Aggregator
信息安全漏洞周报(2025年第39期)
因 AI 需求大涨 DRAM 价格翻倍
《全球数据泄露态势月度报告》(2025年8月)| 附下载地址
GROW计划二期报名启动,携手奇安信基金会守护社会组织网络安全!
Ваш босс создал чатик в Telegram? Готовьтесь закрыть чужой кредит
微塑料可能削弱骨骼
中国信息安全测评中心主任彭涛:凝聚共治合力 筑牢反诈防线
Malicious Code in Fake Postmark MCP Server Steals Thousands of Emails
A newly discovered attack on the npm ecosystem has exposed a deceptive backdoor embedded in a malicious package impersonating Postmark. The package, named postmark-mcp, quietly siphoned off thousands of emails from unsuspecting developers and organizations, all with just one line of code. Over the course of 15 incremental releases, the threat actor behind postmark-mcp built […]
The post Malicious Code in Fake Postmark MCP Server Steals Thousands of Emails appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Прошивки Apple больше не будут гигантами. Инженеры создали систему, которая позволяет анализировать десятки тысяч IPSW
Apple Font Parser Vulnerability Allowing Memory Corruption Attacks
Apple has released a security update for macOS Sequoia 15.7.1 to address a serious vulnerability in its font parser. The flaw, tracked as CVE-2025-43400, allows a maliciously crafted font file to trigger an out-of-bounds write. Exploitation could cause unexpected application crashes or corrupt process memory on affected systems. Apple patched this issue on September 29, 2025, as […]
The post Apple Font Parser Vulnerability Allowing Memory Corruption Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Scattered Spider, ShinyHunters Restructure – New Attacks Underway
100 000 запросов бесплатно, IP-адрес скрыт. На GitHub появился FlareProx — прокси на Cloudflare, который обещает упростить веб-скрейпинг и пентесты
VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution
A zero-day local privilege escalation vulnerability in VMware Tools and VMware Aria Operations is being actively exploited in the wild. The flaw, tracked as CVE-2025-41244, allows an unprivileged local attacker to gain root-level code execution on affected systems. On September 29, 2025, Broadcom disclosed the vulnerability, which exists within VMware’s guest service discovery features. However, […]
The post VMware Tools and Aria 0-Day Vulnerability Exploited for Privilege Escalation and Code Execution appeared first on Cyber Security News.
Veeam RCE Exploit Allegedly Listed for Sale on Dark Web
A new dark web marketplace listing has sparked alarm in the cybersecurity community after a seller using the handle “SebastianPereiro” purportedly advertised a remote code execution (RCE) exploit targeting Veeam Backup & Replication platforms. The alleged exploit, marketed as the “Bug of June 2025,” is claimed to affect certain versions of Veeam 12.x series, specifically […]
The post Veeam RCE Exploit Allegedly Listed for Sale on Dark Web appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
AI-Powered Voice Cloning Raises Vishing Risks
RC²隐私保护联盟 | 东莞 网宇商检 • 高级隐私保护联合认证中心成立
双节安全不缺位! 360数字安全集团7*24H智能守护
VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root
VMware has released an advisory to address three high-severity vulnerabilities in VMware Aria Operations, VMware Tools, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. Disclosed on 29 September 2025, the advisory covers CVE-2025-41244, CVE-2025-41245, and CVE-2025-41246 with CVSSv3 base scores ranging from 4.9 to 7.8. Administrators must apply the patched versions […]
The post VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root appeared first on Cyber Security News.