Aggregator
CVE-2025-9146 | Linksys E5600 1.1.0.26 Firmware checkFw.sh verify_gemtek_header risky encryption
Хакеры против «РЕД СОФТ»: компания выставила свою СУБД на проверку багбаунти-охотников
Crypto Developers Attacked With Malicious npm Packages to Steal Login Details
A sophisticated new threat campaign has emerged targeting cryptocurrency developers through malicious npm packages designed to steal sensitive credentials and wallet information. The attack, dubbed “Solana-Scan” by researchers, specifically targets the Solana cryptocurrency ecosystem by masquerading as legitimate software development kits and scanning tools. The campaign centers around multiple malicious npm packages, including “solana-pump-test” and […]
The post Crypto Developers Attacked With Malicious npm Packages to Steal Login Details appeared first on Cyber Security News.
CVE-2025-38553 | Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 netem_enqueue recursion
CVE-2025-9145 | Scada-LTS 2.7.8.1 SVG File view_edit.shtm backgroundImageMP cross site scripting
CVE-2025-9144 | Scada-LTS 2.7.8.1 publisher_edit.shtm Name cross site scripting
CVE-2025-9143 | Scada-LTS 2.7.8.1 mailing_lists.shtm name/userList/address cross site scripting
Submit #628642: Linksys E5600 1.1.0.26 CWE-327 Use of a Broken or Risky Cryptographic Algorithm [Accepted]
CVE-2025-49797 | Brother Industries/Toshiba Tec Driver Installer on Windows file access (EUVD-2025-19089)
Submit #628448: Scada-LTS 2.7.8.1 Cross Site Scripting [Accepted]
Submit #628445: Scada-LTS 2.7.8.1 Cross Site Scripting [Accepted]
Submit #628437: Scada-LTS 2.7.8.1 Cross Site Scripting [Accepted]
Malicious npm Packages Target Crypto Developers to Steal Login Credentials
A sophisticated threat campaign dubbed “Solana-Scan” has emerged, deploying malicious npm packages aimed at infiltrating the Solana cryptocurrency ecosystem. Identified by the Safety research team through advanced malicious package detection technology, this operation involves a threat actor operating under the handle “cryptohan” and associated with the email [email protected]. The actor has published packages masquerading as […]
The post Malicious npm Packages Target Crypto Developers to Steal Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.