Aggregator
朝鲜特工在 LinkedIn 伪装专业人士渗透企业
Reynolds 勒索软件通过嵌入 BYOVD 禁用 EDR 安全工具
恶意 7-Zip 网站分发掺杂了代理工具的安装程序
新型移动间谍软件 ZeroDayRAT 针对安卓与 iOS 设备发起攻击
诚邀渠道合作伙伴共启新征程
火绒小问答 ——「个人版」常见恶意网址拦截或报毒
微信Linux版高危漏洞已修复 信创安全防护仍需重点强化
朝鲜黑客通过虚假 Zoom 会议、ClickFix 钓鱼攻击加密货币行业高管
Phorpiex 钓鱼攻击投放强隐蔽性 Global Group 勒索软件
Следил за бывшей, а теперь все знают твой email. Хакер wikkid наказал 500000 любителей шпионских приложений
沃尔沃集团北美客户数据在 Conduent 黑客攻击中泄露
新型 Linux 僵尸网络 SSHStalker 采用老式 IRC 协议进行命令与控制通信
Yubico previews passkey-enabled digital signatures in upcoming YubiKey 5.8 firmware
Yubico’s upcoming YubiKey 5.8 firmware introduces standardized APIs that integrate hardware-backed signatures with passkey authentication. To enable privacy-capable digital signatures using passkeys, expanded enterprise IdP support, and next-generation digital wallet use cases, the firmware adds support for FIDO CTAP 2.3 and preview WebAuthn signing extensions. “The adoption of CTAP 2.3, together with enhancements such as the W3C signing extension, enables usable digital signatures in web applications and services where digital signing is part of the … More →
The post Yubico previews passkey-enabled digital signatures in upcoming YubiKey 5.8 firmware appeared first on Help Net Security.
春节防“伪”指南:360安全智能体识破仿冒网站,护航安心年
Windows Remote Access Connection Manager 0-Day Vulnerability Let Attackers Trigger DoS Attack
Microsoft has patched a zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service, tracked as CVE-2026-21525, which allowed attackers to trigger denial-of-service (DoS) conditions on unpatched systems. The flaw, stemming from a NULL pointer dereference (CWE-476), was actively exploited in the wild before disclosure, earning an “Exploitation Detected” rating from Microsoft’s MSRC exploitability […]
The post Windows Remote Access Connection Manager 0-Day Vulnerability Let Attackers Trigger DoS Attack appeared first on Cyber Security News.
文末领福利!Yak Project 致用户与共建者们的2025年报
Sophisticated Cyber Attack Targets Wedding Industry With Teams-Based Malware Delivery
A sophisticated phishing campaign targets wedding planners and vendors with stealer malware disguised as Microsoft Teams meetings. Security researchers highlight the use of compromised legitimate emails to build trust before delivering payloads. Threat actors impersonate legal professionals in emails from czimmerman@craigzlaw[.]com, a domain tied to The Law Offices of Craig Zimmerman, a real consumer protection […]
The post Sophisticated Cyber Attack Targets Wedding Industry With Teams-Based Malware Delivery appeared first on Cyber Security News.