Aggregator
CVE-2024-36030 | Linux Kernel up to 6.8.8 octeontx2-af rvu_npc.c rvu_npc_freemem double free (f5aa87a2c0a7/6e965eba43e9 / WID-SEC-2024-1259)
CVE-2024-36025 | Linux Kernel up to 5.15.155/6.1.86/6.6.27/6.8.6 scsi qla_edif_app_getstats elem[] off-by-one (Nessus ID 209018 / WID-SEC-2024-1259)
CVE-2024-36026 | Linux Kernel up to 6.1.86/6.6.27/6.8.6 MP1_UNLOAD denial of service (WID-SEC-2024-1259)
CVE-2024-36027 | Linux Kernel up to 6.8.7 btrfs_clear_buffer_dirty allocation of resources (f4b994fccbb6/68879386180c / WID-SEC-2024-1259)
CVE-2024-36024 | Linux Kernel up to 6.8.5 AMD Display wake_and_executes race condition (2aac38744561/6226a5aa7737 / WID-SEC-2024-1259)
Affiliates Flock to ‘Soulless’ Scam Gambling Machine
研究显示 AI 的普及与美国初级工作的减少相关
Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same Names
Malware devs abuse Anthropic’s Claude AI to build ransomware
Here’s what you missed on Office Hours: August 2025
8% нашей ДНК принадлежат “древним чужим”. Учёные впервые показали их лицо… и оно не безобидное
Microsoft Word will save your files to the cloud by default
Cisco UCS Manager Software Flaw Allows Attackers to Inject Malicious Commands
Cisco has released urgent security updates to remediate two medium-severity command injection vulnerabilities in its UCS Manager Software that could allow authenticated administrators to execute arbitrary commands and compromise system integrity. Disclosed on August 27, 2025, the advisory (cisco-sa-ucs-multi-cmdinj-E4Ukjyrz) affects multiple UCS fabric interconnect platforms and underscores the importance of timely patching to prevent potential […]
The post Cisco UCS Manager Software Flaw Allows Attackers to Inject Malicious Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Cisco IMC Virtual Keyboard Vulnerability Allows Attackers to Redirect Users to Malicious Websites
Cisco has released urgent security updates to remediate a high-severity vulnerability in its Integrated Management Controller (IMC) virtual keyboard video monitor (vKVM) module that could allow unauthenticated, remote attackers to hijack sessions and redirect users to malicious websites. The flaw, tracked as CVE-2025-20317, carries a CVSS base score of 7.1 and affects a wide range […]
The post Cisco IMC Virtual Keyboard Vulnerability Allows Attackers to Redirect Users to Malicious Websites appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers Abuse Microsoft Teams to Gain Remote Access on Windows With PowerShell-based Malware
Cybercriminals are increasingly weaponizing Microsoft Teams, exploiting the platform’s trusted role in corporate communications to deploy malware and seize control of victim systems. In a sophisticated campaign, threat actors are impersonating IT support staff in Microsoft Teams chats to trick employees into granting remote access, marking a dangerous evolution from traditional email-based phishing attacks. Social […]
The post Hackers Abuse Microsoft Teams to Gain Remote Access on Windows With PowerShell-based Malware appeared first on Cyber Security News.
State of Nevada Faces IT Outage Amid Cyberattack, Offices Suspended
The State of Nevada became the target of a significant cyberattack which resulted in a substantial network security incident impacting government infrastructure across multiple agencies. According to an official communication from the Governor’s Technology Office, state officials rapidly identified the breach and immediately commenced continuous recovery efforts aimed at containing the incident and restoring affected […]
The post State of Nevada Faces IT Outage Amid Cyberattack, Offices Suspended appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
BadSuccessor Post-Patch: Leveraging dMSAs for Credential Acquisition and Lateral Movement in Active Directory
Microsoft’s recent patch for the BadSuccessor vulnerability (CVE-2025-53779) has successfully closed the direct privilege escalation path, but security researchers warn that the underlying technique remains viable for sophisticated attackers. While the patch prevents immediate Domain Admin escalation through one-sided delegated Managed Service Account (dMSA) links, threat actors can still exploit the fundamental mechanics for credential […]
The post BadSuccessor Post-Patch: Leveraging dMSAs for Credential Acquisition and Lateral Movement in Active Directory appeared first on Cyber Security News.