Aggregator
1 in 3 Android Apps Leak Sensitive Data
Kapitein Jan Koolhaas herbegraven in Dordrecht
CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader
SonicWall Discloses Compromise of Cloud Backup Service
New ‘shinysp1d3r’ Ransomware-as-a-Service Targets VMware ESXi in Ongoing Development
EclecticIQ analysts assess with high confidence that ShinyHunters is expanding its operations by combining AI-enabled voice phishing, supply chain compromises, and leveraging malicious insiders, such as employees or contractors, who can provide direct access to enterprise networks. ShinyHunters is very likely relying on members of Scattered Spider and The Com to conduct voice phishing attacks […]
The post New ‘shinysp1d3r’ Ransomware-as-a-Service Targets VMware ESXi in Ongoing Development appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2019-10866 | Form Maker Plugin up to 1.13.2 on WordPress Submissions_fm.php get_labels_parameters Submissioc sql injection (EDB-46958)
CVE-2019-19985 | Email Subscribers / Newsletters up to 4.2.2 on WordPress File Download information disclosure (News 158563 / EDB-48698)
CVE-2019-20361 | Email Subscribers / Newsletters up to 4.3.0 on WordPress hash sql injection (News 158568 / EDB-48699)
CVE-2019-15889 | download-manager Plugin up to 2.9.93 on WordPress Category orderby/search[publish_date] cross site scripting (ID 154356 / EDB-47350)
CVE-2019-16223 | WordPress up to 5.2.2 Post Preview cross site scripting (Bug 160745 / EDB-49338)
CVE-2019-16902 | ARforms Plugin 3.7.1 on WordPress arformcontroller.php arf_delete_file Path input validation (EDB-47443)
CVE-2019-8404 | Webiness Inventory 2.3 ProductModel unrestricted upload (EDB-46405)
CVE-2019-12460 | Web Port 1.19.1 /access/setup Type cross site scripting (ID 158174 / EDB-48612)
CVE-2019-13292 | webERP 4.15 Payments.php SQL Query sql injection (EDB-47013)
ИИ защитит от ИИ? Каждый четвертый IT-специалист в России считает дипфейки самой опасной угрозой.
CVE-2025-10205 | ABB FLXEON up to 9.3.5 hash without salt
CVE-2025-10664 | PHPGurukul Small CRM 4.0 /create-ticket.php subject sql injection
6000 чужих миров и один из них может быть обитаемым. NASA переписала карту космоса
Google fixes actively exploited Chrome zero-day vulnerability (CVE-2025-10585)
Google has released a security update for the Chrome stable channel to fix a zero‑day vulnerability (CVE-2025-10585) reported by its Threat Analysis Group (TAG) on Tuesday. “Google is aware that an exploit for CVE-2025-10585 exists in the wild,” the company announced. About CVE-2025-10585 Like CVE-2025-6554, which was fixed earlier this year, CVE-2025-10585 is a type confusion vulnerability in V8, Chrome’s JavaScript and WebAssembly engine. Unfortunately, that’s the only information Google has shared about it. As … More →
The post Google fixes actively exploited Chrome zero-day vulnerability (CVE-2025-10585) appeared first on Help Net Security.