to 0.7.8 Request Body author/access_level/isCollaborative/projectIds dynamically-determined object attributes
CVE-2025-41246 | VMware Tools prior 12.5.4/13.0.5.0 on Windows authorization
Dutch Teens Arrested Over Alleged Spying for Pro-Russian Hackers
Interpol operation disrupts romance scam and sextortion networks in Africa
Authorities arrested 260 cybercrime suspects during a two-week operation spanning 14 African countries, Interpol announced Friday. The globally coordinated summertime crackdown dubbed “Operation Contender 3.0” targeted criminal networks that facilitated romance scams and sextortion, officials said. Interpol said total losses attributed to the scam syndicates amounted to about $2.8 million, involving almost 1,500 victims. Authorities […]
The post Interpol operation disrupts romance scam and sextortion networks in Africa appeared first on CyberScoop.
Ransomware gang sought BBC reporter’s help in hacking media giant
Меньше ладони человека на радаре, 30 тонн взлётной массы в реальности. Что стоит за китайскими утверждениями о суперстелсе J-35
Hackers Trick Users into Download Weaponized Microsoft Teams to Gain Remote Access
A sophisticated cyber campaign is exploiting the trust users place in popular collaboration software, tricking them into downloading a weaponized version of Microsoft Teams to gain remote access to their systems. Threat actors are using search engine optimization (SEO) poisoning and malicious advertisements to lure unsuspecting victims to fraudulent download pages, a tactic that closely […]
The post Hackers Trick Users into Download Weaponized Microsoft Teams to Gain Remote Access appeared first on Cyber Security News.
SunshineCTF 2025
Date: Sept. 27, 2025, 2 p.m. — 29 Sept. 2025, 14:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://sunshinectf.org/
Rating weight: 51.65
Event organizers: Knightsec
Randall Munroe’s XKCD ‘’Biology Department”
via the comic artistry and dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘’Biology Department” appeared first on Security Boulevard.