Aggregator
CVE-2025-25994 | FeMiner wms 1.0 date1/date2/id sql injection
CVE-2025-25990 | hooskcms 1.7.1 /install/index.php cross site scripting
CVE-2025-26158 | Kashipara Online Attendance Management System 1.0 manage-employee.php department cross site scripting
CVE-2024-56463 | IBM QRadar SIEM up to 7.5.0 UP11 Web UI cross site scripting
CVE-2024-57790 | IXON IXrouter IX2400 3.0 UART/SSH hard-coded password
CVE-2024-3220 | CPython up to 3.13.x on Windows File Extension untrusted search path
制造业面临勒索软件攻击增加24%
CVE-2025-26156 | PHPGurukul Online Shopping Portal 2.1 POST Request Parameter track-orders.php orderid sql injection
CVE-2025-26157 | SourceCodester Beauty Parlour Management System 1.1 POST Request Parameter /bpms/index.php name sql injection
EarthKapre APT Drops Weaponized PDF to Compromise Windows Systems
A highly sophisticated cyber espionage group known as EarthKapre, also referred to as RedCurl, has been identified targeting private-sector organizations, particularly those in the Law Firms & Legal Services industry. The eSentire Threat Response Unit (TRU) uncovered the group’s recent activities in January 2025, revealing a complex attack chain designed for corporate espionage. Technical Analysis: […]
The post EarthKapre APT Drops Weaponized PDF to Compromise Windows Systems appeared first on Cyber Security News.
亚马逊将关闭 Kindle 的 Download & Transfer via USB 功能
CVE-2024-57778 | Orbe ONetView Roeador Onet-1200 Orbe 1680210096 Status Code privileges management
A Threat Actor Claims to be Selling a Chromium Extension and Loader
新的网络钓鱼套件超越了双重保护
Lazarus Group Using New Malware Tactic To Attack Developers Globally
The notorious Lazarus Group in a recent escalation of cyber threats linked to North Korea, has unveiled a sophisticated new tactic to target developers worldwide. This campaign, dubbed “Operation Marstech Mayhem,” involves the deployment of an advanced malware implant known as “Marstech1.” The operation marks a significant evolution in the group’s supply chain attacks, leveraging […]
The post Lazarus Group Using New Malware Tactic To Attack Developers Globally appeared first on Cyber Security News.