Aggregator
CVE-2024-8176 | libexpat stack-based overflow (Nessus ID 233405)
CVE-2020-7676 | angular.js up to 1.7.x Regex cross site scripting (Nessus ID 233421)
CVE-2024-57996 | Linux Kernel up to 6.1.128/6.6.75/6.12.12/6.13.1 net_sched net/sched/sch_sfq.c array index (Nessus ID 233410)
CVE-2025-22230 | VMware Tools up to 12.5.0 on Windows authentication bypass (Nessus ID 233416)
Blacklock Ransomware Infrastructure Breached, Revealing Planned Attacks
Resecurity, a prominent cybersecurity firm, has successfully exploited a vulnerability in the Data Leak Site (DLS) of Blacklock Ransomware, gaining unprecedented access to the group’s infrastructure. This breach, occurring during the winter of 2024-2025, allowed researchers to collect substantial intelligence about the ransomware group’s activities and planned attacks. Exploitation of Local File Include Vulnerability The […]
The post Blacklock Ransomware Infrastructure Breached, Revealing Planned Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2008-3652 | ipsec-tools resource management (Nessus ID 34052 / ID 117251)
CVE-2021-32559 | pywin32 prior b301 ACE integer overflow (FEYE-2021-0017)
CVE-2021-45429 | VirusTotal YARA yara/libyara/libyara.c yr_set_configuration buffer overflow (Issue 1616)
CVE-2022-4671 | PixCodes Plugin up to 2.3.6 on WordPress Shortcode cross site scripting
CVE-2022-4470 | Widgets for Google Reviews Plugin up to 9.7 on WordPress Shortcode Attribute cross site scripting
CVE-2022-4651 | Justified Gallery Plugin up to 1.7.0 on WordPress Shortcode Attribute cross site scripting
CVE-2022-4763 | Icon Widget Plugin up to 1.2.x on WordPress Shortcode Attribute cross site scripting
CVE-2022-4781 | Accordion Shortcodes Plugin up to 2.4.2 on WordPress Shortcode Attribute cross site scripting
CVE-2009-2409 | VMware ESX Server 4.x Service Console cryptographic issues (Nessus ID 67960 / ID 216028)
CVE-2022-28810 | Zoho ManageEngine ADSelfService Plus up to 6121 Password os command injection
Classiscam Operators Use Automated Malicious Sites to Steal Financial Data
Classiscam, an automated scam-as-a-service operation, has been identified as a significant threat in Central Asia, leveraging sophisticated techniques to defraud users of online marketplaces and e-commerce platforms. This fraudulent scheme, highlighted in the High-Tech Crime Trends Report 2025, utilizes Telegram bots to generate fake websites that mimic legitimate services, effectively deceiving victims into sharing their […]
The post Classiscam Operators Use Automated Malicious Sites to Steal Financial Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.