Aggregator
TransUnion Data Breach Impacts 4.5 Million US Customers
DPRK Remote Work Tactics: Leveraging Code-Sharing Platforms
DPRK IT workers have leveraged popular code-sharing platforms such as GitHub, CodeSandbox, and Medium to cultivate convincing developer portfolios and land remote positions under fabricated identities. Investigations reveal approximately 50 active GitHub profiles operated by North Korean actors, supplemented by dozens of profiles across niche freelancing and forum sites. These operatives employ deepfake profile photos, […]
The post DPRK Remote Work Tactics: Leveraging Code-Sharing Platforms appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-9669 | Jinher OA 1.0 GetTreeDate.aspx ID sql injection
Silver Fox APT Hackers Leveraging Vulnerable driver to Attack Windows 10 and 11 Systems by Evading EDR/AV
Emerging in mid-2025, a sophisticated campaign attributed to the Silver Fox APT has begun exploiting a previously unreported vulnerable driver to compromise modern Windows environments. This campaign leverages the WatchDog Antimalware driver (amsdk.sys, version 1.0.600), a Microsoft-signed component built on the Zemana Anti-Malware SDK. By abusing its arbitrary process termination capability, threat actors bypass endpoint […]
The post Silver Fox APT Hackers Leveraging Vulnerable driver to Attack Windows 10 and 11 Systems by Evading EDR/AV appeared first on Cyber Security News.
Submit #637413: Jinhe OA V1.0 SQL Injection [Accepted]
Google и Zed запускают ACP, чтобы освободить ИИ-агентов от монополии VS Code
CVE-2024-13987 | Synology RADIUS Server prior 3.0.27-0139 cross site scripting (SA_25_10)
Submit #637297: Prain 1.3.3 code injection [Duplicate]
Submit #637292: PHP Directory Management System V2.0 SQL Injection [Duplicate]
诚邀渠道合作伙伴共启新征程
【火绒安全周报】抖音曝光“字节跳动”等多款山寨App/5万余条学生个人信息遭非法倒卖
2025数博会 | 中国电信安全:构建多层次立体化大模型安全动态防护体系
报告发布:2025中国数字安全价值图谱(8月)更新
Rage Against the Authentication State Machine
Nx Packages With Millions of Weekly Downloads Hacked With Credential Stealer Malware
A sophisticated supply chain attack has compromised the popular Nx build platform, affecting millions of weekly downloads and resulting in widespread credential theft. The attack, dubbed “s1ngularity,” represents one of the most comprehensive credential harvesting campaigns targeting the developer ecosystem in 2025. GitGuardian observed that malicious actors infiltrated multiple Nx package versions (20.9.0 through 21.8.0) […]
The post Nx Packages With Millions of Weekly Downloads Hacked With Credential Stealer Malware appeared first on Cyber Security News.