Aggregator
New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access
A newly identified ransomware strain named Cephalus has emerged as a sophisticated threat, targeting organizations through compromised Remote Desktop Protocol (RDP) connections. The malware, which takes its name from Greek mythology referencing the son of Hermes who tragically killed his wife with an infallible javelin, represents a concerning evolution in ransomware deployment techniques. Cephalus distinguishes […]
The post New Cephalus Ransomware Leverages Remote Desktop Protocol to Gain Initial Access appeared first on Cyber Security News.
IPFire Firewall Admin Panel Vulnerability Enables Persistent JavaScript Injection
A critical vulnerability in IPFire 2.29’s web-based firewall interface (firewall.cgi) allows authenticated administrators to inject persistent JavaScript code, leading to session hijacking, unauthorized actions, or internal network pivoting. Tracked as CVE-2025-50975, this stored cross-site scripting (XSS) flaw poses significant risk in environments where multiple administrators share firewall management duties. Details of the Flaw The vulnerability […]
The post IPFire Firewall Admin Panel Vulnerability Enables Persistent JavaScript Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
漏洞通告 | CrushFTP 身份认证绕过漏洞被黑客组织积极利用
静默之控:主动与被动双模后门MystRodX的隐匿渗透
Qilin
You must login to view this content
Executive Dark Web Exposure: Protecting your Leadership
Nisos
Executive Dark Web Exposure: Protecting your Leadership
Not long ago, a Social Security number (SSN) felt like a vault key. Private, protected, rarely seen. Today, it’s more like currency...
The post Executive Dark Web Exposure: Protecting your Leadership appeared first on Nisos by Nisos
The post Executive Dark Web Exposure: Protecting your Leadership appeared first on Security Boulevard.
Don’t let “back to school” become “back to (cyber)bullying”
欢迎注册参会|第22届中国信息和通信安全学术会议即将召开
CISA Issues New ICS Advisories on Critical Vulnerabilities and Exploits
The Cybersecurity and Infrastructure Security Agency (CISA) released three Industrial Control Systems (ICS) advisories on August 26, 2025, detailing nine critical vulnerabilities in INVT VT-Designer and HMITool (CVSS v4 8.5). Multiple flaws in Schneider Electric Modicon M340 controllers (CVSS v4 scores up to 9.1), and several issues in Danfoss AK-SM 8xxA Series drives (CVSS v3.1 […]
The post CISA Issues New ICS Advisories on Critical Vulnerabilities and Exploits appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Google 在翻译应用中加入 AI 驱动的语言学习功能
CVE-2017-2299 | puppetlabs-apache up to 1.11.0/2.0.x ssl_certs_dir 7pk security (Nessus ID 255084 / BID-100859)
CVE-2018-12322 | radare2 2.6.0 libr/anal/p/anal_6502.c 6502_op Java Binary File out-of-bounds (Nessus ID 255085)
CVE-2017-5984 | libav 9.21 libavcodec ff_h264_execute_ref_pic_marking out-of-bounds (Nessus ID 255083)
CVE-2016-8678 | ImageMagick 7.0.3.0 File pixel-accessor.h IsPixelMonochrome out-of-bounds (Nessus ID 255087 / BID-93599)
CVE-2018-20199 | Freeware Advanced Audio Decoder 2.8.8 libfaad/filtbank.c ifilter_bank null pointer dereference (Issue 24 / Nessus ID 255088)
CVE-2024-8069 | Citrix Session Recording/Virtual Apps and Desktops deserialization (CTX691941 / WID-SEC-2024-3443)
CVE-2025-3478 | OpenText Enterprise Security Manager up to 7.8.1 cross site scripting (EUVD-2025-25704 / WID-SEC-2025-1904)
CVE-2024-8068 | Citrix Session Recording/Virtual Apps and Desktops privileges management (CTX691941 / EUVD-2024-49530)
Beyond Google Play: The End of Anonymous Sideloading Is Coming to Android
Openness has long been the defining distinction between Android and the iPhone, yet in recent years Google has steadily shifted the balance toward security. Now the company is preparing its most radical step yet...
The post Beyond Google Play: The End of Anonymous Sideloading Is Coming to Android appeared first on Penetration Testing Tools.