Aggregator
CVE-2025-10718 | Ooma Office Business Phone App up to 7.2.2 on Android com.ooma.office2 improper export of android application components
New Malware Loader ‘CountLoader’ Weaponized PDF File to Deliver Ransomware
In recent months, security teams have observed the emergence of a sophisticated malware loader, dubbed CountLoader, which leverages weaponized PDF files to deliver ransomware payloads. First detected in late August 2025, CountLoader is linked to multiple Russian-speaking cybercriminal groups, including affiliates of LockBit, BlackBasta, and Qilin. By masquerading as legitimate documents—often impersonating Ukrainian law enforcement—this […]
The post New Malware Loader ‘CountLoader’ Weaponized PDF File to Deliver Ransomware appeared first on Cyber Security News.
CVE-2025-10717 | intsig CamScanner App 6.91.1.5.250711 on Android com.intsig.camscanner AndroidManifest.xml improper export of android application components
Submit #645012: Ooma Ooma Office 7.2.2 Task Hijacking [Accepted]
CVE-2025-10647 | Embed PDF for WPForms Plugin up to 1.1.5 on WordPress ajax_handler_download_pdf_media unrestricted upload
Submit #645010: INTSIG PTE CamScanner 6.91.1.5.2507110000 Task Hijacking [Accepted]
Steam 将从 2026 年起不再支持 32 位 Windows 操作系统
CVE-2023-53207 | Linux Kernel up to 6.1.42/6.4.7 ublk ublk_ctrl_end_recovery denial of service (Nessus ID 265235)
CVE-2023-53219 | Linux Kernel up to 6.3.3 media del_timer use after free (Nessus ID 265234)
CVE-2023-53222 | Linux Kernel up to 6.4.4 jfs jfs_dmap.c dbFree out-of-bounds (Nessus ID 265237)
CVE-2022-50270 | Linux Kernel up to 6.0.15/6.1.1 f2fs f2fs_direct_IO_enter privilege escalation (Nessus ID 265238 / WID-SEC-2025-2053)
CVE-2022-50294 | Linux Kernel up to 6.2.2 wifi lbs_init_adapter memory leak (Nessus ID 265239 / WID-SEC-2025-2053)
ОС для невидимок: Tails 7.0 ускорилась и усилила анонимность в Tor
WatchGuard Issues Fix for 9.3-Rated Firebox Firewall Vulnerability
新材料拉伸率达到 46 倍且能自我修复
CVE-2025-59358
CISA Alerts of Hackers Targeting Ivanti Endpoint Manager Mobile Vulnerabilities to Distribute Malware
Cyber threat actors have weaponized two critical Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities—CVE-2025-4427 and CVE-2025-4428—to deploy sophisticated malicious loaders and listeners on compromised servers. The malware consists of two sets of components: Loader 1 (web-install.jar, ReflectUtil.class, SecurityHandlerWanListener.class) and Loader 2 (web-install.jar, WebAndroidAppInstaller.class), both designed to inject arbitrary code and maintain persistence on Apache Tomcat deployments. […]
The post CISA Alerts of Hackers Targeting Ivanti Endpoint Manager Mobile Vulnerabilities to Distribute Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
专访英国国家网络部队指挥官,网络战是心理战
Qilin Led Ransomware Attack Claimed to Compromised 104 Organizations in August
The ransomware threat landscape witnessed a dramatic shift in August 2025 as the Qilin group claimed responsibility for 104 separate attacks worldwide. Emerging earlier this year, Qilin quickly cemented its position through aggressive double-extortion tactics and a broad affiliate recruitment strategy. Initial compromises have predominantly leveraged exposed Remote Desktop Protocol (RDP) servers and publicly facing […]
The post Qilin Led Ransomware Attack Claimed to Compromised 104 Organizations in August appeared first on Cyber Security News.