Aggregator
Updated Response to CISA Advisory (AA23-352A): #StopRansomware: Play Ransomware
AttackIQ has released an updated attack graph in response to the recently revised CISA Advisory (AA23-352A) which disseminates Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs) associated with the Play Ransomware group, identified through FBI investigations as recently as May 2025.
The post Updated Response to CISA Advisory (AA23-352A): #StopRansomware: Play Ransomware appeared first on AttackIQ.
The post Updated Response to CISA Advisory (AA23-352A): #StopRansomware: Play Ransomware appeared first on Security Boulevard.
AitM Phishing Attacks on Microsoft 365 and Google Aimed at Stealing Login Credentials
A dramatic escalation in phishing attacks leveraging Adversary-in-the-Middle (AiTM) techniques has swept across organizations worldwide in early 2025, fueled by the rapid evolution and proliferation of Phishing-as-a-Service (PhaaS) platforms. Sekoia researchers and threat intelligence teams are sounding the alarm as these attacks become more complex, harder to detect, and increasingly effective at bypassing even advanced […]
The post AitM Phishing Attacks on Microsoft 365 and Google Aimed at Stealing Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-6035 | GIMP Despeckle Plugin integer overflow
CVE-2025-49080 | Absolute Security Secure Access up to 13.53 denial of service (EUVD-2025-18200)
CVE-2025-5982 | GitLab Enterprise Edition up to 17.10.7/17.11.3/18.0.1 IP Access Restriction insufficient granularity of access control (Issue 514456 / EUVD-2025-18195)
CVE-2024-55567 | Insyde InsydeH2O prior 05.47.01/05.55.01/05.62.01/05.71.01 UsbCoreDxe input validation
CVE-2023-45256 | EuroInformation MoneticoPaiement module up to 1.1.0 on PrestaShop transaction.php TPE/societe/MAC/reference/aliascb sql injection
Google Chrome to Distrust Chunghwa Telecom and Netlock Certificate Authorities (CAs)—What’s Next?
Recently, Google announced that starting August 1, 2025, the Google Chrome browser will no longer trust TLS certificates issued by Chunghwa Telecom and Netlock Certificate Authorities (CAs). According to Google, the decision follows a pattern of compliance failures and a lack of measurable progress in addressing publicly reported issues. Chunghwa Telecom is Taiwan’s largest integrated […]
The post Google Chrome to Distrust Chunghwa Telecom and Netlock Certificate Authorities (CAs)—What’s Next? appeared first on Security Boulevard.
Мир стал понятнее: доказано, как из симметричных уравнений рождается несимметричная реальность
Alleged Data Breach of VYTL-SFT Verahealth Medical Platform
Fog ransomware attack on Asia financial org draws attention over use of employee monitoring software
OneLogin AD Connector Vulnerabilities Expose Authentication Credentials
A critical security vulnerability in OneLogin’s Active Directory (AD) Connector service has exposed enterprise authentication systems to significant risk The flaw, now reportedly fixed, uncovered by SpecterOps allowed malicious actors to obtain authentication credentials, impersonate users, and access sensitive applications through OneLogin’s platform. OneLogin, a prominent identity and access management (IAM) solution, integrates with popular […]
The post OneLogin AD Connector Vulnerabilities Expose Authentication Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Randall Munroe’s XKCD ‘Neighbor-Source Heat Pump’
via the comic artistry and dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Neighbor-Source Heat Pump’ appeared first on Security Boulevard.
Predator spotted in Mozambique for first time, another sign of spyware’s availability
Мы столетиями строили модели полюсов Солнца — и наконец узнали, как сильно ошибались
Researchers warn of ongoing Entra ID account takeover campaign
Attackers are using the TeamFiltration pentesting framework to brute-force their way into Microsoft Entra ID (formerly Azure AD) accounts, Proofpoint researchers have discovered. “Proofpoint’s research indicates that while simulated intrusions using TeamFiltration date back nearly to the tool’s initial release in 2021, there has recently been a surge in login attempts associated with its use,” they shared. “This increase in activity, attributed to UNK_SneakyStrike’s ongoing campaign, began in December 2024 and peaked in January 2025. … More →
The post Researchers warn of ongoing Entra ID account takeover campaign appeared first on Help Net Security.
Threat Actors Using Bat Files to Deploy Quasar RAT
Remote Access Trojans (RATs) like Quasar have been a persistent threat for years, enabling attackers to control infected systems remotely. Recent SANS research has uncovered a new and particularly stealthy Quasar campaign, characterized by strong obfuscation and an innovative anti-sandbox technique. The infection begins with a batch (.bat) script attached to a seemingly harmless document. When […]
The post Threat Actors Using Bat Files to Deploy Quasar RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-7562 | Revenera InstallShield 2021 R2/2022 R2/2023 R2 Standalone MSI Setup temp file (EUVD-2024-54679)
Threat Actors Exploiting Expired Discord Invite Links to Deliver Multi-Stage Malware
Cybercriminals have discovered a sophisticated new attack vector that exploits a critical flaw in Discord’s invitation system, allowing them to hijack expired invite links and redirect unsuspecting users to malicious servers hosting advanced malware campaigns. This emerging threat leverages the trusted nature of Discord, a platform used by millions of gamers and communities worldwide, to […]
The post Threat Actors Exploiting Expired Discord Invite Links to Deliver Multi-Stage Malware appeared first on Cyber Security News.