Aggregator
CVE-2025-15545 | TP-Link Archer RE605X prior (EU)_V3_20260113/(US)_V3_20260126 Backup Restore input validation (EUVD-2025-206536)
CVE-2025-15541 | TP-Link VX800v 1.0 SFTP Service link following (EUVD-2025-206516)
CVE-2025-15542 | TP-Link VX800v 1.0 INVITE Message unusual condition (EUVD-2025-206533)
CVE-2025-15543 | TP-Link VX800v 1.0 USB HTTP Access Path link following (EUVD-2025-206534)
CVE-2026-26736 | Totolink A3002RU 3.0.0-B20220304.1804 formIpv6Setup static_ipv6 stack-based overflow
CVE-2026-1638 | Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16 /goform/mDMZSetCfg dmzIp command injection (CNNVD-202601-4966)
MaaS VIP Keylogger Campaign Uses Steganography and In-Memory Execution to Steal Credentials at Scale
A sophisticated credential-stealing campaign built around a tool called VIP Keylogger has emerged as a serious threat to organizations and individuals. Unlike conventional malware that drops files onto a victim’s hard drive, this keylogger runs entirely in memory, making it far harder for traditional security tools to detect. The campaign was first spotted through suspicious […]
The post MaaS VIP Keylogger Campaign Uses Steganography and In-Memory Execution to Steal Credentials at Scale appeared first on Cyber Security News.
Fake CleanMyMac Site Uses ClickFix Trick to Install SHub Stealer on macOS
Sean Cairncross lays out what’s coming next for Trump’s cyber strategy
The national cyber director is pitching an approach that blends cyber operations with diplomacy, law enforcement and pressure on CEOs to shore up their organizations.
The post Sean Cairncross lays out what’s coming next for Trump’s cyber strategy appeared first on CyberScoop.
CVE-2025-70039 | linagora twake 2023.Q1.1223 os command injection
CVE-2025-70034 | mscdex ssh2 1.17.0 incorrect regex
CVE-2025-70037 | linagora Twake 2023.Q1.1223 redirect
CVE-2025-70038 | linagora Twake 2023.Q1.1223 neutralization
CVE-2025-15568 | TP-Link Archer AXE75 up to 1.3.2 Build 20250107 Web Module os command injection
Ваш смартфон станет еще меньше. Физики придумали, как втиснуть громоздкие радиодетали в микромир
Microsoft Teams will tag third-party bots trying to join meetings
ShinyHunters claims ongoing Salesforce Aura data theft attacks
Signal Confirms Targeted Phishing Attacks Resulting in Account Takeovers
Signal has officially confirmed an ongoing wave of targeted phishing campaigns resulting in successful account takeovers for high-profile users, including journalists and government officials. The encrypted messaging service explicitly stated that its core infrastructure and end-to-end encryption protocols remain intact and entirely uncompromised. Rather than exploiting technical vulnerabilities, threat actors are bypassing security boundaries by […]
The post Signal Confirms Targeted Phishing Attacks Resulting in Account Takeovers appeared first on Cyber Security News.