Aggregator
North Korean Hackers Weaponize GitHub Infrastructure to Distribute Malware
Cybersecurity researchers have uncovered a sophisticated spearphishing campaign orchestrated by the North Korean threat group Kimsuky, leveraging GitHub as a critical piece of attack infrastructure to distribute malware since March 2025. This operation, identified through analysis of a malicious PowerShell script posted on X, showcases an alarming abuse of legitimate platforms like GitHub and Dropbox […]
The post North Korean Hackers Weaponize GitHub Infrastructure to Distribute Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers Allegedly Selling Intelbras Router 0-Day Exploit on Hacker Forums
A notorious threat actor has allegedly listed a previously unknown—or “0day”—exploit for Intelbras routers on a prominent hacker forum. This exploit poses significant risks for many users and organizations that rely on Intelbras hardware for their networking needs. The sale of such a zero-day exploit is prompting close monitoring from security researchers and professionals, given […]
The post Hackers Allegedly Selling Intelbras Router 0-Day Exploit on Hacker Forums appeared first on Cyber Security News.
Steelmaker Nucor Hacked – Attackers Gained Unauthorized Access to IT Systems
Charlotte-based steel giant Nucor Corporation disclosed a significant cybersecurity incident where threat actors gained unauthorized access to the company’s information technology infrastructure. The breach prompted temporary production shutdowns across multiple facilities as the company implemented emergency containment protocols and engaged federal law enforcement authorities to investigate the intrusion. According to the SEC filing report, Nucor’s […]
The post Steelmaker Nucor Hacked – Attackers Gained Unauthorized Access to IT Systems appeared first on Cyber Security News.
CoinMarketCap, Cointelegraph compromised to serve pop-ups to drain crypto wallets
The CoinMarketCap and CoinTelegraph websites have been compromised over the weekend to serve clever phishing pop-ups to visitors, asking them to verify/connect their crypto wallets. The CoinMarketCap compromise CoinMarketCap (aka CMC) is a website popular with crypto investors as it tracks cryptocurrency prices, market capitalizations, and trading volumes. On June 20, 2025, visitors to the site’s homepage were faced with a pop-up that urged them to connect their wallets to maintain access to their CMC … More →
The post CoinMarketCap, Cointelegraph compromised to serve pop-ups to drain crypto wallets appeared first on Help Net Security.
CVE-2025-28367 | mojoPortal up to 2.9.0.1 BetterImageGallery API Controller Web.Config ImageHandler path traversal
CVE-2025-27086 | HPE Performance Cluster Manager up to 1.12 GUI improper authentication
CVE-2025-28102 | flaskBlog 2.6.1 /createpost postContent cross site scripting (Issue 130 / EUVD-2025-12361)
CVE-2025-3841 | wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9 Jinja2 Template jam.py config['template'] special elements used in a template engine
CVE-2025-52920 | Innoshop up to 0.4.1 _ORDER_ID_ shipping_address_id/billing_address_id direct request (EUVD-2025-18869)
CVE-2025-52921 | InnoShop up to 0.4.1 File Manager Rename unprotected alternate channel (EUVD-2025-18868)
CVE-2025-52922 | Innoshop up to 0.4.1 FileManager API Endpoint /api/file_manager/files base_folder path traversal (EUVD-2025-18867)
Confucius Hackers Target Government and Military Entities Using WooperStealer Malware
The notorious Confucius hacking organization, first exposed by foreign security vendors in 2016, continues to pose a significant threat to government and military entities across South and East Asia. With attack activities dating back to 2013, this group has recently escalated its operations, targeting critical domestic units and industries with advanced tactics. Unveiling a Sophisticated […]
The post Confucius Hackers Target Government and Military Entities Using WooperStealer Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Data of more than 740,000 stolen in ransomware attack on Michigan hospital network
Critical Teleport Vulnerability Allows Remote Authentication Bypass
A critical security vulnerability, tracked as CVE-2025-49825, has been discovered in Teleport, a widely used open-source platform for secure access to servers, cloud applications, and infrastructure. This flaw enables remote attackers to bypass authentication controls, potentially granting unauthorized access to sensitive systems managed by Teleport. The Vulnerability The vulnerability affects Teleport Community Edition versions up […]
The post Critical Teleport Vulnerability Allows Remote Authentication Bypass appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
RapperBot Attacking DVRs to Gain Access Over Surveillance Cameras to Record Video
A sophisticated botnet campaign targeting digital video recorders (DVRs) has emerged as a significant threat to surveillance infrastructure worldwide, with cybercriminals exploiting vulnerable IoT devices to build massive botnets capable of large-scale distributed denial-of-service attacks. RapperBot, a variant of the notorious Mirai malware, has been systematically compromising DVR systems to gain unauthorized access to surveillance […]
The post RapperBot Attacking DVRs to Gain Access Over Surveillance Cameras to Record Video appeared first on Cyber Security News.