Aggregator
CVE-2008-6466 | Akirapowered Image Gallery 0.9.6.2 image_gallery.php sql injection (EDB-6516 / BID-31286)
CVE-2008-4362 | DESlock 3.2.7 resource management (EDB-6515 / SA31921)
CVE-2008-7021 | AvailScript Jobs Portal Script File Upload editlogo.php memory corruption (EDB-6514 / XFDB-45335)
Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files
Researchers warn of ongoing spear-phishing attacks by Russian threat actor Midnight Blizzard targeting individuals in various sectors. The attacks involve sending signed RDP configuration files to thousands of targets, aiming to compromise systems for intelligence gathering. The actor impersonates Microsoft employees and references other cloud providers to increase credibility, so users are advised to be […]
The post Massive Midnight Blizzard Phishing Attack Using Weaponized RDP Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Sophisticated Phishing Attack Targeting Ukraine Military Sectors
The Ukrainian Cyber Emergency Response Team discovered a targeted phishing campaign launched by UAC-0215 against critical Ukrainian infrastructure, including government agencies, key industries, and military entities. Phishing emails promoting integration with Amazon, Microsoft, and ZTA contained malicious .rdp files. Upon opening, these files connected devices to attacker-controlled servers, compromising security. The sophisticated attack leveraged a […]
The post Sophisticated Phishing Attack Targeting Ukraine Military Sectors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Chinese Hackers Attacking Microsoft Customers With Sophisticated Password Spray Attacks
Researchers have identified a network of compromised devices, CovertNetwork-1658, used by Chinese threat actors to launch highly evasive password spray attacks, successfully stealing credentials from multiple Microsoft customers. The stolen credentials are then leveraged by threat actors like Storm-0940 to gain unauthorized access to systems. Storm-0940 has been an active threat actor since 2021 and […]
The post Chinese Hackers Attacking Microsoft Customers With Sophisticated Password Spray Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2015-8971 | Terminology 0.7.0 Escape Sequence command injection (Nessus ID 94744 / ID 175882)
New Windows Zero-Day Vulnerability Let Attackers Steal Credentials From Victim’s Machine
A security researcher discovered a vulnerability in Windows theme files in the previous year, which allowed malicious actors to steal Windows users’ credentials. When a theme file specifies a network path for specific properties, like the brand image or wallpaper, Windows automatically sends authenticated network requests to remote hosts, including the user’s NTLM credentials. This […]
The post New Windows Zero-Day Vulnerability Let Attackers Steal Credentials From Victim’s Machine appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.