Aggregator
Microsoft Uncovers Scattered Spider Tactics, Techniques, and Procedures in Recent Attacks
Microsoft has shed light on the sophisticated operations of Octo Tempest, a financially motivated cybercriminal group alternatively known as Scattered Spider, Muddled Libra, UNC3944, or 0ktapus. This threat actor has demonstrated a versatile arsenal of tactics, techniques, and procedures (TTPs) in end-to-end attacks targeting organizations across various sectors. Octo Tempest’s methodology typically begins with initial […]
The post Microsoft Uncovers Scattered Spider Tactics, Techniques, and Procedures in Recent Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-6226 | Mattermost up to 9.11.16/10.5.6/10.7.3/10.8.1 Private Channel missing authentication (EUVD-2025-21867)
CVE-2025-6233 | Mattermost up to 9.11.16/10.5.7/10.7.3/10.8.1 JSONL File Import path traversal (EUVD-2025-21866)
CVE-2025-7803 | descreekert wx-discuz up to 12bd4745c63ec203cb32119bf77ead4a923bf277 /wx.php validToken echostr cross site scripting (EUVD-2025-21921)
WAFFLED: New Technique Targets Web Application Firewall Weaknesses
Cybersecurity researchers at Northeastern University and Dartmouth College have unveiled a groundbreaking attack technique that exploits fundamental parsing discrepancies in Web Application Firewalls (WAFs), potentially compromising the security of millions of websites worldwide. The research, dubbed “WAFFLED” (Web Application Firewall Fuzzing through Language Exploitation and Discrepancy), demonstrates how attackers can bypass five major WAF platforms. […]
The post WAFFLED: New Technique Targets Web Application Firewall Weaknesses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.