Aggregator
APT73
SASE Market Hits $2.4 Billion, Top Vendors Tighten Market Share Grip
The key to growing a cybersecurity career are soft skills
Gorilla Tag: режим «бога» в VR-мире или билет в киберхаос
深入浅出API测试|搜集分析与漏洞挖掘实战
CVE-2024-26713 | Linux Kernel up to 6.6.17/6.7/6.7.5 pseries iommu_device_register null pointer dereference (9978d5b744e0/d4f762d6403f/ed8b94f6e0ac)
CVE-2024-35928 | Linux Kernel up to 6.1.85/6.6.26/6.8.5 AMD GPU amdgpu_device_init memory leak (Nessus ID 210815)
CVE-2024-36885 | Linux Kernel up to 6.6.30/6.8.9 nvkm_firmware_ctor state issue (1a88c18da464/e05af0093028/52a6947bf576)
CVE-2024-41024 | Linux Kernel up to 6.6.40/6.9.9 FastRPC root_pd Privilege Escalation (5e305b5986dc/c69fd8afaceb/bab2f5e8fd5d)
CVE-2024-43903 | Linux Kernel up to 6.1.104/6.6.45/6.10.4 AMD Display amdgpu_dm_plane_handle_cursor_update null pointer dereference
CVE-2024-12626 | AutomatorWP Plugin up to 5.0.9 on WordPress a-0-o-search_field_value cross site scripting
CVE-2024-45818 | Xen VGA deadlock (Nessus ID 210883)
CVE-2024-45819 | Xen libxl information disclosure (Nessus ID 210883)
CVE-2024-26720 | Linux Kernel up to 6.7.5 writeback wb_dirty_limits divide by zero (Nessus ID 207773)
Beware Of Malicious SharePoint Notifications That Delivers Xloader Malware
Through the use of XLoader and impersonating SharePoint notifications, researchers were able to identify a sophisticated malware delivery campaign. A link that was disguised as a legitimate SharePoint notification was included in the emails that were sent out at the beginning of the attack. The engine flagged the message as malicious based on several factors: […]
The post Beware Of Malicious SharePoint Notifications That Delivers Xloader Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Malicious Supply Chain Attacking Moving From npm Community To VSCode Marketplace
Researchers have identified a rise in malicious activity on the VSCode Marketplace, highlighting the vulnerability of the platform to supply chain attacks similar to those previously seen in the npm community. Malicious actors are increasingly exploiting npm packages to distribute malicious code, mirroring tactics previously used in VSCode extensions that involve the npm package etherscancontracthandler, […]
The post Malicious Supply Chain Attacking Moving From npm Community To VSCode Marketplace appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2006-6363 | BlueSocket Bsc 2100 up to 5.1 admin.pl ad_name cross site scripting (EDB-29221 / XFDB-30735)
Hackers Weaponizing LNK Files To Create Scheduled Task And Deliver Malware Payload
TA397, also known as Bitter, targeted a Turkish defense organization with a spearphishing email containing a RAR archive, which included a decoy PDF, a malicious LNK file disguised as a PDF, and an ADS file with PowerShell code. This technique, common for TA397, leverages NTFS ADS to establish persistence and deploy further malware like wmRAT […]
The post Hackers Weaponizing LNK Files To Create Scheduled Task And Deliver Malware Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.