Aggregator
CVE-2025-3929 | MDaemon Email Server up to 25.0.1 HTML Email HTML injection
CVE-2025-30194 | PowerDNS DNSdist up to 1.9.8 nghttp2 Provider use after free
CVE-2025-1194 | huggingface transformers up to 4.49.x SubWordJapaneseTokenizer redos
Fraudulent email domain tracker: April 2025
This is the first release in a new Castle series highlighting email domains associated with fraudulent activity. Our goal is to provide visibility into email infrastructure commonly abused by bots and fraudsters, so that security teams can improve their detection systems.
Each month, we’ll publish a ranked list
The post Fraudulent email domain tracker: April 2025 appeared first on Security Boulevard.
Рекордная волна сканирования .git/config: более 4800 IP за двое суток — и это только начало
Pentagon Stealer: Go and Python Malware with Crypto Theft Capabilities
The current article provides technical analysis of an emerging malware named Pentagon Stealer. The research has been prepared by the analyst team at ANY.RUN. Key Takeaways How We Discovered Pentagon Stealer In early March of this year, when browsing Public submissions, the ANY.RUN team came across an interesting malware sample written in Golang. View sandbox […]
The post Pentagon Stealer: Go and Python Malware with Crypto Theft Capabilities appeared first on ANY.RUN's Cybersecurity Blog.