Aggregator
North Korean hackers trojanize gaming platform to spy on ethnic Koreans in China
A gaming platform built for ethnic Koreans in China has been serving backdoored Windows and Android software to its users since late 2024. The platform, sqgame[.]net, hosts traditional card and board games for a community that sits along the North Korean border and includes many refugees and defectors. ESET researchers tied the operation to ScarCruft, a North Korea-aligned espionage group also tracked as APT37 and Reaper, which has been active since at least 2012. How … More →
The post North Korean hackers trojanize gaming platform to spy on ethnic Koreans in China appeared first on Help Net Security.
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
Trellix Reveals Unauthorized Access to Source Code
4 года на полную зачистку: Росмолодежь берет интернет под контроль ради традиционных ценностей
Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan
Trajan: CI/CD Security Scanner Trajan scans CI/CD pipelines for security vulnerabilities that attackers use to compromise software supply
The post Supply Chains in the Crosshairs: Scan and Simulate Multi-Stage Attacks with Trajan appeared first on Penetration Testing Tools.
Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine
A fake website claiming to offer an official macOS version of the popular text editor Notepad++ has been making rounds online, raising serious cybersecurity concerns across the tech community. The site, operating under the domain notepad-plus-plus-mac.org, falsely presents itself as the official release of Notepad++ for Apple devices, misleading thousands of users who simply want […]
The post Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine appeared first on Cyber Security News.
CVE-2026-33846 | GnuTLS DTLS Handshake Fragment Reassembly merge_handshake_packet message_length length parameter (Nessus ID 312106)
CVE-2026-3832 | GnuTLS Certificate Status Protocol early validation (Nessus ID 312106 / WID-SEC-2026-1312)
CVE-2026-31748 | Linux Kernel up to 6.19.11 comedi me2600_xilinx_download buffer overflow (WID-SEC-2026-1346)
CVE-2026-31747 | Linux Kernel up to 6.19.11 comedi me4000_xilinx_download buffer overflow (WID-SEC-2026-1346)
CVE-2026-31746 | Linux Kernel up to 6.18.21/6.19.11 zcrypt ap_init_apmsg memory leak (WID-SEC-2026-1346)
CVE-2026-31745 | Linux Kernel up to 6.19.11 reset_add_gpio_aux_device double free (WID-SEC-2026-1346)
CVE-2026-31744 | Linux Kernel up to 6.19.11 dev_energymodel_nl_get_perf_domains_doit return null pointer dereference (WID-SEC-2026-1346)
Банки отключили переписки между клиентами. Официально — редизайн. Неофициально — белые списки по требованию спецслужб
Educational tech firm Instructure data breach may have impacted 9,000 schools
Two Strikes, Half a Billion: How North Korean Hackers Seized 76% of All Stolen Crypto in Just 120 Days
North Korean cyber-operatives have once again demonstrated how a handful of precision strikes can fundamentally reshape annual cryptocurrency
The post Two Strikes, Half a Billion: How North Korean Hackers Seized 76% of All Stolen Crypto in Just 120 Days appeared first on Penetration Testing Tools.