Aggregator
CVE-2025-7852 | WPBookit Plugin up to 1.0.6 on WordPress image_upload_handle unrestricted upload (EUVD-2025-22478)
CVE-2025-7437 | Ebook Store Plugin up to 5.8012 on WordPress ebook_store_save_form unrestricted upload (EUVD-2025-22477)
CVE-2022-35768 | Microsoft Windows up to Server 2022 Kernel privilege escalation (EUVD-2022-38641)
CVE-2024-21548 | bun up to 1.1.29 API prototype pollution (SNYK-JS-BUN-8499549 / EUVD-2024-3614)
CVE-2025-50127 | dj-extensions DJ-Flyer Component up to 3.2 on Joomla sql injection (EUVD-2025-22444)
Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware
Cybersecurity researchers have uncovered a sophisticated malware campaign where threat actors are exploiting Hangul Word Processor (.hwp) documents to distribute the notorious RokRAT malware. This marks a significant shift from the malware’s traditional distribution method through malicious shortcut (LNK) files, demonstrating the evolving tactics of advanced persistent threat groups. The attack campaign utilizes carefully crafted […]
The post Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware appeared first on Cyber Security News.
Elephant APT Group Exploits VLC Player and Encrypted Shellcode in Attacks on Defense Sector
Arctic Wolf Labs has uncovered a sophisticated cyber-espionage operation attributed to the Dropping Elephant advanced persistent threat (APT) group, also known as Patchwork or Quilted Tiger, focusing on Turkish defense contractors specializing in precision-guided missile systems. The campaign, which began active operations in July 2025, employs a five-stage execution chain initiated through spear-phishing emails containing […]
The post Elephant APT Group Exploits VLC Player and Encrypted Shellcode in Attacks on Defense Sector appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Windows 强制认证攻击全面解析(2025 年最新)
Everest
You must login to view this content
Ваши диалоги с ChatGPT читают все. С Lumo их не увидит даже Proton
CVE-2022-24765 | Apple Xcode up to 13.3.1 Git access control (HT213261 / EUVD-2022-29592)
CVE-2022-30165 | Microsoft Windows up to Server 2022 Azure Edition Core Hotpatch Kerberos privilege escalation (EUVD-2022-35373)
CVE-2025-0765 | GitLab Community Edition/Enterprise Edition up to 18.0.4/18.1.2/18.2.0 Service Desk Email Address authorization (EUVD-2025-22487 / WID-SEC-2025-1627)
CVE-2024-21542 | luigi up to 3.5.x Archive Extraction _extract_packages_archive path traversal (ID 3301 / EUVD-2024-0098)
CVE-2025-7966 | Get Youtube Subs Plugin up to 3.5 on WordPress subscribe_link_att cross site scripting (EUVD-2025-22505)
CVE-2025-40680 | Capillary CapillaryScope up to 2.4.x on Windows sensitive missing encryption (EUVD-2025-22510)
CVE-2025-8107 | OB OceanBase Server prior 3.2.4.9/4.2.1.10/4.2.5/4.3.3.2/4.3.4 exposure of resource (EUVD-2025-22483)
On-Premises SharePoint Server “ToolShell” Backdoor – Advisory for Mitigation and Response
Organizations Urged to Address Critical Security Flaws to Prevent Unauthorized Access to On-Premises SharePoint Servers.
The post On-Premises SharePoint Server “ToolShell” Backdoor – Advisory for Mitigation and Response appeared first on Sygnia.