Aggregator
CISA Warns of Chinese Hackers Exploiting SharePoint 0-Day Flaws in Active Exploitation
CISA has issued an urgent alert regarding active exploitation of critical Microsoft SharePoint vulnerabilities by suspected Chinese threat actors. The attack campaign, dubbed “ToolShell,” leverages a vulnerability chain involving CVE-2025-49706 (network spoofing) and CVE-2025-49704 (remote code execution) to gain unauthorized access to on-premises SharePoint servers. The sophisticated attack enables malicious actors to achieve both unauthenticated […]
The post CISA Warns of Chinese Hackers Exploiting SharePoint 0-Day Flaws in Active Exploitation appeared first on Cyber Security News.
英国政府计划禁止公共和关基企业支付勒索赎金
Chrome 多个高危漏洞可用于执行任意代码
2300 доменов сожжены — но ядро устояло. Lumma вернулась: злее, тише, опаснее
Hackers Injected Malicious Firefox Browser Packages to Arch Linux User Repository
Security researchers discovered that threat actors had uploaded three corrupted browser packages, firefox-patch-bin, librewolf-fix-bin, and zen-browser-patched-bin, to the Arch User Repository (AUR). These packages appeared to be benign forks of popular Firefox-based browsers but secretly installed a Remote Access Trojan (RAT) by pulling and executing a script from a malicious GitHub repository. The Arch Linux […]
The post Hackers Injected Malicious Firefox Browser Packages to Arch Linux User Repository appeared first on Cyber Security News.
Clorox Sues IT Service Provider Cognizant for Causing 2023 Cyber-Attack
Microsoft fixes bug behind incorrect Windows Firewall errors
国际慈善组织遭勒索攻击,被索要超1500万元赎金
网络战破坏金融稳定!伊朗两家主要银行数据遭擦除
10%-25% 的肺癌患者从未吸烟
关键信息基础设施密码应用要求
С 2021 года хакеры доят Мексику как дойную корову — и никто не может их остановить
猎影计划:从密流中捕获 Cobalt Strike 的隐秘身影
APT-C-06(DarkHotel)利用恶意软件为诱饵的攻击活动
Phishing campaign targets U.S. Department of Education’s G5 portal
A new phishing campaign is targeting users of the U.S. Department of Education’s G5 portal, a site used by educational institutions and vendors to manage grants and federal education funding. Threat researchers at BforeAI uncovered a cluster of lookalike domains designed to steal user credentials by mimicking the official G5.gov login page. Cloned version of the G5 portal (Source: BforeAI) The attack uses deceptive domains like g5parameters.com and g4parameters.com, among others, that copy the visual … More →
The post Phishing campaign targets U.S. Department of Education’s G5 portal appeared first on Help Net Security.