Aggregator
CVE-2024-58250 | ppp up to 2.5.1 Passprompt Plugin untrusted search path (EUVD-2025-12338 / Nessus ID 237396)
CVE-2023-52703 | Linux Kernel up to 6.1.12 usb kalmia_send_init_packet uninitialized pointer (Nessus ID 237398)
CVE-2023-50711 | vmm-sys-util prior 0.12.0 deserialization (Nessus ID 237403)
CVE-2007-5290 | MailBee WebMail default.asp mode2 cross site scripting (EDB-30642 / XFDB-36979)
CVE-2025-3864 | hackney up to 1.23.x HTTP Connection release of resource
Ваш админ стал их точкой входа. И вместе с ним — вся ваша сеть
海洋在变暗
From Infection to Access: A 24-Hour Timeline of a Modern Stealer Campaign
CVE-2025-1753 | run-llama llama_index up to 0.4.0 CLI os.system files os command injection
CVE-2025-40673 | DinoRANK Invoice SDRYYMM-XXXXX.pdf authorization
银狐黑产组织最新Loader攻击样本分析
Mental Denial of Service: Narrative Malware and the Future of Resilience
Mental denial of service (DOS) is the manipulative content that hijacks the cognitive processing of individuals and institutions.
The post Mental Denial of Service: Narrative Malware and the Future of Resilience appeared first on Security Boulevard.
几乎所有成年美国人盐摄入量都超过建议量
Attackers hit MSP, use its RMM software to deliver ransomware to clients
A threat actor wielding the DragonForce ransomware has compromised an unnamed managed service provider (MSP) and pushed the malware onto its client organizations via SimpleHelp, a legitimate remote monitoring and management (RMM) tool. “Sophos MDR has medium confidence the threat actor exploited a chain of vulnerabilities that were released in January 2025,” the company’s incident responders shared on Tuesday. The vulnerabilities in question are CVE-2024-57727, CVE-2024-57728 and CVE-2024-57726, which can be used to compromise SimpleHelp … More →
The post Attackers hit MSP, use its RMM software to deliver ransomware to clients appeared first on Help Net Security.