Aggregator
CVE-2025-21714 | Linux Kernel up to 6.12.12/6.13.1 lib/refcount.c __xa_cmpxchg use after free (Nessus ID 231919 / WID-SEC-2025-0453)
CVE-2025-21713 | Linux Kernel up to 6.12.12/6.13.1 spapr_tce_set_window null pointer dereference (Nessus ID 236983 / WID-SEC-2025-0453)
CVE-2025-21712 | Linux Kernel up to 6.12.12/6.13.1 bitmap_get_stats initialization (Nessus ID 234309 / WID-SEC-2025-0453)
Agenda Ransomware Actors Deploying Linux RAT on Windows Systems Targeting VMware Deployments
Cybersecurity researchers have uncovered a sophisticated ransomware campaign where Agenda group threat actors are deploying Linux-based ransomware binaries directly on Windows systems, targeting VMware virtualization infrastructure and backup environments. This cross-platform execution technique challenges traditional security assumptions and demonstrates how ransomware operators are adapting to bypass endpoint detection systems that primarily focus on Windows-native threats. […]
The post Agenda Ransomware Actors Deploying Linux RAT on Windows Systems Targeting VMware Deployments appeared first on Cyber Security News.
CVE-2025-12095 | Simple Registration for WooCommerce Plugin up to 1.5.8 on WordPress display-role-admin.php cross-site request forgery
CVE-2025-11888 | ShopEngine Elementor WooCommerce Builder Addon Plugin License Status Update post_deactive/post_activate improper authorization
CVE-2025-6639 | Tutor LMS Pro Plugin up to 3.8.3 on WordPress tutor_assignment_submit resource injection
CVE-2025-12005 | WP VR Plugin up to 8.5.41 on WordPress Setting improper authorization
CVE-2025-6680 | Tutor LMS Plugin up to 3.8.3 on WordPress authorization
CVE-2025-8588 | Gutenberg Blocks Plugin up to 3.3.4 on WordPress Marker Title/Marker Description cross site scripting
CVE-2025-8413 | Listeo Plugin up to 2.0.8 on WordPress Shortcode soundcloud cross site scripting
CVE-2025-8666 | Testimonial Carousel for Elementor Plugin up to 11.6.2 on WordPress Widget cross site scripting
Вредоносная модификация Telegram заразила около 60 тысяч Android-устройств
New Text Message Based Phishing Attack from China Targeting Users Around the Globe
A sophisticated text message phishing campaign originating from China has emerged as one of the most extensive cybersecurity threats targeting users worldwide. The operation, attributed to a threat collective known as the Smishing Triad, represents a massive escalation in SMS-based fraud, impersonating services across banking, healthcare, law enforcement, e-commerce, and government sectors. What began as […]
The post New Text Message Based Phishing Attack from China Targeting Users Around the Globe appeared first on Cyber Security News.
Miсrosoft вас сдаст. Новая функция будет автоматически определять, что вы в офисе
Civilian Airport OT: the US Military's Soft Underbelly
Consider the airport baggage carousel. It's big, clunky and tedious to wait by. But look at it like a war planner does, and it's suddenly very different: An almost certainly poorly secured technology system that foreign adversaries could exploit to disrupt military mobilization across the United States.
Yale New Haven Health Will Pay $18M to Settle Hack Lawsuit
Connecticut's largest healthcare network - Yale New Haven Health System - has agreed to pay $18 million to settle class action litigation filed in the aftermath of a March hack affecting nearly 5.6 million people. The incident ranks as the biggest health data breach reported so far in 2025.
Fortinet Accused of Securities Fraud Over Firewall Forecasts
Public pension funds filed securities fraud lawsuits claiming Fortinet misled investors by overstating the value and timing of a major firewall refresh cycle. The lawsuits allege the refresh involved outdated products and had limited business impact, contradicting Fortinet's upbeat public messaging.
AWS Outage Exposes Cloud Dependency, Concentration Risks
The cascading outage across the U.S. East Coast triggered this week by a domain name system failure in an AWS DynamoDB service demonstrates the risks of deep architectural dependencies and the challenges of building true multi-region cloud resilience, said Forrester's Brent Ellis and Dario Maisto.