Aggregator
CVE-2023-3375 | Bookreen up to 2.x unrestricted upload
CVE-2023-35071 | MRV Tech Logging Administration Panel prior 20230915 sql injection
CVE-2023-3377 | Veribilim Veribase up to 20231123 sql injection
CVE-2023-3631 | Medart Notification Panel up to 20231123 sql injection
CVE-2024-38250 | Microsoft Windows up to Server 2022 23H2 Graphics buffer over-read
CVE-2025-26687 | Microsoft Windows up to Server 2025 Win32k use after free (Nessus ID 234050)
CVE-2025-30386 | Microsoft Office use after free (EUVD-2025-14450 / Nessus ID 236844)
CVE-2025-30388 | Microsoft Windows up to Server 2025 Graphics heap-based overflow (EUVD-2025-14412 / WID-SEC-2025-1050)
Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access
Russian state-sponsored threat groups significantly stepped up their cyber operations in 2025, using a range of methods to break into targeted systems. From exploiting remote desktop tools and virtual private networks to manipulating trusted supply chains and deceiving employees through social engineering, these actors have built a dangerous and versatile toolkit for gaining initial access. […]
The post Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access appeared first on Cyber Security News.
Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks
A widely-used JavaScript templating library called art-template has been weaponized to deliver a sophisticated iOS browser exploit kit through a supply chain attack. The backdoored package silently dropped malicious code into end users’ browsers, turning everyday web applications into watering holes targeting Apple device owners worldwide. The attack began when the art-template npm package, originally […]
The post Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks appeared first on Cyber Security News.