Aggregator
«У нас тут 0Day, а у вас нет патча». Mazda, NHS и Harvard стали жертвами халатности Oracle
China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users
APT24, a sophisticated cyber espionage group linked to China’s People’s Republic, has launched a relentless three-year campaign delivering BadAudio, a highly obfuscated first-stage downloader that enables persistent network access to targeted organizations. The threat actor has demonstrated remarkable adaptability by shifting from broad strategic web compromises to precision-targeted attacks focusing on Taiwan-based entities. The group’s […]
The post China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users appeared first on Cyber Security News.
CVE-2025-11456 | ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System Plugin eh_crm_new_ticket_post unrestricted upload
CVE-2025-11771 | TokenICO Cryptocurrency Token, Launchpad Presale, ICO & IDO, Airdrop Plugin createSaleRecord missing authentication
CVE-2025-10938 | UiPress lite Plugin up to 3.5.08 on WordPress User Information uip_process_block_query authorization
CVE-2025-11767 | Tips Shortcode Plugin up to 0.2.1 on WordPress tip cross site scripting
CVE-2025-11765 | Stock Tools Plugin up to 1.1 on WordPress Shortcode image_height/image_width cross site scripting
CVE-2025-11770 | BrightTALK Shortcode Plugin up to 2.4.0 on WordPress format cross site scripting
CVE-2025-11763 | Display Pages Shortcode Plugin up to 1.1 on WordPress column_count cross site scripting
CVE-2025-11764 | Shortcodes Bootstrap Plugin up to 1.1 on WordPress Type cross site scripting
CVE-2025-11768 | Islamic Phrases Plugin up to 2.12.2015 on WordPress Shortcode phrases cross site scripting
CVE-2025-11003 | UiPress Lite Plugin up to 3.5.08 on WordPress uip_save_ui_template cross site scripting
А причём тут звук? Зловред BadAudio три года водил за нос экспертов по кибербезопасности
Microsoft Teams e l’etichetta “in ufficio”: un badge digitale invisibile, tra privacy e normativa
MistTrack 荣获 HKICT Awards 2025 FinTech 金奖,推动链上合规新标杆
Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack
The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom’s internal systems as part of an ongoing exploitation campaign targeting Oracle E-Business Suite vulnerabilities. The hack uses a critical zero-day vulnerability (CVE-2025-61882) rated 9.8 on the CVSS scale, allowing attackers to execute arbitrary code without authentication. Broadcom, a major semiconductor and infrastructure software provider, becomes […]
The post Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack appeared first on Cyber Security News.