Aggregator
CVE-2025-32985 | NetScout nGeniusONE JAR File hard-coded credentials
CVE-2025-32982 | NetScout nGeniusONE improper authorization
CVE-2025-32980 | NetScout nGeniusONE sudo Configuration privilege escalation
CVE-2025-32979 | NetScout nGeniusONE privilege escalation
CVE-2025-32983 | NetScout nGeniusONE up to 6.4.0 information exposure
CVE-2025-46333 | vancluever z2d 0.6.0 z2d.compositor.StrideCompositor.run memory corruption (ID 104)
.NET 实战对抗,内网渗透中红队通过 FSharp 执行命令绕过安全防护
.NET 内网攻防实战电子报刊
.NET 总第 69 期红队武器库和资源汇总
Critical Craft CMS RCE 0-Day Vulnerability Exploited in Attacks to Steal Data
According to security researchers at CERT Orange Cyberdefense, a critical remote code execution (RCE) vulnerability in Craft CMS is actively being exploited to breach servers and steal data. The vulnerability, tracked as CVE-2025-32432 and assigned a maximum CVSS score of 10.0, affects all versions of Craft CMS prior to 3.9.15, 4.14.15, and 5.6.17. CMS RCE […]
The post Critical Craft CMS RCE 0-Day Vulnerability Exploited in Attacks to Steal Data appeared first on Cyber Security News.
Live Webinar | AI vs. Identity Security: Who’s Really In Control?
Suspected Scattered Spider Head Extradited From Spain
Spanish authorities extradited on Wednesday the suspected head of the Scattered Spider cybercrime group to the United States, where he is being held without bail in a downtown Los Angeles federal prison. Tyler Buchanan, 23, faces charges for wire fraud, aggravated identity theft and conspiracy.
Two Ransomware Hacks Affect 1.1 Million Patients
Two separate ransomware hacks of a Maryland medical group and a California hospital resulted in data thefts affecting more than 1.1 million patients, according to recent reports to regulators. Cybercriminals claim to have leaked 480 gigabytes of data from one of the attacks.
CISA Grapples With Growing Exodus, Workforce Buyout Turmoil
The U.S. Cybersecurity and Infrastructure Security Agency on Friday dismissed as false reports of a looming buyout deadline and expanded resignation offers, calling them misinformation. There is no Monday deadline, a spokesperson said.
Endor Labs Raises $93M to Expand AI Code Protection Platform
CEO Varun Badhwar says Silicon Valley-based Endor Labs will use its $93 million Series B funding to build AI-powered code security tools, boost community outreach and target key acquisitions, helping enterprises secure faster, AI-assisted software development.
Critical ScreenConnect Vulnerability Let Attackers Inject Malicious Code
ConnectWise has released an urgent security patch for its ScreenConnect remote access software to address a serious vulnerability that could allow attackers to execute malicious code on affected systems. The vulnerability, identified as CVE-2025-3935 and tracked under CWE-287 (Improper Authentication), affects all ScreenConnect versions up to and including 25.2.3. Security researchers discovered that ScreenConnect versions […]
The post Critical ScreenConnect Vulnerability Let Attackers Inject Malicious Code appeared first on Cyber Security News.