Aggregator
CVE-2024-12206 | stylemix Header Builder Plugin up to 1.3.8 on WordPress stm_header_builder cross-site request forgery
CVE-2024-11815 | Posturinn Shipping with WooCommerce Plugin up to 1.3.1 on WordPress printed_marked/nonprinted_marked cross site scripting
CVE-2024-12330 | Database Backup Plugin up to 7.3 on WordPress backup
Ivanti Connect Secure zero-day exploited since mid-December (CVE-2025-0282)
The zero-day attacks leveraging the Ivanti Connect Secure (ICS) vulnerability (CVE-2025-0282) made public on Wednesday were first spotted in mid-December 2024, Mandiant researchers have shared. It’s still impossible to say whether they were mounted by a single threat actor, but the use of known malware on at least one of the compromised VPN appliances points to China-nexus espionage actor(s) – UNC5337 and UNC5221 – that have exploited ICS zero-days several times in the past few … More →
The post Ivanti Connect Secure zero-day exploited since mid-December (CVE-2025-0282) appeared first on Help Net Security.
APT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub
The malicious Southeast Asian APT group known as OceanLotus (APT32) has been implicated in a sophisticated attack that compromises the privacy of cybersecurity professionals. A recent investigation by the ThreatBook Research and Response Team revealed that a popular privilege escalation tool utilized by cybersecurity experts had been backdoored, leading to significant data breaches and identity […]
The post APT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
The Dangers of DNS Hijacking
Akira
Brekelmans: Onze militairen belangrijk voor veiligheid Caribische eilanden
Алгоритмы X под надзором: прозрачность или оборотные штрафы
Meta's Fact-Checking Pullback Could Help Scammers Thrive
Meta has decided to end its fact-checking program. Meta CEO Mark Zuckerberg announced significant changes to the company's moderation policies and practices on Tuesday, attributing the shift to a renewed commitment to free speech. Some fear the move will embolden financial scammers.
Live Webinar | The Perfect Target: How Cybercriminals Use AI to Create Advanced Phishing Attacks
European Court Fines European Commission for Privacy Breach
European privacy regulation - bane of American technology companies and a favorite cudgel of activists - came to haunt no less an organization than the European Commission, which must pay 400 euros to aggrieved German national Thomas Bindl, peeved that Facebook obtained his IP address.
UN Cybercrime Treaty Faces Long Odds to US Passage
Experts tell Information Security Media Group that a controversial United Nations cybercrime convention is unlikely to be ratified in the U.S. Senate due to mounting concerns from technology, human rights and privacy advocates over its potential impact on internet security and privacy protections.
Zero-Day Patch Alert: Ivanti Connect Secure Under Attack
VPN appliance maker Ivanti has begun releasing updates to patch a zero-day vulnerability being actively exploited by suspected nation-state attackers. Experts are warning users to immediately update their devices, after factory resetting them to flush any malware attackers may have installed.