Aggregator
CVE-2022-45305 | Chocolatey Package up to 3.11.0 on Python C:\Python311 permission
CVE-2022-45304 | Chocolatey Cmder Package up to 1.3.20 C:\tools\Cmder permission
CVE-2022-45306 | Chocolatey Azure-Pipelines-Agent Package up to 2.211.1 C:\agent permission
CVE-2022-36136 | ChurchCRM 4.4.5 Deposit Comment cross site scripting
CVE-2022-44937 | Wenzhou Huoyin BossCMS 2.0.0 Administrator List Module Add cross-site request forgery
“Power Parasites” Phishing Campaign Targets Energy Firms and Major Brands
Silent Push Threat Analysts have uncovered a widespread phishing and scam operation dubbed “Power Parasites,” targeting prominent energy companies and major global brands across multiple sectors in 2024. This campaign, active primarily in Asian countries such as Bangladesh, Nepal, and India, leverages a sophisticated network of deceptive websites, social media platforms, and Telegram channels to […]
The post “Power Parasites” Phishing Campaign Targets Energy Firms and Major Brands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Threat Actors Register Over 26,000 Domains Imitating Brands to Deceive Users
Researchers from Unit 42 have uncovered a massive wave of SMS phishing, or “smishing,” activity targeting unsuspecting users. Since the FBI’s initial warning in April 2024, over 91,500 root domains associated with smishing have been identified and blocked. However, the momentum of this malicious activity has intensified in 2025, with a staggering peak of 26,328 […]
The post Threat Actors Register Over 26,000 Domains Imitating Brands to Deceive Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Threat Actors Registered 26k+ Domains Mimic Brands to Trick Users
In a significant escalation of digital deception tactics, threat actors have registered over 26,000 domains in March 2025 alone, designed to impersonate legitimate brands and government services. These malicious domains serve as landing pages for sophisticated smishing (SMS phishing) campaigns, where unsuspecting users receive text messages containing links to what appear to be legitimate services. […]
The post Threat Actors Registered 26k+ Domains Mimic Brands to Trick Users appeared first on Cyber Security News.
Торвальдс опять разнёс всех: когда имя файла вдруг становится уязвимостью, это уже диагноз, а не фича
Russian Hackers Attempt to Sabotage Digital Control Systems of Dutch Public Service
The Dutch Defense Ministry has revealed that critical infrastructure, democratic processes, and North Sea installations in the Netherlands have become focal points for Russian cyber operations. These attacks, identified as part of a coordinated strategy to destabilize social cohesion and compromise national security across Europe, underscore a growing digital threat landscape. A specific incident in […]
The post Russian Hackers Attempt to Sabotage Digital Control Systems of Dutch Public Service appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Lynx
Lynx
North Korean APT Hackers Pose as Companies to Spread Malware to Job Seekers
Silent Push Threat Analysts have uncovered a chilling new cyberattack campaign orchestrated by the North Korean Advanced Persistent Threat (APT) group known as Contagious Interview, also referred to as Famous Chollima, a subgroup of the notorious Lazarus group. This state-sponsored entity has been implicated in numerous sophisticated cyber-espionage efforts targeting global industries, with a particular […]
The post North Korean APT Hackers Pose as Companies to Spread Malware to Job Seekers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
North Korean Hackers Exploit GenAI to Land Remote Jobs Worldwide
A groundbreaking report from Okta Threat Intelligence reveals how operatives linked to the Democratic People’s Republic of Korea (DPRK), often referred to as North Korean hackers, are leveraging Generative Artificial Intelligence (GenAI) to infiltrate remote technical roles across the globe. These sophisticated campaigns, dubbed “DPRK IT Workers” or “Wagemole” operations, utilize advanced AI tools to […]
The post North Korean Hackers Exploit GenAI to Land Remote Jobs Worldwide appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
20 Common Ports You Must Know
Threat Actors Target Organizations in Thailand with Ransomware Attacks
Thailand is experiencing a significant escalation in ransomware attacks, with both state-sponsored advanced persistent threat (APT) groups and cybercriminal organizations zeroing in on key industries across the country. The surge is underpinned by Thailand’s position as a burgeoning financial hub in Southeast Asia, its strategic geopolitical alliances, rapid digital transformation, and its critical role in […]
The post Threat Actors Target Organizations in Thailand with Ransomware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
WooCommerce Users Targeted by Fake Security Vulnerability Alerts
A concerning large-scale phishing campaign targeting WooCommerce users has been uncovered by the Patchstack securpity team, employing a highly sophisticated email and web-based phishing template to deceive website owners. The attackers behind this operation warn users of a fabricated “Unauthenticated Administrative Access” vulnerability in their WooCommerce installations, urging them to download a supposed patch from […]
The post WooCommerce Users Targeted by Fake Security Vulnerability Alerts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Microsoft Edge security advisory (AV25-233)
ISMG Editors: Top 2025 Breach Trends From Verizon
In this week's update, ISMG editors discussed takeaways from Verizon's annual Data Breach Investigations Report, the cybersecurity ripple effects of the disruptive U.S. tariff policy, and why artificial intelligence tools still aren't ready to take over the security operations center.