Aggregator
CVE-2023-29543 | Mozilla Firefox up to 111 Debugging API use after free (Bug 1816158 / EUVD-2023-33085)
CVE-2023-29544 | Mozilla Firefox up to 111 Garbage Collector resource consumption (Bug 1818781 / EUVD-2023-33086)
CVE-2022-50679 | Linux Kernel up to 5.10.151/5.15.75/6.0.5 net/core/xdp.c xdp_rxq_info_unreg allocation of resources (Nessus ID 278008)
CVE-2022-50673 | Linux Kernel up to 6.1.3 ext4 ext4_inode_attach_jinode use after free (Nessus ID 278009)
CVE-2023-53860 | Linux Kernel up to 6.1.54/6.5.4 permission (Nessus ID 278010)
Bun and done: The second coming of the Shai-Hulud worm
Notepad++ 遭流量劫持,更新程序被植入恶意程序
Over 644,000 Domains Exposed to Critical React Server Components Vulnerability
The Shadowserver Foundation has released alarming new data regarding the exposure of web applications to CVE-2025-55182, a critical vulnerability affecting React Server Components. Following significant improvements to their scanning methodologies, researchers have identified a massive attack surface comprising over 165,000 unique IP addresses and more than 644,000 domains hosting vulnerable code as of December 8, […]
The post Over 644,000 Domains Exposed to Critical React Server Components Vulnerability appeared first on Cyber Security News.
CVE-2025-13072 | HandL UTM Grabber Tracker Plugin up to 2.8.0 on WordPress cross site scripting (EUVD-2025-202398)
CVE-2025-13073 | HandL UTM Grabber Tracker Plugin up to 2.8.0 on WordPress cross site scripting (EUVD-2025-202397)
CVE-2025-13339 | Hippoo Mobile App for WooCommerce Plugin up to 1.7.1 on WordPress template_redirect path traversal (EUVD-2025-202393)
CVE-2025-13152 | Lenovo One Client up to 2.8.200.5081 uncontrolled search path (EUVD-2025-202422)
ClickFix Social Engineering Sparks Rise of CastleLoader Attacks
2026 年云安全预测与首席信息安全官(CISO)核心优先级
North Korean Hackers Deploy EtherRAT Malware in React2Shell Exploits
[Control systems] Schneider Electric security advisory (AV25-825)
Майнинг на тостере и 150000 атак — вот как умный дом тайком расходует ваше электричество
New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks
A sophisticated new phishing framework dubbed “Spiderman” has emerged in the cybercrime underground, dramatically lowering the barrier to entry for financial fraud. This toolkit, observed by Varonis, allows threat actors, even those with minimal technical skill, to spin up pixel-perfect replicas of legitimate banking portals in just a few clicks. The kit targets customers of […]
The post New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks appeared first on Cyber Security News.
When Vendors Become the Vulnerability: What the Marquis Software Breach Signals for Financial Institutions
In December 2025, a ransomware attack on Marquis Software Solutions, a data analytics and marketing vendor serving the financial sector, compromised sensitive customer information held by multiple banks and credit unions, according to Infosecurity Magazine. The attackers reportedly gained access through a known vulnerability in a firewall device connected to Marquis’s remote-access systems. The incident
The post When Vendors Become the Vulnerability: What the Marquis Software Breach Signals for Financial Institutions appeared first on Seceon Inc.
The post When Vendors Become the Vulnerability: What the Marquis Software Breach Signals for Financial Institutions appeared first on Security Boulevard.