Aggregator
CVE-2025-7268 | CADImage Plugin on IrfanView DXF File Parser out-of-bounds
CVE-2025-7267 | CADImage Plugin on IrfanView DXF File Parser out-of-bounds
3500 个网站遭劫持!黑客利用隐匿 JS 与 WebSocket 手段暗中挖掘加密货币
3500 个网站遭劫持!黑客利用隐匿 JS 与 WebSocket 手段暗中挖掘加密货币
DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools
A sophisticated new phishing campaign has emerged, delivering the DeerStealer malware through weaponized .LNK shortcut files that exploit legitimate Windows binaries in a technique known as “Living off the Land” (LOLBin). The malware masquerades as a legitimate PDF document named “Report.lnk” while covertly executing a complex multi-stage attack chain that leverages mshta.exe, a legitimate Microsoft […]
The post DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools appeared first on Cyber Security News.
虚拟支付卡野卡(WildCard)发布新公告暂停充值/提现/注册配合相关调查
EncryptHub’s New Web3 Attack: Fake AI Platforms Deploy Fickle Stealer to Rob Crypto Devs
The hacking collective known as EncryptHub—also tracked as LARVA-208 and Water Gamayun—has launched a new wave of attacks specifically targeting developers within the Web3 ecosystem. Their aim: to infect victims with data-stealing malware capable...
The post EncryptHub’s New Web3 Attack: Fake AI Platforms Deploy Fickle Stealer to Rob Crypto Devs appeared first on Penetration Testing Tools.
伊朗黑客利用安卓恶意软件 DCHSpy 伪装成 VPN,监控目标人士
伊朗黑客利用安卓恶意软件 DCHSpy 伪装成 VPN,监控目标人士
FIDO2 Bypass Uncovered: Hackers Exploit Cross-Device Authentication with QR Code Phishing
Cybercriminals affiliated with the group PoisonSeed have devised a method to circumvent FIDO2 protection—not by breaching the technology itself, but by cleverly exploiting one of its legitimate features: cross-device authentication. Through this technique, attackers...
The post FIDO2 Bypass Uncovered: Hackers Exploit Cross-Device Authentication with QR Code Phishing appeared first on Penetration Testing Tools.
Massistant: China’s New Mobile Forensics Tool Harvests Data from Seized Devices
The Chinese firm SDIC Intelligence Xiamen Information Co., Ltd. (formerly Meiya Pico), renowned for its work in digital forensics and information security technologies, has developed a mobile tool named Massistant for data extraction from...
The post Massistant: China’s New Mobile Forensics Tool Harvests Data from Seized Devices appeared first on Penetration Testing Tools.