Aggregator
CVE-2025-23089 | Node.js up to 21.7.3 unmaintained third party components (WID-SEC-2025-0156)
Firefox 支持播放 MKV 内容
SecWiki News 2025-09-11 Review
Microsoft’s ‘Gross Cybersecurity Negligence Threatens National Security’
Roasting Redmond for Kerberoasting: “Like an arsonist selling firefighting services,” quips this 76-year-old.
The post Microsoft’s ‘Gross Cybersecurity Negligence Threatens National Security’ appeared first on Security Boulevard.
16 Minutes to Impact: npm Supply Chain Abuse Deploys crypto-draining malware
A targeted supply chain compromise of an open-source node package manager (npm) resulted in malicious updates to widely used packages, enabling cryptocurrency theft through traffic interception and transaction manipulation of browser-based crypto wallets.
The post 16 Minutes to Impact: npm Supply Chain Abuse Deploys crypto-draining malware appeared first on Sygnia.
New Google AppSheet Phishing Scam Deliver Fake Trademark Notices
Bluetooth, Wi-Fi и root-права в багажнике. Хакеры научились взламывать автомобили через Apple CarPlay
Fileless Malware Deploys Advanced RAT via Legitimate Tools
CVE-2025-10278 | YunaiV ruoyi-vue-pro up to 2025.09 /crm/contact/transfer ids/newOwnerUserId improper authorization
CVE-2025-10277 | YunaiV yudao-cloud up to 2025.09 /crm/receivable/submit ID improper authorization
Threat Actors Leveraging Open-Source AdaptixC2 in Real-World Attacks
In early May 2025, security teams began observing a sudden rise in post-exploitation activity leveraging an open-source command-and-control framework known as AdaptixC2. Originally developed to assist penetration testers, this framework offers a range of capabilities—file system manipulation, process enumeration, and covert channel tunneling—that have now been adopted by malicious actors. The framework’s modular design and […]
The post Threat Actors Leveraging Open-Source AdaptixC2 in Real-World Attacks appeared first on Cyber Security News.
CVE-2025-10276 | YunaiV ruoyi-vue-pro up to 2025.09 /crm/contract/transfer id/newOwnerUserId improper authorization
CVE-2025-10275 | YunaiV yudao-cloud up to 2025.09 /crm/business/transfer ids/newOwnerUserId improper authorization
Submit #643809: yunaiv ruoyi-vue-pro latest broken function level authorization [Accepted]
Submit #643808: yunaiv yudao-cloud latest broken function level authorization [Accepted]
Submit #643386: yunaiv ruoyi-vue-pro latest broken function level authorization [Accepted]
Submit #643384: yunaiv yudao-cloud latest broken function level authorization [Accepted]
From Alert Fatigue to Proactive Defense: The Case for AI-Driven Prevention
Artificial intelligence is no longer just another tool in the cybersecurity stack—it’s becoming a requirement to keep pace with modern threats. Deep Instinct CIO Carl Froggett discusses how attackers are leveraging AI to move faster and why defenders need to rethink their own strategies. One of the most pressing issues security teams face today is alert..
The post From Alert Fatigue to Proactive Defense: The Case for AI-Driven Prevention appeared first on Security Boulevard.