Aggregator
CVE-2023-3377 | Veribilim Veribase up to 20231123 sql injection
CVE-2023-3631 | Medart Notification Panel up to 20231123 sql injection
CVE-2024-38250 | Microsoft Windows up to Server 2022 23H2 Graphics buffer over-read
CVE-2025-26687 | Microsoft Windows up to Server 2025 Win32k use after free (Nessus ID 234050)
CVE-2025-30386 | Microsoft Office use after free (EUVD-2025-14450 / Nessus ID 236844)
CVE-2025-30388 | Microsoft Windows up to Server 2025 Graphics heap-based overflow (EUVD-2025-14412 / WID-SEC-2025-1050)
Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access
Russian state-sponsored threat groups significantly stepped up their cyber operations in 2025, using a range of methods to break into targeted systems. From exploiting remote desktop tools and virtual private networks to manipulating trusted supply chains and deceiving employees through social engineering, these actors have built a dangerous and versatile toolkit for gaining initial access. […]
The post Russian Threat Groups Use RDP, VPN, Supply Chain Attacks, and Social Engineering for Initial Access appeared first on Cyber Security News.
Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks
A widely-used JavaScript templating library called art-template has been weaponized to deliver a sophisticated iOS browser exploit kit through a supply chain attack. The backdoored package silently dropped malicious code into end users’ browsers, turning everyday web applications into watering holes targeting Apple device owners worldwide. The attack began when the art-template npm package, originally […]
The post Hackers Backdoor Popular art-template npm Package to Launch Watering-Hole Attacks appeared first on Cyber Security News.
CVE-2019-15107 | Webmin up to 1.920 password_change.cgi old command injection (ID 154141 / EDB-47230)
CVE-2023-1833 | Redline Router prior 7.17 authentication bypass
CVE-2023-3374 | Bookreen up to 2.x incomplete blacklist
CVE-2023-36565 | Microsoft Office Graphics use after free
CVE-2023-2889 | Veon Computer Service Tracking Software up to 20231122 sql injection
2026-05-22: SmartApeSG ClickFix --> Unidentified RAT --> NetSupport RAT
CVE-2026-6406 | Docker Desktop up to 4.54.0 Enhanced Container Isolation Local Privilege Escalation (EUVD-2026-31484 / WID-SEC-2026-1259)
CVE-2026-34909 | Ubiquiti UniFi OS Server path traversal (EUVD-2026-31384 / WID-SEC-2026-1639)
CVE-2026-34927 | Trend Micro TrendAI Apex One/TrendAI Apex One as a Service origin validation (EUVD-2026-31285 / Nessus ID 316481)
Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems
A hacker group known as INJ3CTOR3 has been running an active campaign against FreePBX systems, deploying a newly discovered PHP webshell called JOMANGY that uses six separate persistence layers to stay embedded on compromised servers. The campaign targets internet-exposed VoIP phone systems and routes calls through them at the victims’ expense, a scheme known as […]
The post Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems appeared first on Cyber Security News.
FBI warns about fast-growing phishing kit targeting Microsoft 365 users
Kali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications.
The post FBI warns about fast-growing phishing kit targeting Microsoft 365 users appeared first on CyberScoop.