Aggregator
Linux USB 音频驱动漏洞或致攻击者执行任意代码
关于Foxmail邮件客户端存在跨站脚本攻击漏洞的安全公告
关于Foxmail邮件客户端存在跨站脚本攻击漏洞的安全公告
CVE-2025-32260 | detheme DethemeKit for Elementor Plugin up to 2.1.10 on WordPress authorization
CVE-2025-32236 | Woocommerce Advanced Product Organizer – Dynamic Sorting & Reordering Plugin authorization
CVE-2025-32198 | themefusecom Brizy Plugin up to 2.6.14 on WordPress cross site scripting
CVE-2025-32139 | FooBox Image Lightbox Plugin up to 2.7.33 on WordPress cross site scripting
CVE-2025-32199 | vcita Contact Form Builder Plugin up to 4.10.2 on WordPress cross site scripting
CVE-2025-2719 | Swatchly Plugin 1.2.8/1.4.0 on WordPress Options Update authorization
CVE-2025-3417 | Embedder Plugin 1.3/1.3.5 on WordPress ajax_set_global_option improper authorization
CVE-2025-2805 | ORDER POST Plugin up to 2.0.2 on WordPress Shortcode do_shortcode code injection
CVE-2025-2809 | azurecurve Shortcodes in Comments Plugin up to 2.0.2 on WordPress Shortcode do_shortcode code injection
Russian APT Hackers Using Device Code Phishing Technique to Bypass MFA
A sophisticated cyber campaign orchestrated by the Russian state-backed group Storm-2372 has emerged, exploiting device code phishing tactics to circumvent Multi-Factor Authentication (MFA) security measures. This targeted approach represents a significant escalation in threat actors’ capabilities to defeat advanced security systems through social engineering, allowing attackers to gain unauthorized access to high-value targets without triggering […]
The post Russian APT Hackers Using Device Code Phishing Technique to Bypass MFA appeared first on Cyber Security News.
CAPTCHA сломалась — теперь спам пишет ИИ и продаёт вам SEO
Oracle confirms the hack of two obsolete servers hacked. No Oracle Cloud systems or customer data were affected
Threat Actors Turning Messaging Service into a Cash Making Machine
A sophisticated fraud scheme known as SMS pumping is quietly draining millions from businesses worldwide by exploiting SMS verification systems. This cybercrime tactic, similar to a modern-day toll scam, involves artificially inflating SMS traffic through automated means, generating fraudulent revenue while leaving legitimate businesses to absorb unexpected costs. The scheme has become increasingly prevalent as […]
The post Threat Actors Turning Messaging Service into a Cash Making Machine appeared first on Cyber Security News.