Aggregator
Submit #588258: Netgear EX3700 before 1.0.0.88 Stack-based buffer overflow [Accepted]
Major food wholesaler says cyberattack impacting distribution systems
Over 70 Organizations Across Multiple Sectors Targeted by China-Linked Cyber Espionage Group
Skitnet Malware Actively Adopted by Ransomware Gangs to Enhance Operational Efficiency
Skitnet malware, also referred to as Bossnet, has emerged as a critical tool for ransomware gangs in 2025, showcasing a marked increase in operational efficiency for cybercriminals. First advertised on underground forums like RAMP on April 19, 2024, by a threat actor known as LARVA-306, Skitnet was initially positioned as a compact, user-friendly post-exploitation package […]
The post Skitnet Malware Actively Adopted by Ransomware Gangs to Enhance Operational Efficiency appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-49006 | wasp-lang wasp up to 0.16.5 OAuth default permission (GHSA-qvjc-6xv7-6v5f / EUVD-2025-17468)
CVE-2025-48796 | GIMP ANI File Parser ani_load_image stack-based overflow (EUVD-2025-16289)
SmolVLA даёт старт open-source роботам: запускай с дивана, управляй в реале
Alleged admin access sale to multiple FinTech Companies in South America
CVE-2025-39472 | WPWeb WooCommerce Social Login Plugin up to 2.8.2 on WordPress cross-site request forgery (EUVD-2025-11383)
CVE-2025-49131 | labring FastGPT up to 4.9.10 Python Module permission assignment (GHSA-f3pf-r3g7-g895 / EUVD-2025-17467)
CVE-2025-5763 | Tenda CP3 11.10.00.2311090948 apollo sub_F3C8C command injection (EUVD-2025-17119)
CVE-2025-3501 | Red Hat Keycloak/Single Sign-On Verification Policy certificate validation (EUVD-2025-12660)
CVE-2025-5732 | code-projects Traffic Offense Reporting System 1.0 cross-site request forgery (EUVD-2025-17097)
CVE-2025-5734 | TOTOLINK X15 1.0.0-B20230714.1105 HTTP POST Request /boafrm/formWlanRedirect redirect-url buffer overflow (EUVD-2025-17096)
OffensiveCon25 – Entrysign: Create Your Own x86 Microcode for Fun and Profit
Authors/Presenters: Matteo Rizzo, Kristoffer `spq` Janke, Eduardo Vela Nava and Josh Eads
Our sincere appreciation to OffensiveCon by Binary Gecko, and the Presenters/Authors for publishing their outstanding OffensiveCon 2025 video content. Originating from the conference’s events located at the Hilton Berlin; and via the organizations YouTube channel.
Thanks and a Tip O' The Hat to Verification Labs :: Penetration Testing Specialists :: Trey Blalock GCTI, GWAPT, GCFA, GPEN, GPCS, GCPN, CRISC, CISA, CISM, CISSP, SSCP, CDPSE for recommending the OffensiveCon 25 conference.
The post OffensiveCon25 – Entrysign: Create Your Own x86 Microcode for Fun and Profit appeared first on Security Boulevard.
New Wiper Malware Targets Ukrainian Infrastructure
Internet infamy drives The Com’s crime sprees
Unit 221B’s Allison Nixon said crackdowns have effectively shown the group that their actions carry real consequences.
The post Internet infamy drives The Com’s crime sprees appeared first on CyberScoop.
Google Warns of Surge in Cyberattacks Targeting US Users to Steal Login Credentials
Google has highlighted a significant uptick in cyberattacks and scams targeting US consumers, with a particular focus on stealing login credentials. The FBI reports that online scams generated a staggering $16.6 billion in losses last year, reflecting a 33% increase over the previous year. Over 60% of Americans have perceived a rise in scam attempts […]
The post Google Warns of Surge in Cyberattacks Targeting US Users to Steal Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.