Aggregator
RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals
RansomHub, a relatively newer player in the ransomware-as-a-service (RaaS) landscape, is experiencing significant internal turmoil after affiliates suddenly lost access to negotiation chat portals on April 1st, 2025. This disruption has forced affiliates to redirect victim communications to alternative platforms, including those belonging to competing ransomware groups, creating confusion in ongoing extortion attempts and potentially […]
The post RansomHub Ransomware-as-a-service Facing Internal Conflict as Affiliates Lost Access to Chat Portals appeared first on Cyber Security News.
Две новые функции Gmail. Каждая по отдельности — круто. Вместе — катастрофа
CVE-2004-1640 | Xoops 0.94/1.0 search.php/letter.php terme/letter cross site scripting (EDB-24415 / Nessus ID 14614)
CVE-2022-4165 | Contest Gallery Plugin/Contest Gallery Pro Plugin 19.1.5 on WordPress POST Parameter order-custom-fields-with-and-without-search.php cg_order sql injection
CVE-2022-4166 | Contest Gallery Plugin/Contest Gallery Pro Plugin 19.1.5 on WordPress POST Parameter 4_activate.php addCountS sql injection
CVE-2022-4197 | Sliderby10Web Plugin up to 1.2.52 on WordPress Setting cross site scripting
CVE-2022-4243 | ImageInject Plugin on WordPress TODO cross site scripting
CVE-2022-45431 | Dahua DHI-DSS4004-S2 Packet denial of service
CVE-2022-45430 | Dauha DHI-DSS4004-S2 Packet denial of service
CVE-2022-45429 | Dahua DHI-DSS4004-S2 server-side request forgery
CVE-2015-10004 | robbert229 JWT HMAC Comparison timing discrepancy (Issue 12)
CVE-2017-20146 | gorilla handlers cross-domain policy
CVE-2014-125026 | Cloudflare golz4 LZ4 Binding memory corruption
CVE-2018-25046 | Cloud Foundry archiver path traversal
CVE-2013-10005 | btcsuite go-socks RemoteAddr/LocalAddr stack-based overflow
NVIDIA’s Incomplete Patch for Critical Flaw Lets Attackers Steal AI Model Data
A critical vulnerability in NVIDIA’s Container Toolkit, CVE-2024-0132, remains exploitable due to an incomplete patch, endangering AI infrastructure and sensitive data. Coupled with a newly discovered denial-of-service (DoS) flaw in Docker on Linux, these issues could allow attackers to breach systems, steal proprietary AI models, or disrupt operations. Organizations using these tools for AI or […]
The post NVIDIA’s Incomplete Patch for Critical Flaw Lets Attackers Steal AI Model Data appeared first on Cyber Security News.
Threat Actors Manipulate Search Results to Lure Users to Malicious Websites
Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate search engine results, pushing malicious websites to the top where unsuspecting users are likely to click. In recent years, this tactic, often known as SEO poisoning or black hat SEO, has seen cybercriminals hijack the reputation of legitimate websites to promote […]
The post Threat Actors Manipulate Search Results to Lure Users to Malicious Websites appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Vulnhub:The Planets: Earth Writeup
Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware
Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as the Google Play Store to distribute Android malware. These websites, hosted on newly registered domains, create a façade of credible application installation pages, enticing victims with downloads that appear legitimate, including apps like Google Chrome. The sites are engineered with features […]
The post Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.