Aggregator
CVE-2023-53863 | Linux Kernel up to 6.4.3 netlink lib/iov_iter.c privilege escalation (Nessus ID 278013)
CVE-2024-38798 | TianoCore EDK2 up to <=stable202505 information disclosure (Nessus ID 278014)
New EtherRAT backdoor surfaces in React2Shell attacks tied to North Korea
Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits
Highlights: Introduction Throughout 2025, we conducted and published several reports related to our research on the Silver Fox APT. In some of them (for example, here), the threat actor delivered the well-known ValleyRAT backdoor, also referred to as Winos or Winos4.0, as the final stage. Since this malware family is widely used, modular, and often associated with Chinese threat actors […]
The post Cracking ValleyRAT: From Builder Secrets to Kernel Rootkits appeared first on Check Point Research.
В России вынесли первое постановление о штрафе за поиск «экстремистских материалов»
What’s Next for SOC in 2026: Get the Early-Adopter Advantage
Cybersecurity is about to hit a turning point in 2026. Attackers aren’t only testing AI but also building campaigns around it. Their tooling is getting faster, more adaptive, and far better at mimicking user behavior, from reconnaissance to phishing to initial access. The Shift is Already Underway With geopolitical tension rising and technology accelerating, SOCs are entering a period where both […]
The post What’s Next for SOC in 2026: Get the Early-Adopter Advantage appeared first on Cyber Security News.
CVE-2025-1161 | NomySost Nomysem up to May 2025 incorrect privileged apis (EUVD-2025-202404)
Ivanti security advisory (AV25-824)
Adobe security advisory (AV25-823)
JWT 常见测试点
G.O.S.S.I.P 阅读推荐 2025-12-10 BitUnlocker
Эпоха агентов наступает, но сначала нужен стандарт. Anthropic, OpenAI и Block объединились, чтобы разработать «порты» и «Readme» для умных помощников
Hack the Box Starting Point: Crocodile
Outbound HTB Walkthrough / Solution — Exploiting Roundcube Webmail CVE-2025–49113 and Rooting via…
The Phishing Pond TryHackMe Writeup
I Spied on Hackers So You Don’t Have To: How Dark Web Chatter Led to a $Cloud Misconfiguration Bug…
I Spied on Hackers So You Don’t Have To: How Dark Web Chatter Led to a $Cloud Misconfiguration Bug…
BNY Partners With Google on Financial Services AI Platform
BNY is integrating Google Cloud's Gemini Enterprise agentic artificial intelligence platform into its proprietary enterprise AI platform, Eliza. The move represents an evolution from AI as a pilot project to AI as infrastructure for the global financial services organization.