Aggregator
CVE-2024-54223 | Contact Form ARForms Form Builder Plugin up to 1.7.1 on WordPress cross site scripting
Kill
Apiiro unveils free scanner to detect malicious code merges
CVE-2025-0413 | Parallels Desktop 19.4.1 54985 Data Reporter link following (ZDI-25-082)
Black Basta ransomware gang's internal chat logs leak online
[CISA AA25-050A] #StopRansomware: Ghost (Cring) Ransomware
AttackIQ has released a new attack graph in response to the CISA Advisory (AA25-050A) published on February 19, 2025, which disseminates known Ghost Ransomware Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IOCs) identified through FBI investigations as recently as January 2025.
The post [CISA AA25-050A] #StopRansomware: Ghost (Cring) Ransomware appeared first on AttackIQ.
The post [CISA AA25-050A] #StopRansomware: Ghost (Cring) Ransomware appeared first on Security Boulevard.
Products in evaluation
Ivanti Endpoint Manager Vulnerabilities Proof-of-Concept (PoC) Exploit Released
A cluster of four critical vulnerabilities in Ivanti Endpoint Manager (EPM) has entered a dangerous new phase with the public release of proof-of-concept (PoC) exploit code, escalating risks for organizations using the enterprise device management platform. Discovered by researchers in October 2024 and patched by Ivanti in January 2025, these vulnerabilities (CVE-2024-10811, CVE-2024-13161, CVE-2024-13160, CVE-2024-13159) […]
The post Ivanti Endpoint Manager Vulnerabilities Proof-of-Concept (PoC) Exploit Released appeared first on Cyber Security News.
New NailaoLocker Ransomware Attacking European Healthcare
European healthcare organizations are facing a sophisticated cyber threat from a newly identified ransomware strain called NailaoLocker, deployed as part of a campaign tracked as Green Nailao by Orange Cyberdefense CERT. The attacks, first detected between June and October 2024, exploit vulnerabilities in Check Point VPN appliances and leverage advanced backdoors like ShadowPad and PlugX […]
The post New NailaoLocker Ransomware Attacking European Healthcare appeared first on Cyber Security News.
How Page Protect Enabled Seamless PCI DSS 4.0 Compliance for a Leading Beverage Retailer
Discover how a leading beverage retailer achieved seamless PCI DSS 4.0 compliance before the March 31st deadline in minutes with DataDome’s Page Protect—no-code setup, real-time monitoring & script security.
The post How Page Protect Enabled Seamless PCI DSS 4.0 Compliance for a Leading Beverage Retailer appeared first on Security Boulevard.
RansomHub
RansomHub
RansomHub
48 Hours in the Trenches: The High-Stakes World of Incident Response
Okay, so this is all going to sound a bit dramatic, but it’s with good reason. I manage a cybersecurity response team for a top-level MSSP. If there’s one thing I know, in the fast-paced world of cybersecurity, there’s a […]
The post 48 Hours in the Trenches: The High-Stakes World of Incident Response appeared first on TechSpective.
The post 48 Hours in the Trenches: The High-Stakes World of Incident Response appeared first on Security Boulevard.
DEF CON 32 – MicroHard More Like MicroEasy To Exploit
Authors/Presenters: Ricky Lawshae
Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – MicroHard More Like MicroEasy To Exploit appeared first on Security Boulevard.
Early Trends in 2025
With every new year bringing new technologies, expanding attack surfaces, and legions of salivating threat actors.
The post Early Trends in 2025 appeared first on Security Boulevard.