Aggregator
CVE-2025-40545 | SolarWinds Observability Self-Hosted redirect (EUVD-2025-197926 / WID-SEC-2025-2615)
Shai-Hulud 2.0: over 14,000 secrets exposed
On November 24, a new wave of the Shai-Hulud supply chain attack emerged. The threat actors exfiltrate stolen credentials directly to GitHub repositories created with compromised tokens. GitGuardian identified 14,206 secrets across 487 organizations, with 2,485 still valid.
The post Shai-Hulud 2.0: over 14,000 secrets exposed appeared first on Security Boulevard.
[Control systems] CISA ICS security advisories (AV25-782)
CVE-2025-63433 | Xtooltech Xtool AnyScan App up to 4.40.40 on Android hard-coded key (EUVD-2025-198966)
CVE-2025-63432 | Xtooltech Xtool AnyScan Android Application up to 4.40.40 SSL certificate validation (EUVD-2025-198967)
А вы знали, что ваш VPN теперь видно? Илон Маск нашел способ показать всем, что вы врете о своем местоположении
Hackers Leveraging WhatsApp to Silently Install Malware to Harvest Logs and Contact Details
A new malware campaign targeting Brazilian users has emerged, using WhatsApp as its primary distribution channel to spread banking trojans and harvest sensitive information. This sophisticated attack leverages social engineering by exploiting the trust victims place in their existing contacts, making the malicious files appear legitimate. The campaign begins with phishing emails containing archived VBS […]
The post Hackers Leveraging WhatsApp to Silently Install Malware to Harvest Logs and Contact Details appeared first on Cyber Security News.