Aggregator
【培训】第15期全国开源情报能力培训班下周北京开班
【情报】特朗普执政后美国全球使领馆人员变动情况
用IDA微码(Hex-Rays Microcode)技术反简单CFF
ИИ оказался «паразитом», который 25 лет «питался» живым трудом 100 000+ редакторов Википедии
Phishing Scam Uses Big-Name Brands to Steal Logins
A recent investigation by Cyble Research and Intelligence Labs (CRIL) has uncovered a sophisticated phishing campaign exploiting globally recognized and regional brands to steal user credentials, marking an escalation in adversary tradecraft and reach. Unlike conventional phishing threats, this operation delivers meticulously crafted HTML attachments often camouflaged as procurement documents or invoices directly through email, […]
The post Phishing Scam Uses Big-Name Brands to Steal Logins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
SAP Releases Security Update to Fix Critical Code Execution and Injection Flaws
SAP has released a significant security update addressing 18 new vulnerabilities across its enterprise software portfolio, including several critical flaws related to code execution and data injection. This monthly security patch day features four high-severity vulnerabilities that require immediate attention from organizations utilizing SAP infrastructure. The most severe vulnerabilities have a CVSS score of 10.0, […]
The post SAP Releases Security Update to Fix Critical Code Execution and Injection Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Attackers exploited another Gladinet Triofox zero-day (CVE-2025-12480)
Attackers have exploited a now-fixed vulnerability (CVE-2025-12480) in the Gladinet Triofox secure file sharing and remote access platform while it was still a zero-day, Mandiant revealed on Monday. CVE-2025-12480 exploitation and attack details Gladinet’s Triofox solution is used by medium and large businesses to securely share files and allow users to access them without a VPN. CVE-2025-12480 is an Improper Access Control flaw allowing unauthenticated attackers to access the solution’s configuration/setup page. According to Mandiant’s … More →
The post Attackers exploited another Gladinet Triofox zero-day (CVE-2025-12480) appeared first on Help Net Security.
Have I Been Pwned Adds 1.96B Accounts From Synthient Credential Data
Спасибо за 1400%. Как власти Британии и США сделали VPN-сервисам лучшую в мире рекламу
Hackers Exploit Critical Flaw in Gladinet's Triofox File Sharing Product
CVE-2025-61623 | Apache OFBiz up to 24.09.02 cross site scripting
CVE-2025-59118 | Apache OFBiz up to 24.09.02 unrestricted upload
CVE-2025-41102 | Fairsketch RISE CRM Framework up to 3.8 POST Request /events/save Title cross site scripting
CVE-2025-7633 | Zoho ManageEngine Exchange Reporter Plus up to 5723 Custom Report cross site scripting
CVE-2025-7632 | Zoho ManageEngine Exchange Reporter Plus up to 5723 Public Folders Report cross site scripting
CVE-2025-7430 | Zoho ManageEngine Exchange Reporter Plus up to 5723 Folder Message Report cross site scripting
CVE-2025-11960 | Aryom KVKNET up to 2.1.7 cross site scripting
New “KomeX” Android RAT Hits Hacker Forums with Tiered Subscriptions
A sophisticated Android remote-access trojan named KomeX RAT has emerged on underground hacking forums, with the threat actor Gendirector actively marketing the malware through tiered subscription models. The malware, built on the foundation of previously documented BTMOB, poses a significant threat to Android device owners due to its extensive capabilities and aggressive advertising campaign within […]
The post New “KomeX” Android RAT Hits Hacker Forums with Tiered Subscriptions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.