Aggregator
CVE-2025-71325 | picklescan up to 0.0.26 _list_globals error condition
CVE-2025-71322 | PickleScan up to 0.0.32 pty.spawn protection mechanism
CVE-2025-32748 | Dell PowerFlex rack 3.7 Header Host redirect
CVE-2026-12515 | Red Hat Hardened Images/Satellite 6 authorization
CVE-2025-71321 | picklescan up to 0.0.32 deserialization
CVE-2025-71323 | picklescan up to 0.0.32 Ctypes kernel32.dll incomplete blacklist
CVE-2025-71320 | picklescan up to 0.0.32 incomplete blacklist
SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies
Austin, TX, USA, June 17th, 2026, CyberNewswire New SpyCloud research highlights the expansion of phishing attacks as AI and phishing-as-a-service fuel enterprise targeting. SpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enterprise organizations as artificial intelligence […]
The post SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies appeared first on Cyber Security News.
URL Phishing Is Draining SOCs, How to Cut Triage Time and Catch Incidents Early
URL phishing is becoming harder to triage at scale. Suspicious links can hide behind redirects, fresh domains, and browser-side changes that basic URL checks often miss. For analysts, that means more time spent rebuilding what the page actually does before they can make a clear decision. To respond faster, SOC teams need browser-level visibility: what the page loads, […]
The post URL Phishing Is Draining SOCs, How to Cut Triage Time and Catch Incidents Early appeared first on Cyber Security News.
27-Year-Old OpenBSD Vulnerability Allows Attackers to Bypass PAP Authentication Entirely
A long-standing vulnerability in OpenBSD’s networking stack has been disclosed, revealing that attackers can bypass PAP authentication entirely due to a decades-old logic flaw. The issue resides in the sppp_pap_input() function within OpenBSD’s sppp(4) subsystem, which manages synchronous PPP links used in PPPoE connectivity. During the PPP authentication phase, systems relying on the Password Authentication Protocol (PAP) validate user […]
The post 27-Year-Old OpenBSD Vulnerability Allows Attackers to Bypass PAP Authentication Entirely appeared first on Cyber Security News.
Hackers Use ClickFix Prompt to Install MSI Package and Launch Hands-On-Keyboard Attack
A single deceptive prompt. That is all it took for attackers to gain a foothold inside an organization, spread to over 11 systems, and deploy two separate remote access tools before anyone noticed. A new campaign using the ClickFix technique has shown how far one unguarded moment can go. ClickFix is a social engineering trick […]
The post Hackers Use ClickFix Prompt to Install MSI Package and Launch Hands-On-Keyboard Attack appeared first on Cyber Security News.
FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries
EU grants Ukraine access to cybersecurity reserve for major attacks
Третья мировая война, культ и ядерная энергетика. О чём говорят за закрытыми дверями богатейшие люди мира
The dual-use dilemma: Rethinking detection for remote access tool abuse
Hackers Use Fake Software Update Prompts to Steal Passwords and Crypto Wallet Data From macOS Users
A dangerous new cyber campaign is putting macOS users at serious risk, and it does not rely on software bugs to do its damage. Instead, the attackers trick people into handing over their own passwords and sensitive data by making everything look completely normal. What appears to be a routine software update turns out to […]
The post Hackers Use Fake Software Update Prompts to Steal Passwords and Crypto Wallet Data From macOS Users appeared first on Cyber Security News.