Aggregator
Microsoft Warns of Void Blizzard Hackers Attacking Telecommunications & IT Organizations
Microsoft Threat Intelligence has unveiled a sophisticated Russian-affiliated cyberespionage group dubbed “Void Blizzard” (also known as LAUNDRY BEAR) that has been conducting widespread attacks against telecommunications and IT organizations since April 2024. The threat actor has successfully compromised critical infrastructure across NATO member states and Ukraine, with operations spanning government agencies, defense contractors, healthcare systems, […]
The post Microsoft Warns of Void Blizzard Hackers Attacking Telecommunications & IT Organizations appeared first on Cyber Security News.
Hackers Exploit Craft CMS Vulnerability to Inject Cryptocurrency Miner Malware
Threat actors have exploited a critical Remote Code Execution (RCE) vulnerability, identified as CVE-2025-32432, in the Craft Content Management System (CMS). Discovered by Orange Cyberdefense in mid-February 2025 and publicly disclosed on April 25, 2025, this flaw carries a maximum CVSS score of 10 due to its unauthenticated nature. Affecting Craft CMS versions from 3.0.0-RC1 […]
The post Hackers Exploit Craft CMS Vulnerability to Inject Cryptocurrency Miner Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
ruoyi4.8后台RCE分析
Arm Mali GPU Vulnerability Let Bypass MTE and Gain Arbitrary Kernel Code Execution
Security researchers have uncovered a critical vulnerability in Arm’s Mali GPU driver that allows malicious Android applications to bypass Memory Tagging Extension (MTE) protections and achieve arbitrary kernel code execution. The vulnerability, designated CVE-2025-0072, represents a significant threat to devices equipped with newer Arm Mali GPUs utilizing the Command Stream Frontend (CSF) architecture, including Google’s […]
The post Arm Mali GPU Vulnerability Let Bypass MTE and Gain Arbitrary Kernel Code Execution appeared first on Cyber Security News.
CVE-2025-48708
Gmail 用户关注质子邮件,以提高隐私保护水平
SafePay 勒索软件袭击了万宝路-切斯特菲尔德病理公司,在一次重大外泄事件中窃取了 23.5 万人的个人数据。
CVE-2025-5271 | Mozilla Firefox up to 138 Devtools injection
CVE-2025-5270 | Mozilla Firefox up to 138 cleartext transmission (Nessus ID 237299)
CVE-2025-5265 | Mozilla Firefox up to 138 on Windows Copy as cURL Remote Code Execution (Nessus ID 237301)
APT36 and Sidecopy Hackers Target India’s Critical Infrastructure with Malware Attacks
Seqrite Labs, India’s largest malware analysis facility, has uncovered a sophisticated campaign dubbed Operation Sindoor, orchestrated by Pakistan-aligned threat groups APT36 and Sidecopy. Launched on May 7, 2025, this state-sponsored Advanced Persistent Threat (APT) activity, combined with coordinated hacktivist operations, targeted India’s critical sectors, including defense, government IT infrastructure, healthcare, telecom, and education. Operation Sindoor […]
The post APT36 and Sidecopy Hackers Target India’s Critical Infrastructure with Malware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.