Aggregator
APT-C-36(盲眼鹰)组织在新攻击活动中升级对抗手段
ShinySp1d3r: союз ShinyHunters и Scattered Spider, бросивший вызов LockBit и DragonForce
英国政府建议居民删除邮件以节省用水
Ondata di attacchi brute-force contro le VPN Fortinet, poi FortiManager
Ukrainian Web3team Weaponizing NPM Package to Attack Job Seekers and Steal Sensitive Data
A sophisticated cybercriminal operation disguised as a Ukrainian Web3 development team has been targeting job seekers through weaponized NPM packages, security researchers warn. The attack leverages fake interview processes to trick unsuspecting candidates into downloading and executing malicious code that steals cryptocurrency wallets, browser data, and sensitive personal information. The campaign centers around a seemingly […]
The post Ukrainian Web3team Weaponizing NPM Package to Attack Job Seekers and Steal Sensitive Data appeared first on Cyber Security News.
CVE-2010-4837 | Extensiondepot Com Jsupport 1.5.6 index2.php subject cross site scripting (EDB-15501 / SA42262)
CVE-2010-4838 | Extensiondepot Com Jsupport 1.5.6 administrator/index.php alpha sql injection (EDB-15502 / SA42262)
PartCrafter:首个结构化3D多部件生成模型
What is MCP Server – How it is Powering AI-Driven Cyber Defense
MCP (Model Control Plane) Server is a centralized platform that orchestrates, manages, and secures the lifecycle of AI models deployed across an organization’s infrastructure. By providing integration, management, and real-time monitoring of models, MCP servers enable enterprises to defend against sophisticated, AI-powered cyberattacks. This article explores MCP server integration and usage, its core workings, the […]
The post What is MCP Server – How it is Powering AI-Driven Cyber Defense appeared first on Cyber Security News.
美国智库借以伊网络对抗评析战时网络行动的作用
VMware ESXi严重漏洞威胁全球大量服务器,国内超1700台受影响
CVE-2025-6184 | Tutor LMS Pro Plugin up to 3.7.0 on WordPress get_submitted_assignments sql injection (EUVD-2025-24547)
Defending Trust & Reputation as CISOs and Leaders Prepare Their AI Strategy - Santosh Nair - BSW #408
New Windows 0-Click NTLM Credential Leakage Vulnerability Bypasses Microsoft’s Patch
A critical zero-click NTLM credential leakage vulnerability that circumvents Microsoft’s recent patch for CVE-2025-24054. The newly identified flaw, assigned CVE-2025-50154, allows attackers to extract NTLM hashes from fully patched Windows systems without any user interaction, demonstrating that Microsoft’s April security update was incomplete. Key Takeaways1. CVE-2025-50154 bypasses Microsoft's recent patch, enabling zero-click NTLM credential theft.2. […]
The post New Windows 0-Click NTLM Credential Leakage Vulnerability Bypasses Microsoft’s Patch appeared first on Cyber Security News.