Aggregator
CVE-2020-3999 | VMware ESXi/Workstation/Fusion/Cloud Foundation GuestInfo denial of service (VMSA-2020-0029)
CVE-2025-8703 | Wanzhou WOES Intelligent Optimization Energy Saving System Environmental Real-Time Data Module GetAreaTrendChartData sql injection (EUVD-2025-23969)
CVE-2025-8704 | Wanzhou WOES Intelligent Optimization Energy Saving System Analysis Conclusion Query Module GetAlarmResultProcessList sql injection (EUVD-2025-23973)
CVE-2025-8705 | Wanzhou WOES Intelligent Optimization Energy Saving System Energy Overview Module GetTargetConfig sql injection (EUVD-2025-23972)
CVE-2025-8706 | Wanzhou WOES Intelligent Optimization Energy Saving System Energy Overview Module CreateFunctionLog sql injection (EUVD-2025-23975)
CVE-2025-8707 | Huuge Box App 1.0.3 on Android com.huuge.game.zjbox AndroidManifest.xml improper export of android application components (EUVD-2025-23974)
Submit #623679: wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562 Command Injection [Accepted]
CVE-2025-8751 | Protected Total WebShield Extension up to 3.2.0 on Chrome Block Page Category cross site scripting
维他动力 Vbot:当遥控器被丢掉,才是机器狗「有生命感」的第一步?
US Confirms Shutdown of BlackSuit Ransomware That Hacked Over 450 Organizations
U.S. authorities have announced the successful dismantling of the BlackSuit ransomware operation, a notorious group linked to attacks on more than 450 organizations worldwide. The operation, led by Immigration and Customs Enforcement’s (ICE) Homeland Security Investigations (HSI), involved seizing servers, domains, and digital assets used for deploying ransomware, extorting victims, and laundering illicit profits. BlackSuit, […]
The post US Confirms Shutdown of BlackSuit Ransomware That Hacked Over 450 Organizations appeared first on Cyber Security News.
CVE-2025-53630 | ggml-org llama.cpp ggml/src/gguf.cpp gguf_init_from_file_impl heap-based overflow (WID-SEC-2025-1747)
Submit #623677: Total WebShield Chrome Antivirus Protection v3.2.0 Client‑side Self‑HTML Injection [Accepted]
Удар по спецсвязи НАТО. Уязвимы военные, полиция и разведка
Record-Breaking GreedyBear Attack Uses 650 Hacking Tools to Steal $1M from Victims
The threat actor group dubbed GreedyBear has orchestrated an industrial-scale operation blending malicious browser extensions, executable malware, and phishing infrastructure to siphon over $1 million in cryptocurrency from victims. This coordinated assault, uncovered by Koi Security researchers, leverages a staggering 650 hacking tools comprising 150 weaponized Firefox extensions and nearly 500 malicious Windows executables demonstrating […]
The post Record-Breaking GreedyBear Attack Uses 650 Hacking Tools to Steal $1M from Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
GreedyBear: 40 Fake Crypto Wallet Extensions Found on Firefox Marketplace
CVE-2025-8748 | Mobile Industrial Robots MiR Robots/MiR Fleet up to 2.x HTTP Request os command injection (EUVD-2025-23984)
Multiple Security Vulnerabilities Found in WWBN AVideo, MedDream, and Eclipse ThreadX
Cisco Talos’ Vulnerability Discovery & Research team has disclosed a total of 12 critical security vulnerabilities across three popular software platforms, highlighting significant security risks that could potentially impact millions of users worldwide. The disclosure includes seven vulnerabilities in WWBN AVideo, four in MedDream PACS Premium, and one in Eclipse ThreadX FileX, all of which […]
The post Multiple Security Vulnerabilities Found in WWBN AVideo, MedDream, and Eclipse ThreadX appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-8750 | macrozheng mall up to 1.0.3 Add Product Page /minio/upload File cross site scripting
PyPI Released Advisory to Prevent ZIP Parser Confusion Attacks on Python Package Installers
In recent months, security researchers have uncovered a novel attack vector targeting Python package installers through ambiguities in the ZIP archive format. By exploiting discrepancies between local file headers and the central directory, malicious actors can craft seemingly benign wheel distributions that, when unpacked by vulnerable installers, silently smuggle unauthorized files into the target environment. […]
The post PyPI Released Advisory to Prevent ZIP Parser Confusion Attacks on Python Package Installers appeared first on Cyber Security News.