Aggregator
Submit #621977: Tenda AC18 V15.03.05.19 Misconfiguration [Accepted]
Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations
A sophisticated espionage campaign dubbed “Fire Ant” demonstrates previously unknown capabilities in compromising VMware virtualization infrastructure. Since early 2025, this threat actor has systematically targeted VMware ESXi hosts, vCenter servers, and network appliances using hypervisor-level techniques that evade traditional endpoint security solutions. The campaign exhibits strong technical overlap with the previously identified UNC3886 threat group, […]
The post Fire Ant Hackers Exploiting Vulnerabilities in VMware ESXi and vCenter to Infiltrate Organizations appeared first on Cyber Security News.
CVE-2025-8181 | TOTOLINK N600R/X2000R 1.0.0.1 FTP Service vsftpd.conf least privilege violation
Firefox 141 Released with Patches for 18 Vulnerabilities, Including High-Severity RCE Flaws
On July 22, 2025, Mozilla unveiled the Firefox 141 update, a release focused on enhancing browser security. According to security bulletin MFSA 2025-56, the update addresses 18 vulnerabilities, including flaws in the JavaScript engine,...
The post Firefox 141 Released with Patches for 18 Vulnerabilities, Including High-Severity RCE Flaws appeared first on Penetration Testing Tools.
CVE-2025-8180 | Tenda CH22 1.0.0.1 /goform/deleteUserName formdeleteUserName old_account buffer overflow
Submit #621968: TOTOLINK X2000R V1.0.0 Misconfiguration [Duplicate]
CVE-2025-8179 | PHPGurukul Local Services Search Engine Management System 2.1 /admin/changeimage.php editid sql injection
Submit #621966: TOTOLINK N600R V4.3.0 Misconfiguration [Accepted]
Submit #621964: Tenda CH22 V1.0.0.1 Buffer overflow vulnerability [Accepted]
New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer
A newly uncovered campaign is exploiting gamers’ enthusiasm for off-beat indie titles to plant credential-stealing malware on machines. Branded installers for nonexistent games such as “Baruda Quest,” “Warstorm Fire,” and “Dire Talon” are pushed through slick YouTube trailers and Discord download links that imitate legitimate early-access promotions. The lures contain Electron-based executables weighing 80 MB […]
The post New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer appeared first on Cyber Security News.