Aggregator
glibc漏洞使数百万Linux系统面临代码执行风险
Alleged Sale of Unauthorized Admin Access to a UK WordPress Gambling Platform
木马化的KeePass用于部署Cobalt Strike并窃取凭据
RVTools供应链攻击:Bumblebee恶意软件通过可信的VMware实用程序交付
Auth0-PHP Vulnerability Enables Unauthorized Access for Attackers
Critical security vulnerability has been discovered in the Auth0-PHP SDK that could potentially allow unauthorized access to applications through brute force attacks on session cookie authentication tags. The vulnerability specifically affects versions 8.0.0-BETA1 and newer of the SDK when configured with CookieStore for session storage. A patch has been released in version 8.14.0, and Okta, […]
The post Auth0-PHP Vulnerability Enables Unauthorized Access for Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Ivanti EPMM 0-day Vulnerability Actively Exploited in the Wild
Ivanti has disclosed two zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM) solution. When chained together, these vulnerabilities allow attackers to execute unauthenticated remote code. Security researchers have confirmed active exploitation in the wild, with the Shadowserver Foundation tracking nearly 800 vulnerable instances still exposed online. The vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, were disclosed […]
The post Ivanti EPMM 0-day Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News.
Active Exploitation of Ivanti EPMM Zero-Day Vulnerability in the Wild
Security researchers at The Shadowserver Foundation have identified active exploitation attempts targeting a critical zero-day vulnerability in Ivanti’s Enterprise Mobility Management (EPMM) platform. The vulnerability, tracked as CVE-2025-4427, can be chained with CVE-2025-4428 to achieve remote code execution (RCE), posing a significant threat to unpatched systems. Recent monitoring shows a concerning number of vulnerable instances […]
The post Active Exploitation of Ivanti EPMM Zero-Day Vulnerability in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Microsoft unveils Windows AI Foundry for AI-powered PC apps
Hacker Arrested for Taking Over SEC Social Media to Spread False Bitcoin News
Alabama man has been sentenced to 14 months in prison for orchestrating a sophisticated SIM swap attack that allowed him to hijack the U.S. Securities and Exchange Commission’s (SEC) social media account on X, formerly known as Twitter. The unauthorized access was used to post false information about Bitcoin ETF approvals, causing significant market volatility […]
The post Hacker Arrested for Taking Over SEC Social Media to Spread False Bitcoin News appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.