Aggregator
CVE-2024-11276 | edgarrojas PDF Builder for WooCommerce Plugin up to 1.2.136 on WordPress page cross site scripting
CVE-2024-11687 | martinnguyen1990 Next-Cart Store to WooCommerce Migration Plugin up to 3.9.2 on WordPress page cross site scripting
Cisco Confirms Salt Typhoon Exploitation in Telecom Hits
CVE-2007-3624 | SAP Message Server group heap-based overflow (VU#305657 / EDB-30265)
CVE-2025-0111 | Palo Alto Cloud NGFW/PAN-OS/Prisma Access Management Web Interface file inclusion
CVE-2024-13622 | imagisol File Uploads Addon for WooCommerce Plugin up to 1.7.1 on WordPress /wp-content/uploads information disclosure
Leaked Black Basta Chat Logs Show Banality of Ransomware
Two hundred thousand internal chat messages from the Russian ransomware group Black Basta have been leaked online, supposedly in reprisal for the operation targeting Russian banks. The partial logs, spanning 13 months, detail negotiations with victims, ransoms paid, internal disagreements and more.
Apple Withdraws Strong Encryption Feature for All UK Users
Amidst the ever-rising tide of cyberattacks and data breaches, Apple is deactivating a key data security feature for all U.K. users, rather than accede to a reported demand from the British government that the technology giant give it on-demand backdoor access to any user's data in the world.
OSINT GPT: An open-source intelligence (OSINT) analysis tool leveraging GPT-powered embeddings and vector search engines for efficient data processing
SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix
In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer overflow vulnerability CVE-2025-0282 in Ivanti Connect Secure, as confirmed by JPCERT/CC. This vulnerability, disclosed in January 2025, had already been actively exploited since late December 2024, prior to its public announcement. The malware, an evolved variant of the SPAWN family, integrates […]
The post SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key
A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing attackers to extract private keys used for signing SAML authentication requests. The flaw, tracked as CVE-2022-35202, stems from the use of a Java keystore accessible via WebDAV and protected by an auto-generated, low-complexity password. This vulnerability could potentially enable attackers to […]
The post Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
NSA Allegedly Hacked Northwestern Polytechnical University, China Claims
Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a cyberattack on Northwestern Polytechnical University, a prominent Chinese institution specializing in aerospace and defense research. The allegations, published by organizations such as Qihoo 360 and the National Computer Virus Emergency Response Center (CVERC), claim that the NSA’s Tailored Access Operations (TAO) […]
The post NSA Allegedly Hacked Northwestern Polytechnical University, China Claims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials
The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens, has seen a significant increase in its distribution since the beginning of 2025. Initially distributed in limited volumes in mid-2024, this malware has now gained traction, with February’s activity levels matching those of January, signaling a sharp upward trend. Security researchers […]
The post ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.