Aggregator
Malicious JScript Loader Jailbreaked to Uncover Xworm Payload Execution Flow
Cybersecurity researchers have uncovered a sophisticated multi-stage attack chain utilizing JScript to deliver dangerous malware payloads. The attack, which employs a complex obfuscation technique, ultimately delivers either XWorm or Rhadamanthys malware depending on the victim’s geographic location. This loader operates through a meticulously crafted execution flow that begins with JScript, transitions to PowerShell, and culminates […]
The post Malicious JScript Loader Jailbreaked to Uncover Xworm Payload Execution Flow appeared first on Cyber Security News.
Добровольно, но по запросу: как бизнес сдаст данные в госозеро
CVE-2025-29281 | PerfreeBlog 4.0.11 unrestricted upload
CVE-2025-32606 | Listings for Buildium Plugin up to 0.1.4 on WordPress Setting cross-site request forgery
CVE-2024-13452 | Supsystic Contact Form Plugin up to 1.7.29 on WordPress Setting saveAsCopy cross-site request forgery
CVE-2025-2314 | User Profile Builder Plugin up to 3.13.5/3.13.6/3.13.7 on WordPress Shortcode cross site scripting
CVE-2025-26903 | InPost Gallery Plugin up to 2.1.4.3 on WordPress cross-site request forgery
CVE-2025-22263 | Global Gallery Plugin up to 8.8.0 on WordPress cross site scripting
CVE-2025-26748 | Arkhe Theme up to 3.11.0 on WordPress cross-site request forgery
CVE-2025-31380 | Paid Videochat Turnkey Site Plugin up to 7.3.11 on WordPress improper authentication
CVE-2025-32593 | Add Product Frontend for WooCommerce Plugin up to 1.0.6 on WordPress authorization
CVE-2025-32620 | fromdoppler Doppler Forms Plugin up to 2.4.5 on WordPress authorization
CVE-2025-32544 | WooCommerce Loyal Customers Plugin up to 2.6 on WordPress authorization
CVE-2025-26867 | Bulk Theme up to 1.0.11 on WordPress authorization
CVE-2025-32652 | Solace Extra Plugin up to 1.3.1 on WordPress unrestricted upload
CVE-2025-26920 | customify-theme Theme up to 0.4.8 on WordPress authorization
CVE-2025-30406:Gladinet 公司 Triofox 和 CentreStack 产品 RCE 漏洞被黑客恶意利用
CVE-2025-28137 | TOTOLINK A810R 4.1.2cu.5182_B20201026 setNoticeCfg NoticeUrl privilege escalation
Microsoft Disables ActiveX by Default in 365 to Block Malware Execution by Hackers
Microsoft has taken a critical step to enhance security across its productivity suite by disabling ActiveX controls by default in Microsoft 365 applications. This significant security update, which began rolling out earlier this month, aims to reduce the risk of malware and unauthorized code execution that has long plagued the legacy technology. Starting April 2025, […]
The post Microsoft Disables ActiveX by Default in 365 to Block Malware Execution by Hackers appeared first on Cyber Security News.