Aggregator
Threat Actors Weaponize PDF Editor Trojan to Convert Devices into Proxies
Researchers have discovered a complex campaign using trojanized software that uses authentic code-signing certificates to avoid detection and turn compromised machines into unintentional residential proxies, according to a recent threat intelligence notice from Expel Security. The operation begins with files bearing the code-signing signature of “GLINT SOFTWARE SDN. BHD.,” a seemingly legitimate entity whose credentials […]
The post Threat Actors Weaponize PDF Editor Trojan to Convert Devices into Proxies appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Microsoft asks customers for feedback on reported SSD failures
CVE-2024-4813 | Ruijie RG-UAC up to 20240506 interface_commit.php Name os command injection
CVE-2024-4814 | Ruijie RG-UAC up to 20240506 static_route_edit_commit.php oldipmask/oldgateway os command injection
CVE-2024-4815 | Ruijie RG-UAC up to 20240506 detail.php filename os command injection
CVE-2024-4816 | Ruijie RG-UAC up to 20240506 gre_add_commit.php name/remote/local/IP os command injection
CVE-2025-53187 | ABB ASPECT 3.07 code injection
CVE-2025-9043 | Seagate Toolkit prior 2.34.0.33 Program.exe unquoted search path
CVE-2025-57700 | Delta Electronics DIAEnergie up to 1.11.00.002 cross site scripting (PCSA-2025-00012)
CVE-2025-57701 | Delta Electronics DIAEnergie up to 1.11.00.002 cross site scripting (PCSA-2025-00012)
CVE-2025-57702 | Delta Electronics DIAEnergie up to 1.11.00.002 cross site scripting (PCSA-2025-00012)
CVE-2025-57702 | Delta Electronics DIAEnergie up to 1.11.00.002 cross site scripting (PCSA-2025-00012)
CVE-2025-8973 | SourceCodester Cashier Queuing System 1.0 /Actions.php Username sql injection
CVE-2025-9011 | PHPGurukul Online Shopping Portal Project 2.0 /shopping/signup.php emailid sql injection (EUVD-2025-24983)
CVE-2025-9012 | PHPGurukul Online Shopping Portal Project 2.0 bill-ship-addresses.php billingpincode sql injection (EUVD-2025-24987)
CVE-2025-9013 | PHPGurukul Online Shopping Portal Project 2.0 password-recovery.php emailid sql injection (EUVD-2025-24986)
CVE-2025-8990 | code-projects Online Medicine Guide 1.0 /browsemdcn.php Search sql injection (EUVD-2025-24954)
Threat Actors Abuse AI Website Creation App to Deliver Malware
Cybercriminals have discovered a new avenue for malicious activities by exploiting Lovable, an AI-powered website creation platform, to develop sophisticated phishing campaigns and malware delivery systems. The platform, designed to democratize web development through natural language prompts, has inadvertently become a tool for threat actors seeking to create convincing fraudulent websites with minimal technical expertise. […]
The post Threat Actors Abuse AI Website Creation App to Deliver Malware appeared first on Cyber Security News.