Aggregator
CVE-2025-10839 | SourceCodester Pet Grooming Management Software 1.0 /admin/inv-print.php ID sql injection
CVE-2025-10840 | SourceCodester Pet Grooming Management Software 1.0 /admin/print-payment.php sql111 sql injection
CVE-2025-10380 | Advanced Views Plugin up to 3.7.19 on WordPress special elements used in a template engine
CVE-2025-8902 | Widget Options Extended Plugin up to 5.2.1 on WordPress do_sidebar cross site scripting
Hackers Exploits IMDS Service to Gain Initial Access to a Cloud Environment
Threat actors were manipulating the Instance Metadata Service (IMDS), a core component designed to securely furnish compute instances with temporary credentials to infiltrate and navigate cloud infrastructures. By compelling unsuspecting applications to query IMDS endpoints, attackers harvest short-lived tokens, enabling credential theft, lateral movement, and privilege escalation within victim environments. Exploit IMDS Service Wiz reports […]
The post Hackers Exploits IMDS Service to Gain Initial Access to a Cloud Environment appeared first on Cyber Security News.
CVE-2025-10851 | Campcodes Gym Management System 1.0 /ajax.php?action=login Username sql injection (EUVD-2025-30878)
CVE-2025-10857 | Campcodes Point of Sale System POS 1.0 /login.php Username sql injection (EUVD-2025-30876)
CVE-2025-10147 | Eric Teubert Podlove Podcast Publisher Plugin up to 4.2.6 on WordPress move_as_original_file unrestricted upload (EUVD-2025-30877)
CVE-2025-9798 | Netcad Netigma prior 6.3.5 V8 cross site scripting (EUVD-2025-30875)
受 Salesforce 供应链攻击影响,全球汽车巨头 Stellantis 数据遭泄露
New npm Malware Steals Browser Passwords via Steganographic QR Code
A novel npm package named fezbox has been uncovered by the Socket Threat Research Team as a sophisticated malware delivery mechanism that exfiltrates username and password credentials from browser cookies via an embedded QR code. Published under the npm alias janedu (registration email janedu0216@gmail[.]com), the package masquerades as a harmless JavaScript/TypeScript utility library while quietly […]
The post New npm Malware Steals Browser Passwords via Steganographic QR Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
22,2 терабита чистого хаоса. Абсолютный рекорд DDoS-атак побит вновь
A suspected Scattered Spider member suspect detained for casino network attacks
Lean Teams, Higher Stakes: Why CISOs Must Rethink Incident Remediation
ShadowV2 Botnet Exploits Misconfigured AWS Docker Containers for DDoS-for-Hire Service
Inc Ransomware Group Claims 5.7 TB Theft from Pennsylvania Attorney General’s Office
Apple’s New Memory Integrity Enforcement
Apple has introduced a new hardware/software security feature in the iPhone 17: “Memory Integrity Enforcement,” targeting the memory safety vulnerabilities that spyware products like Pegasus tend to use to get unauthorized system access. From Wired:
In recent years, a movement has been steadily growing across the global tech industry to address a ubiquitous and insidious type of bugs known as memory-safety vulnerabilities. A computer’s memory is a shared resource among all programs, and memory safety issues crop up when software can pull data that should be off limits from a computer’s memory or manipulate data in memory that shouldn’t be accessible to the program. When developers—even experienced and security-conscious developers—write software in ubiquitous, historic programming languages, like C and C++, it’s easy to make mistakes that lead to memory safety vulnerabilities. That’s why proactive tools like ...
The post Apple’s New Memory Integrity Enforcement appeared first on Security Boulevard.
Zloader Malware Used as Gateway for Ransomware Deployment in Corporate Networks
Zloader, a sophisticated Zeus-based modular trojan that first emerged in 2015, has undergone a significant transformation from its original banking-focused purpose to become a dangerous tool for initial access and ransomware deployment in corporate environments. Following an almost two-year hiatus, this malware reemerged in September 2023 with substantial enhancements to its obfuscation techniques, domain generation […]
The post Zloader Malware Used as Gateway for Ransomware Deployment in Corporate Networks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.