Aggregator
CVE-2025-48462 | Advantech Wireless Sensing and Equipment A2.01 B00 resource consumption (EUVD-2025-18988)
CVE-2025-47943 | Gogs up to 0.14.0+dev public/plugins/ cross site scripting (GHSA-xh32-cx6c-cp4v / EUVD-2025-18995)
CVE-2025-6560 | Sapido BR071n credentials storage (EUVD-2025-19052)
CVE-2025-6559 | Sapido BR071n os command injection (EUVD-2025-19048)
CVE-2025-52560 | Kanboard up to 1.2.45 Password Reset password recovery (GHSA-2ch5-gqjm-8p92 / EUVD-2025-18976)
CVE-2025-48463 | Advantech Wireless Sensing and Equipment A2.01 B00 cleartext transmission (EUVD-2025-18987)
CVE-2025-6552 | java-aodeng Hope-Boot 1.0.0 Login WebController.java doLogin redirect_url (EUVD-2025-19051)
CVE-2025-52570 | mbuesch letmein up to 10.2.0 letmeind/letmeinfwd improper control of interaction frequency (GHSA-jpv7-p47h-f43j / EUVD-2025-19032)
Next‑AEO Helps LLMs Find You—Because Google Isn’t the Only Search Engine Anymore
Ongoing Campaign Abuses Microsoft 365’s Direct Send to Deliver Phishing Emails
Kansas City Man Pleads Guilty After Hacking to Promote His Cybersecurity Services
A Kansas City man has pleaded guilty to federal charges after admitting he hacked into the computer systems of multiple organizations in an attempt to promote his cybersecurity services, according to the U.S. Department of Justice. Nicholas Michael Kloster, 32, was indicted last year after a series of unauthorized intrusions targeting three separate organizations in […]
The post Kansas City Man Pleads Guilty After Hacking to Promote His Cybersecurity Services appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
We know GenAI is risky, so why aren’t we fixing its flaws?
Even though GenAI threats are a top concern for both security teams and leadership, the current level of testing and remediation for LLM and AI-powered applications isn’t keeping up with the risks, according to Cobalt. GenAl as a threat or a tool (Source: Cobalt) Pentest data reveals industry divide in LLM security Pentesting data from the report highlights a troubling reality: LLM applications often have serious security vulnerabilities. These high-risk issues appear more frequently in … More →
The post We know GenAI is risky, so why aren’t we fixing its flaws? appeared first on Help Net Security.
小米 AI 眼镜首发体验:对于国内用户,这可能是更好的 Meta Ray-Ban
小米 AI 眼镜首发体验:对于国内用户,这可能是更好的 Meta Ray-Ban
CVE-2019-6693
在被欧盟罚款5亿欧元后苹果修改开发者政策 不限外部购买但费率更加复杂
Infosec products of the month: June 2025
Here’s a look at the most interesting products from the past month, featuring releases from: Akamai, AttackIQ, Barracuda Networks, BigID, Bitdefender, Contrast Security, Cymulate, Dashlane, Embed Security, Fortanix, Fortinet, Jumio, Lemony, Malwarebytes, SpecterOps, StackHawk, Stellar Cyber, Sumsub, Thales, Tines, Vanta, and Varonis. Bitdefender unifies security, risk management, and compliance in a single platform Bitdefender announced GravityZone Compliance Manager, a new addition to its GravityZone platform that helps organizations reduce the burden of compliance and streamline … More →
The post Infosec products of the month: June 2025 appeared first on Help Net Security.
BreachForums黑客论坛运营者在法国被捕
BreachForums黑客论坛运营者在法国被捕
据报道,法国警方逮捕了网络犯罪论坛BreachForum的五名运营者,该网站被网络犯罪分子用来泄露和出售被盗数据,暴露超数百万人的敏感信息。此次执法行动是由巴黎警察局网络犯罪部门(BL2C)于周一实施的。
在这次行动中,他们共逮捕了四名黑客,他们的网名分别是“ShinyHunters”、“Hollow”、“Noct”和“Depressed”。
几个月以来,有传言说另一个著名的威胁者“IntelBroker”也被捕了。据证实,IntelBroker已于2025年2月被法国当局逮捕。
多年来,BreachForums黑客论坛经历了无数次的迭代,但作为网络犯罪分子交易、出售和泄露被盗数据的社区,以及出售进入企业网络和其他非法网络犯罪服务权限的网络犯罪组织,其业务一直层出不穷。在2023年,原始的BreachForums在其运营商Conor Brian FitzPatrick(即Pompompurin)被捕后关闭。
不久之后,社区中的其他威胁者推出了BreachForums v2,由ShinyHunters、Baphomet和后来的IntelBroker等威胁者领导。
据报道,被逮捕的五名威胁者均参与了该网站新版本的运营。ShinyHunters 和 IntelBroker 是该网站的管理员/所有者,存档的帖子显示Hollow作为版主。目前尚不清楚 "depressed" 和 "noct" 在网站运营中所起的作用。
这些网络犯罪分子被指控直接参与了针对法国实体的数据泄露,如Boulanger、SFR、France Travail和法国足球联合会。
尤其是针对France Travail(前身为Pôle employi)的攻击格外引人注目,因为它泄露了约4300万人的敏感信息。
IntelBroker 因其参与在欧洲刑警组织、 通用电气、Weee!、AMD、惠普、诺基亚和思科等机构的高调漏洞而闻名。该威胁者在攻破DC Health Link后进入了公众视野,DC Health Link是管理美国众议院议员及其家属的医疗保健计划的组织。
在被捕者中,ShinyHunters最为臭名昭著,因为其与多起备受瞩目的数据泄露和攻击有关,包括针对Salesforce和PowerSchool的攻击,以及影响桑坦德银行(Santander)、Ticketmaster、AT&T、Advance Auto Parts、内曼马库斯(Neiman Marcus)和Cylance的雪花攻击。
ShinyHunters威胁者在2025年也参与了大量的攻击活动,该组织由多个使用相同名称的威胁者组成。据称,该网站遭到MyBB零日漏洞的攻击,于2025年4月下线。此后,该论坛再也没有上线。