Aggregator
CVE-2025-22810 | CBB Team Content Blocks Builder Plugin up to 2.7.6 on WordPress cross site scripting
马斯克:如果OpenAI维持非营利,将撤回竞购;库克官宣2月19 日发布苹果新品;中国影史首部百亿元票房影片诞生 | 极客早知道
黑客利用 Webflow CDN PDF 的 CAPTCHA 技巧绕过安全扫描器
CVE-2025-22819 | 4wpbari Qr Code and Barcode Scanner Reader Plugin up to 1.0.0 on WordPress cross site scripting
CVE-2025-22811 | Modeltheme MT Addons for Elementor Plugin up to 1.0.6 on WordPress cross site scripting
CVE-2025-22820 | Daniel Walmsley VR Views Plugin up to 1.5.1 on WordPress cross site scripting
CVE-2025-22826 | wpecommerce & wp.insider Sell Digital Downloads Plugin up to 2.2.7 on WordPress cross site scripting
CVE-2025-22821 | vfthemes StorePress Plugin up to 1.0.12 on WordPress cross site scripting
CVE-2025-22827 | WP Joomag Plugin up to 2.5.2 on WordPress cross site scripting
CVE-2025-22824 | Lucia Intelisano Live Flight Radar Plugin up to 1.0 on WordPress cross site scripting
吾爱破解2025春节红包活动番外篇第三题
CVE-2022-40258 | AMI Megarac Redfish/API weak password hash
CVE-2023-21608 | Adobe Acrobat Reader up to 20.005.30418/22.003.20281/22.003.20282 use after free (apsb23-01)
APT37黑客组织利用群组聊天传播恶意LNK文件展开攻击——每周威胁情报动态第211期 (02.07-02.13)
APT37黑客组织利用群组聊天传播恶意LNK文件展开攻击——每周威胁情报动态第211期 (02.07-02.13)
【2025春节】解题领红包所有题writeup
Storm-2372 conducts device code phishing campaign
Microsoft Threat Intelligence Center discovered an active and successful device code phishing campaign by a threat actor we track as Storm-2372. Our ongoing investigation indicates that this campaign has been active since August 2024 with the actor creating lures that resemble messaging app experiences including WhatsApp, Signal, and Microsoft Teams. Storm-2372’s targets during this time have included government, non-governmental organizations (NGOs), information technology (IT) services and technology, defense, telecommunications, health, higher education, and energy/oil and gas in Europe, North America, Africa, and the Middle East. Microsoft assesses with medium confidence that Storm-2372 aligns with Russian interests, victimology, and tradecraft.
The post Storm-2372 conducts device code phishing campaign appeared first on Microsoft Security Blog.