Aggregator
US Disrupts Massive Cell Phone Array in New York
This is a weird story:
The US Secret Service disrupted a network of telecommunications devices that could have shut down cellular systems as leaders gather for the United Nations General Assembly in New York City.
The agency said on Tuesday that last month it found more than 300 SIM servers and 100,000 SIM cards that could have been used for telecom attacks within the area encompassing parts of New York, New Jersey and Connecticut.
“This network had the power to disable cell phone towers and essentially shut down the cellular network in New York City,” said special agent in charge Matt McCool...
The post US Disrupts Massive Cell Phone Array in New York appeared first on Security Boulevard.
Купюры пахнут прошлым. Но именно они становятся щитом в час угрозы
CVE-2025-51818 | MCCMS 2.7.0 Backups.php file access (EUVD-2025-25468)
CVE-2025-48459 | Apache IoTDB up to 2.0.4 deserialization
CVE-2025-48392 | Apache IoTDB up to 2.0.4 denial of service
CVE-2025-36174 | IBM Integrated Analytics System up to 1.0.30.0 unrestricted upload (EUVD-2025-25664)
【安全圈】CISA警告:Chrome零日漏洞CVE-2025-10585遭在野利用
【安全圈】黑客利用Pandoc SSRF漏洞瞄准AWS EC2凭证
【安全圈】Stellantis确认客户数据泄露,汽车制造业再陷供应链攻击阴影
【安全圈】无人机闯入空域致哥本哈根与奥斯陆机场大规模停飞
iframe Security Exposed: The Blind Spot Fueling Payment Skimmer Attacks
Vegas Gambling Giant Hit by Cyber Incident, Employee Data Exposed
Supply chain attacks are exploiting our assumptions
OnePlus OxygenOS Vulnerability Allows Any App to Read SMS Data Without Permission
A severe security vulnerability in OnePlus OxygenOS has been discovered that allows any installed application to read SMS and MMS messages without requesting permission or notifying users. The flaw, designated CVE-2025-10184, affects multiple OnePlus devices running OxygenOS versions 12 through 15, potentially compromising SMS-based multi-factor authentication (MFA) systems and exposing sensitive personal communications to unauthorized […]
The post OnePlus OxygenOS Vulnerability Allows Any App to Read SMS Data Without Permission appeared first on Cyber Security News.
Salesforce CLI Installer Flaw Lets Attackers Run Code and Gain SYSTEM-Level Access
A serious security flaw in the Salesforce CLI installer (sf-x64.exe) has been assigned CVE-2025-9844. This weakness allows attackers to execute arbitrary code with SYSTEM-level privileges on Windows machines. Users who installed Salesforce CLI from untrusted sources may be at risk. The vulnerability stems from improper handling of file paths during installation, which can be abused […]
The post Salesforce CLI Installer Flaw Lets Attackers Run Code and Gain SYSTEM-Level Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Banking Trojans Targeting Android Users Disguise as Government and Trusted Payment Apps
Since August 2024, a financially motivated threat group has been targeting Android users in Indonesia and Vietnam with banking trojans disguised as official government identity and payment applications. By employing elaborate download mechanisms, reusing infrastructure, and leveraging template-based spoofed sites, the operators have used a coordinated campaign to evade detection and steal user credentials. The […]
The post Banking Trojans Targeting Android Users Disguise as Government and Trusted Payment Apps appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.