Aggregator
特朗普政府发布加强国家网络安全的行政命令
9th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES American tax company, Optima Tax Relief, has disclosed a ransomware attack that resulted in the theft of 69GB of sensitive data, including corporate records and customer case files containing personal information such […]
The post 9th June – Threat Intelligence Report appeared first on Check Point Research.
New Mirai botnet targets TBK DVRs by exploiting CVE-2024-3721
CVE-2025-3582 | Newsletter Plugin up to 8.84 on WordPress Form Setting cross site scripting (EUVD-2025-17434)
CVE-2018-12071 | CodeIgniter up to 3.1.8 Session Library session fixiation (EUVD-2022-3879)
CVE-2025-5863 | Tenda AC5 15.03.06.47 /goform/SetRebootTimer formSetRebootTimer rebootTime stack-based overflow (EUVD-2025-17437)
CVE-2025-5865 | RT-Thread 5.1.0 Parameter lwp_syscall.c sys_select timeout memory corruption (Issue 10298 / EUVD-2025-17440)
CVE-2024-9407 | Red Hat Enterprise Linux/OpenShift Container Platform Bind-propagation Option mount input validation (EUVD-2024-3036 / Nessus ID 209515)
CVE-2025-5893 | Honding Smart Parking Management System up to 1.4 exposure of sensitive system information to an unauthorized control sphere (EUVD-2025-17439)
CVE-2025-5866 | RT-Thread 5.1.0 lwp_syscall.c sys_sigprocmask how array index (Issue 10300 / EUVD-2025-17438)
Сверхзвук над США снова в законе — Трамп развязал руки авиации одной подписью
Удалил папку — открыл уязвимость: Microsoft выпустила "лечение" дыры в защите Windows
FBI Warns Smart Home Users of Badbox 2.0 Botnet Threat
Malicious npm Utility Packages Enable Attackers to Wipe Production Systems
Socket’s Threat Research Team has uncovered two malicious npm packages, express-api-sync and system-health-sync-api, designed to masquerade as legitimate utilities while embedding destructive backdoors capable of annihilating production systems. Published under the npm alias “botsailer” with the associated email anupm019@gmail[.]com, these packages represent a shift from traditional data theft to outright sabotage. New Wave of Sabotage […]
The post Malicious npm Utility Packages Enable Attackers to Wipe Production Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Сослался на фейковое дело — получил уголовку. Адвокатов больше не прощают за баловство с ChatGPT
Weekly Update 455
The bot-fighting is a non-stop battle. In this week's video, I discuss how we're tweaking Cloudflare Turnstile and combining more attributes around how bot-like requests are, and... it almost worked. Just as I was preparing to write this intro, I found a small spike of anomalous