Aggregator
Please support the site operations by clicking ads.
Кошелёк офлайн, почта онлайн. Trezor снова взломали через подрядчика
Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide
A Ukrainian national has been sentenced to four years in U.S. prison for his role in the Conti ransomware operation, which compromised more than 1,000 victims worldwide and generated at least $150 million in ransom payments. Oleksii Oleksiyovych Lytvynenko, 44, previously living in Cork, Ireland, was sentenced for conspiracy to commit wire fraud. U.S. prosecutors […]
The post Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide appeared first on Cyber Security News.
CVE-2026-84390 | Fortinet FortiMonitorOnSight up to 7.2.2/7.2.7 access control
Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed. Rather than relying on a […]
The post Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links. Called Mantax Otax, the malware can lock files, watch the screen, intercept verification codes and secretly use a phone’s cameras, making one infection both an extortion and privacy crisis. The campaign appears built around standalone […]
The post New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims appeared first on Cyber Security News.
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of […]
The post VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates
Canonical has officially rolled out Ubuntu 24.04.5 LTS, the fifth maintenance update to the “Noble Numbat” long-term support release, delivering a fresh installation image packed with the latest security patches, bug fixes, and an upgraded hardware enablement stack built around the Linux 7.0 kernel. For a distribution that underpins millions of servers, cloud instances, and […]
The post Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates appeared first on Cyber Security News.
IBM и NASA научили ИИ искать лучшие места для жизни на Луне
CVE-2026-89256 | WWBN AVideo Bookmark plugin bookmark name cross site scripting
CVE-2026-89258 | Gohugoio Hugo up to 0.164.x Symlink os.ReadFile path traversal
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability
- CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability
- CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Ukrainian hacker gets four years in US prison over Conti ransomware attacks
CVE-2026-89259 | gohugoio Hugo up to 0.164.x Build Process hugo.toml permission
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations. MikroTik RouterOS Flaws CVE-2026-67277 […]
The post CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.