Aggregator
CVE-2025-10304 | Everest Backup Plugin up to 2.3.8 on WordPress process_status_unlink authorization (EUVD-2025-200726 / CNNVD-202512-418)
CVE-2025-12585 | MxChat Plugin up to 2.5.5 on WordPress Conversation information disclosure (EUVD-2025-200727 / CNNVD-202512-419)
CISA warns of Chinese "BrickStorm" malware attacks on VMware servers
Amid rising threats, NATO holds its largest-ever cyberdefense exercise
Бесконечные патроны и 100 киловатт мощи. Япония нашла дешевый способ борьбы с роями дронов-камикадзе
CISA and NSA Warn of BRICKSTORM Malware Attacking VMware ESXi and Windows Environments
The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Canadian Centre for Cyber Security (Cyber Centre) issued a joint advisory today, warning of a sophisticated new malware campaign orchestrated by People’s Republic of China (PRC) state-sponsored cyber actors. The advisory details “BRICKSTORM,” a formidable backdoor designed to establish long-term persistence […]
The post CISA and NSA Warn of BRICKSTORM Malware Attacking VMware ESXi and Windows Environments appeared first on Cyber Security News.
Qilin
You must login to view this content
Alleged Leak of Unauthorized Monsta FTP Access; CVE-2025-34299
Prompt Injection Flaw in GitHub Actions Hits Fortune 500 Firms
A new class of prompt injection vulnerabilities, dubbed “PromptPwnd,” has been uncovered by cybersecurity firm Aikido Security. The flaws affect GitHub Actions and GitLab CI/CD pipelines that are integrated with AI agents, including Google’s Gemini CLI, Claude Code, and OpenAI Codex. The vulnerability has been confirmed to impact at least five Fortune 500 companies, with […]
The post Prompt Injection Flaw in GitHub Actions Hits Fortune 500 Firms appeared first on Cyber Security News.