Aggregator
CVE-2025-65501 | obgm libcoap 4.3.5 DTLS Handshake coap_dtls_info_callback null pointer dereference (Nessus ID 276683)
CVE-2025-54956 | r-lib gh up to 1.4.x Header Authorization resource transfer (Issue 222 / EUVD-2025-23481)
INC
You must login to view this content
Akira
You must login to view this content
Code beautifiers expose credentials from banks, govt, tech orgs
Code-formatters expose thousands of secrets from banks, govt, tech orgs
Four Ways AI Is Being Used to Strengthen Democracies Worldwide
CISA Releases Seven Industrial Control Systems Advisories
CISA released seven Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-329-01 Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share
- ICSA-25-329-02 Rockwell Automation Arena Simulation
- ICSA-25-329-03 Zenitel TCIV-3+
- ICSA-25-329-04 Opto 22 groov View
- ICSA-25-329-05 Festo Compact Vision System, Control Block, Controller, and Operator Unit products
- ICSA-25-329-06 SiRcom SMART Alert (SiSA)
- ICSA-22-333-05 Mitsubishi Electric FA Engineering Software (Update C)
CISA encourages users and administrators to review newly released ICS Advisories for technical details and mitigations.
«Пушистый волк» и акты сверки. Как старый хакер VasyGrek кошмарит российских бухгалтеров в 2025 году
Fake “Windows Update” screens fuels new wave of ClickFix attacks
A convincing (but fake) “Windows Update” screen can be the perfect lure for tricking users into infecting their computers with malware. Add a multi-stage delivery chain with some offbeat techniques, and infostealer operators have everything they need to slip past defenses. The malware delivery campaigns “Since the beginning of October, Huntress has identified multiple ClickFix lure sites that trick victims into running a malicious command, following a consistent format and leading to a unique execution … More →
The post Fake “Windows Update” screens fuels new wave of ClickFix attacks appeared first on Help Net Security.
12月6日专题会议 | 网络空间态势感知
Threat Actors Exploiting Black Friday Shopping Hype – 2+ Million Attacks Recorded
The 2025 Black Friday shopping season has become a prime hunting ground for cybercriminals, with threat actors recording over 2 million phishing attacks targeting online gamers and shoppers worldwide. As global e-commerce continues to grow at 7-9% annually, attackers have adapted their tactics to exploit the seasonal rush, reduced user vigilance, and high-demand retail periods. […]
The post Threat Actors Exploiting Black Friday Shopping Hype – 2+ Million Attacks Recorded appeared first on Cyber Security News.