Aggregator
CVE-2025-40680 | Capillary CapillaryScope up to 2.4.x on Windows sensitive missing encryption (EUVD-2025-22510)
CVE-2025-8107 | OB OceanBase Server prior 3.2.4.9/4.2.1.10/4.2.5/4.3.3.2/4.3.4 exposure of resource (EUVD-2025-22483)
On-Premises SharePoint Server “ToolShell” Backdoor – Advisory for Mitigation and Response
Organizations Urged to Address Critical Security Flaws to Prevent Unauthorized Access to On-Premises SharePoint Servers.
The post On-Premises SharePoint Server “ToolShell” Backdoor – Advisory for Mitigation and Response appeared first on Sygnia.
CVE-2025-8022 | bun os command injection (SNYK-JS-BUN-9510752 / EUVD-2025-22414)
CVE-2025-8009 | Security Ninja Plugin up to 5.201/5.242 on WordPress get_file_source path traversal (EUVD-2025-22484)
CVE-2025-41240 | bitnamicharts /opt/bitnami/*/secrets information disclosure (EUVD-2025-22486)
CVE-2024-8418 | Aardvark-dns 1.12.0/1.12.1 TCP Query denial of service (EUVD-2024-2791 / Nessus ID 211080)
CVE-2025-4395 | Medtronic MyCareLink Patient Monitor 24952 empty password in configuration file (EUVD-2025-22480)
CVE-2025-7745 | ABB AC500 V2 up to 2.5.2 buffer over-read (EUVD-2025-22485 / WID-SEC-2025-1633)
CVE-2025-4394 | Medtronic MyCareLink Patient Monitor 24952 cleartext storage (EUVD-2025-22512)
CVE-2024-45769 | Red Hat Enterprise Linux 6/7/8/9 Performance Co-Pilot out-of-bounds write (EUVD-2024-41692 / Nessus ID 207940)
Threat Actors Using .hwp Files to Distribute RokRAT Malware and Evade Detection Mechanisms
The AhnLab Security intelligence Center (ASEC) has identified a sophisticated campaign where threat actors are leveraging Hangul Word Processor (.hwp) documents to disseminate the RokRAT remote access trojan (RAT), marking a departure from traditional methods that relied on shortcut (LNK) files embedded with decoy content and malicious scripts. This shift to .hwp files, commonly used […]
The post Threat Actors Using .hwp Files to Distribute RokRAT Malware and Evade Detection Mechanisms appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Akira
You must login to view this content
Sophos and SonicWall Patch Critical RCE Flaws Affecting Firewalls and SMA 100 Devices
GreySkull: полиция снесла четыре онлайн-пыточных и загнала 18 живодёров в клетку
Qilin
You must login to view this content