Aggregator
CVE-2025-24917 | Tenable Network Monitor up to 6.5.0 on Windows access control
CVE-2025-48375 | schule111 Schule up to 1.0.0 forgot_password.php allocation of resources (GHSA-h3f2-mc85-67gc)
Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets
A new project has exposed a critical attack vector that exploits protocol vulnerabilities to disrupt DNS infrastructure, manipulate Non-Human Identity (NHI) secrets, and ultimately bypass zero-trust security frameworks. This research, conducted in a controlled lab environment, highlights a sophisticated attack chain targeting BIND DNS servers using a known vulnerability, CVE-2025-40775, rated as High severity with […]
The post Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-4540 | MTSoftware C-Lodop 6.6.1.1 on Windows CLodopPrintService unquoted search path
Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000
A threat actor known as #LongNight has reportedly put up for sale remote code execution (RCE) access to Burger King Spain’s backup system, leveraging vulnerabilities in the AhsayCBS platform. Priced at $4,000, this exploit offers malicious actors a potential gateway to compromise a critical infrastructural component of the fast-food giant’s operations in Spain. 4 The […]
The post Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
美国起诉与勒索软件攻击有关的Qakbot僵尸网络领导人
Alleged Sale of Web Admin Access to a Private Clinic in the USA
Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability
Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These flaws, when chained together, allow unauthenticated remote code execution (RCE) on internet-facing systems, posing a severe risk to enterprise security. EclecticIQ analysts have confirmed active exploitation in the wild since the disclosure date, with […]
The post Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
警方在全球打击行动中逮捕了270名暗网供应商和买家
Operation Endgame Takes Down DanaBot Malware, Neutralizes 300 Servers
Hackers Target macOS Users with Fake Ledger Apps to Deploy Malware
Hackers are increasingly targeting macOS users with malicious clones of Ledger Live, the popular application for managing crypto assets via Ledger cold wallets. Since August 2024, Moonlock Lab has been tracking a malware campaign that initially focused on stealing passwords and wallet details but has now evolved to extract seed phrases, enabling attackers to drain […]
The post Hackers Target macOS Users with Fake Ledger Apps to Deploy Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique
打印机制造商Procolled数月来一直提供恶意软件驱动程序
比特币在“披萨日”突破亚马逊市值,价格创下新高
Инженер Microsoft в свободное от работы время сделал Ubuntu, которая выглядит как Windows 11 — и она лучше, чем кажется
GitLab修补高严重性缺陷:修复了DPS和2FA绕过
U.S. Authorities Seize DanaBot Malware Operation, Indict 16
U.S. authorities seized the infrastructure of the DanaBot malware and charged 16 people in an action that is part of the larger Operation Endgame, a multinational initiative launched last year to disrupt and take apart global cybercriminals operations.
The post U.S. Authorities Seize DanaBot Malware Operation, Indict 16 appeared first on Security Boulevard.