Aggregator
CVE-2025-1836 | Incorta 2023.4.3 Edit Insight Service Name csv injection
CVE-2025-1841 | ESAFENET CDG 5.6.3.154.205 ClientSortLog.jsp startDate/endDate sql injection
CVE-2025-1842 | FITSTATS Technologies AthleteMonitoring up to 20250302 /login.php username cross site scripting
CVE-2025-1843 | Mini-Tmall up to 20250211 ProductMapper.java select orderBy sql injection
CVE-2007-1008 | Apple iTunes 7.0.2 memory corruption (EDB-29616 / BID-22615)
JavaGhost: Exploiting Amazon IAM Permissions for Phishing Attacks
Unit 42 researchers have observed a threat actor group known as JavaGhost exploiting misconfigurations in Amazon Web Services (AWS) environments to conduct sophisticated phishing campaigns. Active for over five years, JavaGhost has pivoted from website defacement to leveraging compromised cloud infrastructure for financial gain. The group’s attacks stem from exposed long-term AWS access keys, which […]
The post JavaGhost: Exploiting Amazon IAM Permissions for Phishing Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Симфония страха: хакеры Qilin стали дирижерами Хьюстонского оркестра
MediaTek Warns of Multiple Vulnerabilities that let Attackers Escalate Privileges
MediaTek has issued urgent security advisories warning of multiple high-severity vulnerabilities in its system-on-chip (SoC) architectures, including flaws that enable local privilege escalation (LPE) and remote code execution (RCE). The March 2025 Product Security Bulletin highlights three high severity vulnerabilities CVE-2025-20644, CVE-2025-20645, and CVE-2025-20646—affecting modem firmware, cryptographic key management, and Wi-Fi subsystems. These vulnerabilities impact […]
The post MediaTek Warns of Multiple Vulnerabilities that let Attackers Escalate Privileges appeared first on Cyber Security News.
The New Ransomware Groups Shaking Up 2025
【安全圈】黑客滥用 Google 和 PayPal 的基础设施窃取用户个人数据
【安全圈】虚假验证码网络钓鱼活动影响超过1150个组织
【安全圈】美国追回 2021 年铀金融黑客攻击中被盗的 3100 万美元
报告发布 | BLACKBASTA勒索组织内部泄密事件分析报告
报告发布 | BLACKBASTA勒索组织内部泄密事件分析报告
报告发布 | BLACKBASTA勒索组织内部泄密事件分析报告
报告发布 | BLACKBASTA勒索组织内部泄密事件分析报告
报告发布 | BLACKBASTA勒索组织内部泄密事件分析报告
New Vulnerability in Substack let Attackers Take Over Subdomains
A newly disclosed edge case in Substack’s custom domain implementation allows threat actors to hijack inactive subdomains, potentially enabling content spoofing, phishing campaigns, and brand impersonation. The researcher identified 1,426 vulnerable domains – representing 8% of all Substack-associated custom domains – that remain exposed due to misconfigured DNS records, including 11 wildcard domains that exponentially […]
The post New Vulnerability in Substack let Attackers Take Over Subdomains appeared first on Cyber Security News.
DOGE Access to Personal Information and The Difficulty of Showing Harm in Privacy Litigation
If a company has effective insurance, prevention becomes even less cost-effective. By failing to “value” privacy alone, the system skews in favor of not protecting privacy.
The post DOGE Access to Personal Information and The Difficulty of Showing Harm in Privacy Litigation appeared first on Security Boulevard.