Aggregator
WooCommerce 插件中的严重漏洞危及 10 万个网站
Detecting Evolving Phishing Campaigns in 2025 Cyber Environments
Cybersecurity experts are warning of a dramatic shift in phishing attack strategies in 2025. Threat actors are leveraging artificial intelligence to create hyper-targeted campaigns that bypass traditional security measures. While overall phishing volume has dropped 20% compared to 2024, attacks have become significantly more sophisticated, personalized, and difficult to detect. AI Powers a New Generation […]
The post Detecting Evolving Phishing Campaigns in 2025 Cyber Environments appeared first on Cyber Security News.
APT41 在隐蔽的网络间谍活动中使用谷歌日历作为秘密 C2
Four Senate Democrats call on DHS to reinstate Cyber Safety Review Board membership
The lawmakers say the January purge has left the United States blind on the nature of the historic Salt Typhoon telecommunications breach.
The post Four Senate Democrats call on DHS to reinstate Cyber Safety Review Board membership appeared first on CyberScoop.
Senators call on Trump admin to reinstate cyber review board for Salt Typhoon investigation
CVE-2015-4596 | Lenovo Mouse Suite up to 6.72 access control (Nessus ID 85908)
CVE-2018-10206 | Vaultize Enterprise File Sharing 17.05.31 Message Stored cross site scripting
CVE-2018-10207 | Vaultize Enterprise File Sharing 17.05.31 FlexPaperViewer SWF Reader improper authorization
CVE-2018-10208 | Vaultize Enterprise File Sharing 17.05.31 Error Page /share/error?message Reflected cross site scripting
CVE-2018-10209 | Vaultize Enterprise File Sharing 17.05.31 Download Pop-Up Stored cross site scripting
CVE-2018-10210 | Vaultize Enterprise File Sharing up to 17.05.31 Password Reset User password recovery
CVE-2018-10211 | Vaultize Enterprise File Sharing 17.05.31 History vaultize_session_id improper authorization
CVE-2018-10212 | Vaultize Enterprise File Sharing 17.05.31 Folder improper authorization
CVE-2018-10213 | Vaultize Enterprise File Sharing 17.05.31 Invitation Mail cross site scripting
CVE-2019-3905 | Zoho ManageEngine ADSelfService Plus up to 5.x server-side request forgery (ID 371541)
CVE-2019-7161 | Zoho ManageEngine ADSelfService Plus up to 5.x Build 5704 inadequate encryption
CVE-2019-6512 | WSO2 API Manager 2.6.0 server-side request forgery
Attackers Exploit Microsoft Entra Billing Roles to Escalate Privileges in Organizational Environments
A startling discovery by BeyondTrust researchers has unveiled a critical vulnerability in Microsoft Entra ID and Azure environments, where attackers can exploit lesser-known billing roles to escalate privileges within organizational tenants. This sophisticated attack vector leverages the ability of guest users, often invited for collaboration with limited permissions, to create and control Azure subscriptions in […]
The post Attackers Exploit Microsoft Entra Billing Roles to Escalate Privileges in Organizational Environments appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.