Aggregator
Эпопея с CISA продолжается: ключевых сотрудников агентства внезапно отправили в отпуск
CVE-2025-24032、CVE-2025-24531等:PAM-PKCS#11中的关键缺陷将Linux身份验证暴露给攻击者
Anduril 将从微软接手陆军版 HoloLens 头戴式显示设备
North Korean Hackers Exploit PowerShell Trick to Hijack Devices in New Cyberattack
深度解读 | 六部门印发方案,要求完善数据流通安全治理
Hackers Trick You To Run PowerShell As Admin & Paste Their Code to Hack Windows
Microsoft Threat Intelligence has uncovered a new tactic employed by the North Korean state-sponsored hacking group Emerald Sleet, also known as Kimsuky or VELVET CHOLLIMA. The group is leveraging social engineering techniques to trick victims into running PowerShell commands as administrators, enabling them to compromise devices and exfiltrate sensitive data. Emerald Sleet’s latest approach involves […]
The post Hackers Trick You To Run PowerShell As Admin & Paste Their Code to Hack Windows appeared first on Cyber Security News.
CVE-2025-0506 | eaglethemes Rise Blocks Plugin up to 3.6 on WordPress titleTag cross site scripting
CVE-2024-13456 | nmedia Easy Quiz Maker Plugin up to 2.0 on WordPress Shortcode wqt-question cross site scripting
CVE-2024-13437 | chuhpl Book a Room Plugin up to 2.9 on WordPress Setting bookaroom_Settings cross-site request forgery
CVE-2024-13459 | jeremyshapiro FuseDesk Plugin up to 6.6.1 on WordPress Shortcode fusedesk_newcase cross site scripting
CVE-2024-13531 | enituretechnology ShipEngine Shipping Quotes Plugin up to 1.0.7 on WordPress edit_id sql injection
‘Wormable’ Windows LDAP Vulnerability Allow Attackers Arbitrary Code Remotely
A critical security vulnerability has been identified in Windows’ Lightweight Directory Access Protocol (LDAP) implementation, allowing attackers to execute arbitrary code remotely. This “wormable” vulnerability, designated as CVE-2025-21376, was disclosed on February 11, 2025, by Microsoft. The vulnerability is classified as a Remote Code Execution (RCE) issue, which can be exploited without requiring any user […]
The post ‘Wormable’ Windows LDAP Vulnerability Allow Attackers Arbitrary Code Remotely appeared first on Cyber Security News.