Aggregator
CVE-2024-50083 | Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4 request_sock_subflow_v4 net/mptcp/protocol.c denial of service (Nessus ID 212953 / WID-SEC-2024-3289)
Russian Espionage Group Static Tundra Targets Legacy Cisco Flaw
Florida man gets 10 years in prison in first Scattered Spider sentencing
Noah Urban’s sentence stems from a broader conspiracy involving four other defendants who conducted attacks from September 2021 to April 2023.
The post Florida man gets 10 years in prison in first Scattered Spider sentencing appeared first on CyberScoop.
Alleged Sale of RDWeb Access to an Unidentified Software Company in USA
Warlock Ransomware Exploiting SharePoint Vulnerabilities to Gain Access and Steal Credentials
In recent weeks, the cybersecurity community has witnessed the rapid emergence of Warlock, a novel ransomware strain that weaponizes unpatched Microsoft SharePoint servers to infiltrate enterprise networks. Initial analysis reveals that threat actors exploit publicly exposed SharePoint instances via specially crafted HTTP POST requests, deploying web shells that grant remote code execution within the target […]
The post Warlock Ransomware Exploiting SharePoint Vulnerabilities to Gain Access and Steal Credentials appeared first on Cyber Security News.
CIS Controls Ambassador Spotlight: Eric Woodard
CIS Controls Ambassador Spotlight: Eric Woodard
Prepping the Front Line for MFA Social Engineering Attacks
‘Rapper Bot’ hit the Pentagon in at least 3 cyberattacks
The post ‘Rapper Bot’ hit the Pentagon in at least 3 cyberattacks appeared first on CyberScoop.
Why Certified VMware Pros Are Driving the Future of IT
Internet Archive Abused for Hosting Stealthy JScript Loader Malware
Security researchers have uncovered a novel malware delivery chain in recent weeks that leverages the Internet Archive’s legitimate infrastructure to host obfuscated payloads. The attack begins with a seemingly innocuous JScript file delivered via malspam, which in turn invokes a PowerShell loader. This PowerShell script reaches out to the Internet Archive (archive.org) to retrieve a […]
The post Internet Archive Abused for Hosting Stealthy JScript Loader Malware appeared first on Cyber Security News.
Mozilla High Severity Vulnerabilities Enables Remote Code Execution
Mozilla has released Firefox 142 to address multiple high-severity security vulnerabilities that could allow attackers to execute arbitrary code remotely on affected systems. The security advisory, published on August 19, 2025, reveals nine distinct vulnerabilities ranging from sandbox escapes to memory safety bugs, with several classified as high-impact threats capable of enabling remote code execution […]
The post Mozilla High Severity Vulnerabilities Enables Remote Code Execution appeared first on Cyber Security News.
微软表示正在调查与安全更新相关的硬盘故障问题
CVE-2024-27349 | Apache HugeGraph-Server up to 1.2.x RESTful-API authentication spoofing (EUVD-2024-1128)
CVE-2024-32741 | Siemens SIMATIC CN 4100 up to 2.x GRUB hard-coded password (ssa-273900)
CVE-2025-8023 | Mattermost up to 9.11.17/10.5.8/10.8.3/10.9.2 path traversal (EUVD-2025-25412 / WID-SEC-2025-1625)
CVE-2025-25005 | Microsoft Exchange Server information disclosure (Nessus ID 249140)
Tailing Hackers, Columbia University Uses Logging to Improve Security
FBI Warns Russian State Hackers Targeting Critical Infrastructure Networking Devices
The Federal Bureau of Investigation (FBI) has issued a stark warning to the public, private sector, and international partners regarding persistent cyber threats from actors affiliated with the Russian Federal Security Service’s (FSB) Center 16. This unit, recognized in cybersecurity circles under monikers such as “Berserk Bear” and “Dragonfly,” has been actively exploiting vulnerabilities in […]
The post FBI Warns Russian State Hackers Targeting Critical Infrastructure Networking Devices appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.