Aggregator
CVE-2025-32102
CVE-2024-29269
M8.2 级太阳耀斑引发 G4 级地磁风暴
CVE-2007-4552 | Agares Media Arcadem 2.0.1 index.php blockpage sql injection (EDB-4326 / BID-25418)
Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN
Preinstalled Android Apps Found Leaking PINs and Executing Malicious Commands
On May 30, 2025, CERT Polska coordinated the public disclosure of three significant security vulnerabilities affecting preinstalled Android applications on smartphones from Ulefone and Krüger&Matz. These flaws, tracked as CVE-2024-13915, CVE-2024-13916, and CVE-2024-13917, expose users to risks ranging from unauthorized device resets to theft of sensitive PIN codes and privilege escalation by malicious applications. Technical […]
The post Preinstalled Android Apps Found Leaking PINs and Executing Malicious Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Prioritizing Vulnerabilities in a Sea of Alerts
According to recent industry analysis, cybersecurity professionals are overwhelmed by a flood of security alerts. Organizations process an average of 569,354 alerts annually, yet only 2-5% require immediate action, highlighting the importance of prioritizing vulnerabilities. This overwhelming volume of notifications has created a critical challenge for security teams worldwide. They must now navigate massive amounts […]
The post Prioritizing Vulnerabilities in a Sea of Alerts appeared first on Cyber Security News.
New Linux Vulnerabilities Expose Password Hashes via Core Dumps
CVE-2024-28123 | Wasmi 128 Host out-of-bounds write
CVE-2023-50726 | argocd up to 2.8.11/2.9.0/2.9.7/2.10.0/2.10.2 privileges management (GHSA-g623-jcgg-mhmm)
CVE-2025-5447 | Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 /goform/ssid1MACFilter apselect_%d/newap_text_%d os command injection
Threat Actors Using ClickFix Technique to Deliver EddieStealer Malware
Cybersecurity researchers have identified a sophisticated new malware campaign leveraging the deceptive ClickFix technique to distribute EddieStealer, a dangerous information-stealing malware built using the Rust programming language. This emerging threat represents a significant evolution in social engineering tactics, exploiting user trust through fake CAPTCHA verification systems to trick victims into executing malicious commands. The attack […]
The post Threat Actors Using ClickFix Technique to Deliver EddieStealer Malware appeared first on Cyber Security News.
Ubuntu security advisory (AV25-305)
Российская игровая консоль? Уже можно пощупать
Alleged database leak of National Agency for Land Conservation, Cadastre, and Cartography (ANCFCC)
HuluCaptcha – A FakeCaptcha Kit That Trick Users to Run Code via The Windows Run Command
A new and sophisticated malware distribution framework dubbed “HuluCaptcha” has emerged, leveraging fake CAPTCHA verification pages to trick users into executing malicious PowerShell commands through Windows Run dialogs. This advanced threat represents a significant evolution in social engineering attacks, combining legitimate-looking security verification interfaces with complex multi-stage infection chains that have successfully compromised high-value targets […]
The post HuluCaptcha – A FakeCaptcha Kit That Trick Users to Run Code via The Windows Run Command appeared first on Cyber Security News.