Aggregator
Block the Prompt, Not the Work: The End of "Doctor No"
Submit #780538: LibRaw 0.22.0 Out-of-bounds Write [Accepted]
Ransomware Groups Exploit Legit IT Tools to Bypass Antivirus
长城杯半决赛三道 Web—从 redis SSRF、ZipSlip 到 glibc iconv 溢出
Submit #780561: nothings stb (stb_vorbis.c) ≤ 1.22 Out-of-bounds Write, Integer Overflow [Accepted]
Submit #780560: nothings stb (stb_vorbis.c) ≤ 1.22 Free of Pointer not at Start of Buffer [Accepted]
Submit #780559: nothings stb (stb_truetype.h) ≤ 1.26 Out-of-Bounds Read [Accepted]
Submit #780558: nothings stb (stb_truetype.h) ≤ 1.26 Out-of-Bounds Read [Accepted]
Submit #780462: nothings stb ≤ 2.30 (latest) Use After Free [Accepted]
Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures
HSBC India Asks Customers to use All-Uppercase Passwords
Beginning April 6, 2026, HSBC India will require its internet banking customers to enter their passwords in uppercase letters only. The mandate, communicated via official customer emails, has sparked widespread concern among technical experts regarding the bank’s credential storage practices and overall security posture. The Uppercase Migration According to the bank’s recent communications, customers must […]
The post HSBC India Asks Customers to use All-Uppercase Passwords appeared first on Cyber Security News.
Хотите знать, где спит ваш бывший? Операторы связи сделали эту услугу бесплатной
Hackers Use EtherRAT and EtherHiding to Hide Malware Infrastructure on Ethereum
A sophisticated backdoor called EtherRAT is actively targeting organizations across multiple sectors by hiding its command infrastructure inside the Ethereum blockchain — a move that makes it uniquely hard to track and shut down. The malware runs on Node.js and gives attackers full remote control over compromised machines, enabling them to execute commands, steal cryptocurrency […]
The post Hackers Use EtherRAT and EtherHiding to Hide Malware Infrastructure on Ethereum appeared first on Cyber Security News.
Axios供应链攻击事件再追踪:线索直指Lazarus组织
Romania under daily barrage of cyberattacks, defense minister says
Submit #780443: D-Link DNS-120/202L/315L/320/320L/320LW/321/322L/323/325/326/327L/326/340L/343/345/726-4/1100-4/1200-05/1550-04 up to 20260205 Improper Access Controls [Duplicate]
Submit #780442: D-Link DNS-120/202L/315L/320/320L/320LW/321/322L/323/325/326/327L/326/340L/343/345/726-4/1100-4/1200-05/1550-04 up to 20260205 Improper Access Controls [Accepted]
Submit #780441: D-Link DNS-120/202L/315L/320/320L/320LW/321/322L/323/325/326/327L/326/340L/343/345/726-4/1100-4/1200-05/1550-04 up to 20260205 Improper Access Controls [Accepted]
Major Cyber Attacks in March 2026: OAuth Phishing, SVG Smuggling, Magecart, and More
March 2026 brought a wave of cyber attacks that reflected how quickly modern threats can move from subtle early signals to serious business impact. ANY.RUN analysts identified and explored several major threats this month, exposing phishing campaigns, stealthy malware, payment-skimming activity, and resilient botnet infrastructure affecting organizations across industries. From Microsoft 365 token abuse and […]
The post Major Cyber Attacks in March 2026: OAuth Phishing, SVG Smuggling, Magecart, and More appeared first on ANY.RUN's Cybersecurity Blog.