Aggregator
CVE-2025-26986 | Pearl Plugin up to 3.4.8 on WordPress file inclusion
CVE-2016-11018 | Huge-IT gallery-images Plugin up to 1.8.9/1.9.0 on WordPress Header huge_it_image_gallery_ajax_callback Client-Ip/X-Forwarded-For sql injection
CVE-2023-50897 | Media File Renamer Plugin up to 5.7.7 on WordPress code injection
CVE-2022-2445 | Ultimate Member Plugin up to 2.5.0 on WordPress pack path traversal
New VanHelsing ransomware targets Windows, ARM, ESXi systems
CVE-2014-8739 | Creative Contact Form Plugin up to 1.0.0/2.0.1/6.4.4 on WordPress UploadHandler.php unrestricted upload (Exploit 35057 / EDB-35057)
CVE-2025-2748 | Kentico Xperience up to 13.0.178 File Upload cross site scripting
CVE-2025-2747 | Kentico Xperience up to 13.0.178 Sync Server improper authentication
CVE-2025-2746 | Kentico Xperience up to 13.0.172 Empty SHA1 Username improper authentication
CVE-2025-30163 | Cilium up to 1.16.7/1.17.1 fromNodes/toNodes authorization (GHSA-c6pf-2v8j-96mc)
CVE-2025-30162 | Cilium up to 1.15.14/1.16.7/1.17.1 authorization (GHSA-24qp-4xx8-3jvj)
CVE-2025-2749 | Kentico Xperience up to 13.0.178 Sync Server path traversal
FBI Warns of Document Converter Tools Due to Uptick in Scams
VanHelsing
Spit Happens: 23andMe is Bankrupt — Secure Your DNA Data NOW Already
Double hell-ix: Personal genomics firm tells customers your data is safe—but few will trust the loss-making biotech pioneer.
The post Spit Happens: 23andMe is Bankrupt — Secure Your DNA Data NOW Already appeared first on Security Boulevard.
Hackers Deploy Fake Semrush Ads to Steal Google Account Credentials
In a recent cybersecurity threat, hackers have been using fake Semrush ads to target Google account credentials. This campaign involves creating malicious ads that impersonate Semrush, a popular SEO and advertising platform used by many businesses, including 40% of Fortune 500 companies. The attackers aim to exploit the trust associated with Semrush to gain access […]
The post Hackers Deploy Fake Semrush Ads to Steal Google Account Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Using security information and event management tools to manage cyber security risks (ITSM.80.024)
Pocket Card Users Targeted in Sophisticated Phishing Campaign
A new phishing campaign targeting Japanese Pocket Card users has been uncovered by Symantec. The attackers are employing sophisticated tactics to deceive cardholders into divulging their login credentials, potentially compromising their financial accounts. Japanese Cardholders at Risk of Credential Theft The phishing operation begins with fraudulent emails masquerading as official notifications from Pocket Card’s online […]
The post Pocket Card Users Targeted in Sophisticated Phishing Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Albabat Ransomware Expands Reach to Target Linux and macOS Platforms
A recent report from Trend Micro has revealed that a new variant of the Albabat ransomware now targets Linux and macOS platforms, marking a significant expansion in its capabilities. Previously limited to Windows systems, this updated strain demonstrates the evolving sophistication of ransomware threats. The malware is still under active development, with its multi-OS functionality […]
The post Albabat Ransomware Expands Reach to Target Linux and macOS Platforms appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.