Aggregator
CVE-2025-22495 | Eaton Network M2 up to 3.0.3 NTP Server Configuration os command injection
CVE-2025-22491 | Eaton Foreseer Reporting Software up to 1.5.99 Hierarchy Management Page cross site scripting
CVE-2025-9429 | mtons mblog up to 3.5.0 Post /post/submit content/title/ cross site scripting (ICPMLJ/ICPMLW)
CVE-2025-9430 | mtons mblog up to 3.5.0 /admin/options/update input cross site scripting (ICPMMF)
CVE-2025-9431 | mtons mblog up to 3.5.0 /search kw cross site scripting (ICPMML)
CVE-2025-9432 | mtons mblog up to 3.5.0 Admin Panel /admin/post/list Title cross site scripting (ICPMMQ)
CVE-2025-9434 | 1000projects Online Project Report Submission and Evaluation System edit_title.php?id=1 cross site scripting
CVE-2025-9438 | 1000projects Online Project Report Submission and Evaluation System /admin/add_student.php cross site scripting
Major Cyber Attacks in August 2025: 7-Stage Tycoon2FA Phishing, New ClickFix Campaign, and Salty2FA
Alleged mastermind behind K-Pop celebrity stock heist extradited to South Korea
New Android Hook Malware Variant Locks Devices With Ransomware
Threat Actors Update Android Droppers to Remain Effective with Even Simple Malware
Threat actors are increasingly refining Android droppers to circumvent enhanced security measures, extending their utility beyond sophisticated banking trojans to simpler malware variants like SMS stealers and basic spyware. Historically, droppers served as innocuous entry points for payloads requiring elevated permissions, such as Accessibility Services, particularly after Android 13’s API restrictions limited direct installations. These […]
The post Threat Actors Update Android Droppers to Remain Effective with Even Simple Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CISA Alerts on Git Arbitrary File Write Flaw Actively Exploited
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a critical vulnerability in Git (CVE-2025-48384) that enables arbitrary file writes and has already been observed in active exploitation campaigns. The flaw arises from Git’s inconsistent handling of carriage return characters (CR) in its configuration files, potentially allowing threat actors to execute […]
The post CISA Alerts on Git Arbitrary File Write Flaw Actively Exploited appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Major Cyber Attacks in August 2025: 7-Stage Tycoon2FA Phishing, New ClickFix Campaign, and Salty2FA
Phishing kits and stealers didn’t slow down this August, and neither did we. ANY.RUN analysts tracked some of the month’s most dangerous campaigns, from a 7-stage Tycoon2FA phishing chain to Rhadamanthys delivered via ClickFix, and the discovery of Salty2FA, a brand-new PhaaS framework linked to Storm-1575. All were analyzed inside ANY.RUN’s Interactive Sandbox, revealing full […]
The post Major Cyber Attacks in August 2025: 7-Stage Tycoon2FA Phishing, New ClickFix Campaign, and Salty2FA appeared first on ANY.RUN's Cybersecurity Blog.