Aggregator
CVE-2025-26305 | libming 0.4.8 SWF File util/parser.c parseSWF_SOUNDINFO memory leak (Issue 322)
CVE-2024-46869 | Linux Kernel up to 6.10.11/6.11.0 btintel_pcie allocation of resources (fa9e1c1b1f38/2b4545f08cc6/7ffaa2002518 / Nessus ID 216493)
CVE-2024-53069 | Linux Kernel up to 6.11.7 __scm null pointer dereference (3d36e2b1d803/ca61d6836e6f / Nessus ID 216493)
CVE-2024-50224 | Linux Kernel up to 6.6.59/6.11.6 spi_get_csgpiod null pointer dereference (e79c1f1c9100/89f74c968319/25f00a13dccf / Nessus ID 216493)
CVE-2024-53143 | Linux Kernel up to 6.11.10/6.12.1 fsnotify iput use after free (45a8f8232a49/83af1cfa10d9/21d1b618b6b9 / Nessus ID 216493)
CVE-2024-50221 | Linux Kernel up to 6.11.6 Vangogh vangogh_tables_init out-of-bounds write (f8fd9f0d57af/4aa923a6e640 / Nessus ID 216493)
Guidance on securely configuring network protocols (ITSP.40.062)
Chinese Hackers Exploiting Check Point Firewall Vulnerability To Deploy Ransomware
A sophisticated cyber espionage campaign linked to Chinese state-aligned threat actors has targeted organizations across 15 countries using an updated variant of the Shadowpad malware to deploy previously undocumented ransomware. The attacks, analyzed by Trend Micro’s incident response team, exploit weak passwords and multi-factor authentication (MFA) bypass techniques to infiltrate Check Point firewall VPNs. Over […]
The post Chinese Hackers Exploiting Check Point Firewall Vulnerability To Deploy Ransomware appeared first on Cyber Security News.
Sophisticated Payment Card Skimming Campaign Conceals Itself by Leveraging Stripe API
by Source Defense A newly discovered payment card skimming campaign has emerged exhibiting a concerning level of sophistication and leveraging unique tactics that make detection highly challenging. The attack, identified by Source Defense researchers, employs an innovative technique that exploits Stripe’s deprecated API to verify card details before exfiltration – ensuring that only valid payment
The post Sophisticated Payment Card Skimming Campaign Conceals Itself by Leveraging Stripe API appeared first on Source Defense.
The post Sophisticated Payment Card Skimming Campaign Conceals Itself by Leveraging Stripe API appeared first on Security Boulevard.
Карманный убийца дронов: система Dronebuster DTIM обезвредит цель за 7 км
CVE-2024-50129 | Linux Kernel up to 6.11.5 pse-pd out-of-bounds (50ea68146d82/f2767a41959e / Nessus ID 216493)
CVE-2024-53139 | Linux Kernel up to 6.6.62/6.11.9 net/core/dev.c sctp_v6_available use after free (ad975697211f/05656a665927/eb72e7fcc839 / Nessus ID 216493)
Google Adds Quantum-Resistant Digital Signatures to Cloud KMS
PascalCTF Beginners 2025
Date: March 19, 2025, 3 p.m. — 19 March 2025, 20:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.pascalctf.it/
Rating weight: 0.00
Event organizers: Paolo
ThunderCipher
Date: Feb. 20, 2025, 7:30 a.m. — 20 Feb. 2025, 13:30 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://thundercipher.tech/
Rating weight: 0
Event organizers: ThunderCipher
Check Point Software to Open First Asia-Pacific R&D Centre in Bengaluru, India
Check Point Software Technologies Ltd. has announced plans to establish its inaugural Asia-Pacific Research and Development (R&D) Centre in Bengaluru, India. This initiative, unveiled during the CPX Bangkok 2025 conference, aims to drive innovation in cybersecurity solutions while strengthening global product development and talent acquisition. The Bengaluru centre underscores Check Point’s commitment to leveraging India’s […]
The post Check Point Software to Open First Asia-Pacific R&D Centre in Bengaluru, India appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
PoC Exploit Released for Ivanti Endpoint Manager Vulnerabilities
A recent investigation into Ivanti Endpoint Manager (EPM) has uncovered four critical vulnerabilities that could allow unauthenticated attackers to exploit machine account credentials for relay attacks, potentially leading to server compromise. These vulnerabilities, identified in the C:\Program Files\LANDesk\ManagementSuite\WSVulnerabilityCore.dll, were patched in January 2025 following their discovery in October 2024. The vulnerabilities are categorized as follows: […]
The post PoC Exploit Released for Ivanti Endpoint Manager Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Ransomware Trends 2025 – What’s new
As of February 2025, ransomware remains a formidable cyber threat, evolving in complexity and scale. The ransomware ecosystem has adapted to previous law enforcement disruptions, showcasing a resilient business model that continues to attract financially motivated cybercriminals. The proliferation of Ransomware-as-a-Service (RaaS) has significantly contributed to the volume of attacks, allowing less experienced affiliates to […]
The post Ransomware Trends 2025 – What’s new appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers Delivering Malware Bundled with Fake Job Interview Challenges
ESET researchers have uncovered a series of malicious activities orchestrated by a North Korea-aligned group known as DeceptiveDevelopment, active since early 20241. The cybercriminals pose as company recruiters, enticing freelance software developers with fake employment offers. As part of the elaborate ruse, targets are asked to complete coding tests, such as adding features to existing […]
The post Hackers Delivering Malware Bundled with Fake Job Interview Challenges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.