Aggregator
Critical CrushFTP vulnerability exploited. Have you been targeted? (CVE-2025-54309)
Unknown attackers have exploited a vulnerability (CVE-2025‑54309) in the CrushFTP enterprise file-transfer server solution to gain administrative access to vulnerable deployments. It’s currently unclear what the attackers are using this access for, but data theft looks most likely. According to the Shadowserver Foundation, there are currently around 1,040 exposed and unpatched CrushFTP instances vulnerable to CVE-2025-54309, predominantly located in the US, Europe, and Canada. How many have been compromised since the attacks began is difficult … More →
The post Critical CrushFTP vulnerability exploited. Have you been targeted? (CVE-2025-54309) appeared first on Help Net Security.
Attackers Exploit Zero-Day Flaws in On-Premises SharePoint
Hackers have been exploiting two zero-day vulnerabilities in on-premises installations of Microsoft SharePoint to gain remote access, and steal cryptographic keys and data. As Microsoft rolls out patches against "ToolShell," experts warn administrators to also rotate keys, to help eject attackers.
PHP PDO Flaw Allows Attackers to Inject Malicious SQL Commands
A critical vulnerability in PHP’s widely-used PDO (PHP Data Objects) library has been discovered that enables attackers to inject malicious SQL commands even when developers implement prepared statements correctly. The security flaw, revealed through analysis of a DownUnderCTF capture-the-flag challenge, exploits weaknesses in PDO’s SQL parser and affects millions of web applications worldwide. Technical Overview […]
The post PHP PDO Flaw Allows Attackers to Inject Malicious SQL Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CISA Warns of Microsoft SharePoint Server 0-Day RCE Vulnerability Exploited in Wild
CISA has issued an urgent warning about a critical zero-day remote code execution vulnerability affecting Microsoft SharePoint Server on-premises installations that threat actors are actively exploiting in the wild. The vulnerability, tracked as CVE-2025-53770, poses a significant security risk to organizations running SharePoint infrastructure and has prompted immediate action requirements from federal agencies, as well […]
The post CISA Warns of Microsoft SharePoint Server 0-Day RCE Vulnerability Exploited in Wild appeared first on Cyber Security News.
Думали, искусство — это про душу? Робот нарисовал короля лучше человека
Lighthouse Studio RCE Vulnerability Let Attackers Gain Access to Hosting Servers
A critical remote code execution vulnerability has been discovered in Lighthouse Studio, one of the most widely deployed yet relatively unknown survey software platforms developed by Sawtooth Software. The flaw, designated CVE-2025-34300, affects the Perl CGI scripts that power web-based surveys, potentially exposing thousands of hosting servers to complete compromise by attackers who possess nothing […]
The post Lighthouse Studio RCE Vulnerability Let Attackers Gain Access to Hosting Servers appeared first on Cyber Security News.
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and More
智元、宇树扎堆上市,半年 300 亿融资背后,机器人赛道「太火了」?
Over 1,000 CrushFTP servers exposed to ongoing hijack attacks
Microsoft Confirms Hackers Exploiting SharePoint Flaws, Patch Now
The Overlooked Risk in AI Infrastructure: Physical Security
As artificial intelligence (AI) accelerates across industries from financial modeling and autonomous vehicles to medical imaging and logistics optimization, one issue consistently flies under the radar: Physical security.
The post The Overlooked Risk in AI Infrastructure: Physical Security appeared first on Security Boulevard.
Livewire Vulnerability Exposes Millions of Laravel Apps to Remote Code Execution Attacks
A critical security vulnerability in Laravel’s Livewire framework has been discovered that could expose millions of web applications to remote code execution (RCE) attacks. The flaw, designated as CVE-2025-54068, affects Livewire v3 versions from 3.0.0-beta.1 through 3.6.3, with a CVSS v4 score indicating high severity across confidentiality, integrity, and availability metrics. The vulnerability originates from […]
The post Livewire Vulnerability Exposes Millions of Laravel Apps to Remote Code Execution Attacks appeared first on Cyber Security News.
Max не звонит, но мошенники «от Max» работают в три смены
Assessing the Role of AI in Zero Trust
Microsoft issues emergency patches for SharePoint zero-days exploited in “ToolShell” attacks
New KAWA4096’s Ransomware Leverages Windows Management Instrumentation to Delete Shadow Copies
A sophisticated new ransomware strain named KAWA4096 has emerged in the cybersecurity landscape, showcasing advanced evasion techniques and borrowing design elements from established threat actors. Named after the Japanese word for “river,” this malicious software first surfaced in June 2025 and has already claimed at least 11 victims across multiple regions, with the United States […]
The post New KAWA4096’s Ransomware Leverages Windows Management Instrumentation to Delete Shadow Copies appeared first on Cyber Security News.
Surveillance Firm Exploits SS7 Flaw to Track User Locations
A sophisticated surveillance operation has been discovered exploiting critical vulnerabilities in the global telecommunications infrastructure to track mobile phone users’ locations without authorization, security researchers have revealed. The attack leverages weaknesses in the decades-old SS7 (Signaling System No. 7) protocol that underpins international cellular networks. New Attack Method Discovered Security experts at Enea’s Threat Intelligence […]
The post Surveillance Firm Exploits SS7 Flaw to Track User Locations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.