Aggregator
North Korea’s OtterCookie Malware Added a New Feature to Attack Windows, Linux, and macOS
A North Korea-linked attack group, known as WaterPlum (also referred to as Famous Chollima or PurpleBravo), has been actively targeting financial institutions, cryptocurrency operators, and FinTech companies globally. Since 2023, their infamous Contagious Interview campaign has utilized malware such as BeaverTail and InvisibleFerret to infiltrate systems. However, in September 2024, WaterPlum introduced a sophisticated new […]
The post North Korea’s OtterCookie Malware Added a New Feature to Attack Windows, Linux, and macOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Мем-койны обещают веселье, но заканчиваются как всегда: скам, убытки и ощущение, что тебя снова развели
CVE-2025-4540 | MTSoftware C-Lodop 6.6.1.1 CLodopPrintService unquoted search path
CVE-2025-4539 | Hainan ToDesk 4.7.6.3 DLL File Parser profapi.dll uncontrolled search path
Submit #566789: Lodop Web Printing Service C-Lodop 6.611 Unquoted Search Path [Accepted]
CVE-2025-4538 | kkFileView 4.4.0 /fileUpload File unrestricted upload
Submit #566698: Hainan Interesting Technology Co., Ltd todesk 4.7.6.3 privilege escalation [Accepted]
Одно уравнение смогло объяснить то, над чем суперкомпьютеры ломали голову десятилетиями
Submit #567142: kkFileView 4.4.0 Code Execution [Duplicate]
Submit #566596: kkFileView 4.4.0 Arbitrary File Writing [Accepted]
Submit #567159: kkFileView 4.4.0 Arbitrary File Upload [Duplicate]
Submit #567123: kkFileView 4.4.0 Stored XSS [Duplicate]
权限维持,通过 Sharp4WinService 指定任意程序转换为系统服务运行
福利 | 最专业、最全面的 [ .NET 代码审计 ] 体系化学习平台
.NET 总第 71 期红队武器库和资源汇总
权限维持,通过 Sharp4WinService 指定任意程序转换为系统服务运行
福利 | 最专业、最全面的 [ .NET 代码审计 ] 体系化学习平台
.NET 总第 71 期红队武器库和资源汇总
“PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram
A newly identified information-stealing malware, dubbed PupkinStealer, Developed in C# using the .NET framework, this lightweight yet effective malware targets sensitive user data, including browser credentials, desktop files, messaging app sessions, and screenshots. According to a CYFIRMA detailed analysis shared with Cyber Security News, PupkinStealer leverages Telegram’s Bot API for stealthy data exfiltration, underscoring the […]
The post “PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram appeared first on Cyber Security News.