Aggregator
CIISec Members Say Budgets Are Falling Behind Threats
Asahi halts ordering, shipping, and customer service after cyberattack
U.K. Police Just Seized £5.5 Billion in Bitcoin — The World’s Largest Crypto Bust
信息安全漏洞周报(2025年第39期)
因 AI 需求大涨 DRAM 价格翻倍
《全球数据泄露态势月度报告》(2025年8月)| 附下载地址
GROW计划二期报名启动,携手奇安信基金会守护社会组织网络安全!
Ваш босс создал чатик в Telegram? Готовьтесь закрыть чужой кредит
微塑料可能削弱骨骼
中国信息安全测评中心主任彭涛:凝聚共治合力 筑牢反诈防线
Malicious Code in Fake Postmark MCP Server Steals Thousands of Emails
A newly discovered attack on the npm ecosystem has exposed a deceptive backdoor embedded in a malicious package impersonating Postmark. The package, named postmark-mcp, quietly siphoned off thousands of emails from unsuspecting developers and organizations, all with just one line of code. Over the course of 15 incremental releases, the threat actor behind postmark-mcp built […]
The post Malicious Code in Fake Postmark MCP Server Steals Thousands of Emails appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Прошивки Apple больше не будут гигантами. Инженеры создали систему, которая позволяет анализировать десятки тысяч IPSW
Apple Font Parser Vulnerability Allowing Memory Corruption Attacks
Apple has released a security update for macOS Sequoia 15.7.1 to address a serious vulnerability in its font parser. The flaw, tracked as CVE-2025-43400, allows a maliciously crafted font file to trigger an out-of-bounds write. Exploitation could cause unexpected application crashes or corrupt process memory on affected systems. Apple patched this issue on September 29, 2025, as […]
The post Apple Font Parser Vulnerability Allowing Memory Corruption Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Scattered Spider, ShinyHunters Restructure – New Attacks Underway
100 000 запросов бесплатно, IP-адрес скрыт. На GitHub появился FlareProx — прокси на Cloudflare, который обещает упростить веб-скрейпинг и пентесты
VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution
A zero-day local privilege escalation vulnerability in VMware Tools and VMware Aria Operations is being actively exploited in the wild. The flaw, tracked as CVE-2025-41244, allows an unprivileged local attacker to gain root-level code execution on affected systems. On September 29, 2025, Broadcom disclosed the vulnerability, which exists within VMware’s guest service discovery features. However, […]
The post VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution appeared first on Cyber Security News.
Veeam RCE Exploit Allegedly Listed for Sale on Dark Web
A new dark web marketplace listing has sparked alarm in the cybersecurity community after a seller using the handle “SebastianPereiro” purportedly advertised a remote code execution (RCE) exploit targeting Veeam Backup & Replication platforms. The alleged exploit, marketed as the “Bug of June 2025,” is claimed to affect certain versions of Veeam 12.x series, specifically […]
The post Veeam RCE Exploit Allegedly Listed for Sale on Dark Web appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.