Aggregator
6000+ Apache ActiveMQ Instances Vulnerable to CVE-2026-34197 Exposed Online
More than 6,000 internet-exposed Apache ActiveMQ instances are still vulnerable to CVE-2026-34197. This newly tracked security flaw has now been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog. The exposure data comes from The Shadowserver Foundation, which said it has started daily internet scans for the flaw. In an update published on April 20, […]
The post 6000+ Apache ActiveMQ Instances Vulnerable to CVE-2026-34197 Exposed Online appeared first on Cyber Security News.
Sim-боксы, 2000 SIM-карт и шесть лет тюрьмы. В Ярославле накрыли три группы, помогавшие украинским кол-центрам обзванивать россиян
CISA flags new SD-WAN flaw as actively exploited in attacks
CVE-2018-8618 | Microsoft Edge/ChakraCore Chakra Scripting Engine memory corruption (EUVD-2022-2580 / Nessus ID 119591)
CVE-2022-20548 | Google Android 13.0 EqualizerEffect.cpp setParameter out-of-bounds write (A-240919398 / EUVD-2022-25808)
CVE-2022-20549 | Google Android 13.0 KeyMintUtils.cpp authToken2AidlVec out-of-bounds write (A-242702451 / EUVD-2022-25809)
DragonForce
You must login to view this content
F-35 是为不同战争而造的尖端战斗机
Akira
You must login to view this content
Hackers Use Nightmare-Eclipse Tools After Compromising FortiGate SSL VPN Access
A real-world intrusion campaign leveraging publicly available Nightmare-Eclipse privilege escalation tooling, BlueHammer, RedSun, and UnDefend, following what appears to be unauthorized access through a compromised FortiGate SSL VPN. The incident marks the first confirmed in-the-wild deployment of these tools against a live enterprise environment, raising urgent alarms for security teams globally. The tools at the […]
The post Hackers Use Nightmare-Eclipse Tools After Compromising FortiGate SSL VPN Access appeared first on Cyber Security News.
Submit #794681: bagisto v2.3.15 Cross Site Scripting [Accepted]
Submit #794680: bagisto v2.3.15 Server-Side Request Forgery [Accepted]
Блокировки, проверки и новые запреты. В России готовят третий пакет мер против мошенников
Chinese APT Targets Indian Banks, Korean Policy Circles
Cyber chief: UK faces "perfect storm" for cyber security
Scaling Your Media Workloads: Introducing Akamai’s New 8-Card VPU Plan
New cross domain guidance for government, industry and the wider security community
Gentlemen RaaS Attacking Windows, Linux With additional locker written in C for ESXi
A new ransomware-as-a-service (RaaS) operation known as “The Gentlemen” has emerged as a serious threat to corporate networks worldwide. Since appearing around mid-2025, this group has rapidly grown into a well-organized criminal platform, publicly claiming over 320 victims, with most attacks — more than 240 — recorded in the opening months of 2026. The speed […]
The post Gentlemen RaaS Attacking Windows, Linux With additional locker written in C for ESXi appeared first on Cyber Security News.