Aggregator
CVE-2010-2844 | Newanz NewsOffice 2.0.18 news_show.php n-cat cross site scripting (EDB-34258 / XFDB-60182)
CVE-2010-3489 | Digitalworkroom CMS Digital Workroom 5.5.0 login2.php goback cross site scripting (EDB-34649 / BID-43290)
CVE-2010-1606 | Ncrypted NCT Jobs Portal Script admin_login.php passwd cross site scripting (EDB-12370 / XFDB-58081)
CVE-2010-4860 | Galaxyscriptz MyPhpAuction 2010 product_desc.php ID sql injection (EDB-15154 / XFDB-62144)
CVE-2010-4901 | Squiz MySource Matrix 3.28.3 char_map.php width cross site scripting (EDB-34609 / ID 12412)
Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details
A sophisticated phishing campaign has emerged targeting job seekers through fake Google career recruitment opportunities, leveraging social engineering tactics to harvest Gmail credentials and personal information. The malicious operation exploits the trust associated with Google’s brand reputation, crafting convincing recruitment emails that direct victims to fraudulent login portals designed to capture authentication details. The attack […]
The post Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details appeared first on Cyber Security News.
CVE-2025-7493 | Red Hat Enterprise Linux 6/7/8/9/10 FreeIPA insufficient granularity of access control (EUVD-2025-31739 / WID-SEC-2025-2164)
CVE-2020-36843 | str4d ed25519-java up to 0.3.0 EdDSA signature verification (Issue 82 / Nessus ID 232871)
New Android Banking Trojan “Klopatra” Uses Hidden VNC to Control Infected Smartphones
New Android Banking Trojan “Klopatra” Uses Hidden VNC to Control Infected Smartphones
Microsoft Investigating Widespread Outlook.com Outage Preventing Users from Accessing Mailbox
Microsoft is actively investigating and addressing widespread errors preventing users from accessing their mailboxes on Outlook.com. The company has been providing regular updates throughout the day, indicating that targeted infrastructure restarts are gradually restoring service. The issue, which began early on October 1, 2025, affects users attempting to log in or access their emails via […]
The post Microsoft Investigating Widespread Outlook.com Outage Preventing Users from Accessing Mailbox appeared first on Cyber Security News.
Hackers Abuse EV Certificates to Sign Completely Undetectable DMG Malware
Security researchers have uncovered a new macOS malware campaign in which threat actors are abusing Extended Validation (EV) code-signing certificates to distribute completely undetectable (FUD) disk image (DMG) payloads. While EV certificate abuse has long plagued the Windows ecosystem, its expansion into macOS malware marks a significant escalation in code-signing exploitation. A fresh DMG sample […]
The post Hackers Abuse EV Certificates to Sign Completely Undetectable DMG Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Campaign Warns Solicitors and House Buyers of Payment Diversion Fraud
Качай, не бойся, но ты уже взломан. В 70% случаев российские компании «попадались» из-за загрузки зараженного файла
How I maintain release notes for curl
How Mixture-of-Adaptations Makes Language Model Fine-Tuning Cheaper and Smarter
Webinar | Beyond DMARC: Closing Critical Gaps in Your Email Security Shield
China's 'Phantom Taurus' Hacks Middle East
A Chinese cyberespionage threat actor with a history of hacking Microsoft Exchange to spy on geopolitical events including summits in Africa, the Middle East and Asia, has shifted its attention to targeting databases, say researchers.
Hour-Long Email Phishing Breach Affects PHI of 150,000
A Florida firm that offers medication therapy management services to health plans is notifying nearly 150,000 individuals that their information was potentially compromised in a phishing attack affecting one employee's email account for only about an hour. Why do users still fall for phishing scams?