Aggregator
Yurei Ransomware Leverages SMB Shares and Removable Drives to Encrypt Files
Yurei ransomware first emerged in early September 2025, targeting Windows environments with a sophisticated Go-based payload designed for rapid, large-scale encryption. Once executed, the malware enumerates all accessible local and network drives, appends a .Yurei extension to each file, and writes unique ransom notes in every affected directory. Its operators then demand payment over Tor, […]
The post Yurei Ransomware Leverages SMB Shares and Removable Drives to Encrypt Files appeared first on Cyber Security News.
CVE-2025-43934 | Dell PowerProtect Data Domain with Data Domain Operating System LTS2023 path traversal (dsa-2025-333 / EUVD-2025-32909)
CVE-2025-11405 | SourceCodester Hotel and Lodge Management System 1.0 /del_tax.php ID sql injection (EUVD-2025-32908)
CVE-2025-61670 | bytecodealliance wasmtime up to 37.0.1 C API release of resource (GHSA-vvp9-h8p2-xwfc / EUVD-2025-32904)
CVE-2025-61776 | DependencyTrack dependency-track up to 4.13.4 .NET insufficiently protected credentials (GHSA-83g2-vgqh-mgxc / EUVD-2025-32901)
CVE-2025-45375 | Dell PowerProtect Data Domain with Data Domain Operating System LTS2023 stack-based overflow (dsa-2025-333 / EUVD-2025-32902)
银狐最新过沙箱高级免杀木马分析
Salesforce Refuses to Pay Ransom to Data-Stealing Hackers
Salesforce is refusing a demand by the hackers behind that widespread data-stealing attacks on its customers, which threatened to release massive amounts of the data unless the SaaS vendor negotiated a ransom payment. In an email, Salesforce reportedly told customers about its refusal to pay and offered them its support.
The post Salesforce Refuses to Pay Ransom to Data-Stealing Hackers appeared first on Security Boulevard.
CVE-2025-43727 | Dell PowerProtect Data Domain with Data Domain Operating System LTS2023 incorrect implementation of authentication algorithm (dsa-2025-159 / EUVD-2025-32898)
Nagios Vulnerability Allows Users to Retrieve Cleartext Administrative API Keys
Security researchers have identified two significant vulnerabilities in Nagios Log Server that expose critical system information and allow unauthorized service manipulation. The vulnerabilities, tracked as CVE-2025-44823 and CVE-2025-44824, affect versions prior to 2024R1.3.2 and pose serious risks to enterprise monitoring infrastructure. CVE ID Affected Product CVSS Score Severity Impact CVE-2025-44823 Nagios Log Server 9.9 CRITICAL […]
The post Nagios Vulnerability Allows Users to Retrieve Cleartext Administrative API Keys appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
"ChatGPT, напиши код" — звучит удобно. Пока не получите уязвимость в продакшене и счёт на $670,000 от хакеров
Realm.Security Redefines Security Data Pipelines with AI, Raises $15M to Accelerate Next-Gen SOC Operations
Realm.Security, the company pioneering an AI-native Security Data Pipeline Platform (SDPP), today announced a $15 million Series A funding round led by Jump Capital, with participation from Glasswing Ventures and Accomplice.
The post Realm.Security Redefines Security Data Pipelines with AI, Raises $15M to Accelerate Next-Gen SOC Operations appeared first on Realm.Security.
The post Realm.Security Redefines Security Data Pipelines with AI, Raises $15M to Accelerate Next-Gen SOC Operations appeared first on Security Boulevard.
Cybercrime crew claims attack on Japanese brewer as it restarts operations
Step Into the Password Graveyard… If You Dare (and Join the Live Session)
ClamAV 1.5.0 Released with New MS Office and PDF Verification Features
Cisco has announced the release of ClamAV 1.5.0, a significant update to the open-source antivirus engine that introduces major security enhancements, new document scanning capabilities, and extensive API improvements. This version strengthens the platform’s detection and verification mechanisms, with a particular focus on Microsoft Office documents, PDF files, and overall cryptographic integrity, providing users with […]
The post ClamAV 1.5.0 Released with New MS Office and PDF Verification Features appeared first on Cyber Security News.
Akira
You must login to view this content