Aggregator
CVE-2024-6807 | SourceCodester Student Study Center Desk Management System 1.0 HTTP POST Request Users.php?f=save firstname/middlename/lastname/username cross site scripting (EUVD-2024-48012)
Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016)
Two Mirai botnets are exploiting a critical remote code execution vulnerability (CVE-2025-24016) in the open-source Wazuh XDR/SIEM platform, Akamai researchers have warned. What is Wazuh? Wazuh is a popular open-source security information and event management (SIEM) and extended detection and response (XDR) solution that’s widely used for host-based intrusion detection, log analysis, file integrity monitoring, and more. It’s core components are: Wazuh Manager (server component), which analyzes data and triggers alerts. Made to be installed … More →
The post Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016) appeared first on Help Net Security.
报名 | 美团技术沙龙第85期【AI+安全:智能技术在安全领域的应用探索】
Malicious Actors Exploit SoraAI’s Popularity & GitHub to Distribute Malware
Threat actors are leveraging the growing popularity of OpenAI’s Sora, a cutting-edge video generation model, to distribute malicious software. Disguised as a legitimate shortcut file named “SoraAI.lnk,” this information-stealing malware mimics the branding of Sora to trick users into initiating a multi-stage attack chain. Deceptive Tactics Target OpenAI’s Sora Brand First reported on VirusTotal from […]
The post Malicious Actors Exploit SoraAI’s Popularity & GitHub to Distribute Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account
Только начали карьеру в ИТ? Поздравляем — вы входите в список «легко заменяемых»
20 万一台的「人脑计算机」,可能是人类战胜 AI 的唯一方式?
全球六大AI安全智能体差异对比
按摩脸部和颈部或有助于大脑冲掉垃圾
CVE-2025-3117 | Schneider Electric Modicon Controllers M262 prior 5.3.12.51 cross site scripting (SEVD-2025-161-02)
CVE-2025-3905 | Schneider Electric Modicon Controllers LMC058 prior 5.3.12.51 PLC cross site scripting (SEVD-2025-161-02)
CVE-2025-5742 | Schneider Electric EVLink WallBox configuration cross site scripting (SEVD-2025-161-03)
CVE-2025-3899 | Schneider Electric Modicon Controllers M241/Modicon Controllers M251 prior 5.3.12.51 Webserver cross site scripting (SEVD-2025-161-02)
NHS: Blood Supply Still Affected by June 2024 Vendor Attack
The National Health System in England is still dealing with blood supply issues one year after a ransomware attack on a British pathology laboratory services provider disrupted patient care and testing services at several London-based hospitals and triggered a nationwide blood shortage.
SentinelOne Sees No Breach After Hardware Supplier Hacked
Cybersecurity firm SentinelOne said suspected Chinese attackers, wielding ShadowPad backdoor malware, infiltrated a logistics firm that it used for supplying hardware to its employees, but that the intrusion doesn't appear to have resulted in any infiltration of its own, corporate network.
Whole Foods Supplier Faces Cyberattack Disrupting Operations
A cyberattack on United Natural Foods, the largest U.S. health food distributor and a key Whole Foods supplier, has disrupted the company's fulfillment operations, prompting a notification to law enforcement and a forensic investigation as it works to restore affected systems.
Mirai Botnet Variant Exploits DVR Flaw to Build Swarm
A Mirai botnet malware variant is targeting a command injection vulnerability in internet-connected digital video recorders used for CCTV surveillance, enabling attackers to take control of the devices and add them to a botnet. A security researcher first identified the vulnerability in April 2024.