Aggregator
Apple Patches Zero-Day Flaw Used in 'Sophisticated' Attack
CVE-2024-36401: как одна уязвимость позволила взломать 7100+ серверов
CVE-2023-20087 | Cisco Identity Services Engine Web-based Management Interface absolute path traversal (cisco-sa-ise-file-dwnld-Srcdnkd2 / EUVD-2023-24266)
The Growing Challenge of AI Agent and NHI Management
MoQ: Refactoring the Internet's real-time media stack
CVE-2024-56179 | Alludo MindManager up to 24.1.149 on Windows File Attachment path traversal (EUVD-2024-54899)
CVE-2025-38618 | Linux Kernel up to 6.17-rc1 vsock accept use after free
CVE-2025-38616 | Linux Kernel up to 6.12.42/6.15.10/6.16.1/6.17-rc1 tls out-of-bounds
CVE-2024-58239 | Linux Kernel up to 6.7.6 tls recv infinite loop
CVE-2025-38617 | Linux Kernel up to 6.1.147/6.6.101/6.12.41/6.15.9/6.16.0 packet_set_ring/packet_notifier race condition
BQTLOCK Ransomware Operates as RaaS With Advanced Evasion Techniques
A sophisticated new ransomware strain named BQTLOCK has emerged in the cyberthreat landscape since mid-July 2025, operating under a comprehensive Ransomware-as-a-Service (RaaS) model that democratizes access to advanced encryption capabilities for cybercriminals. The malware, associated with ‘ZerodayX’, the alleged leader of the pro-Palestinian hacktivist group Liwaa Mohammed, represents a concerning evolution in ransomware distribution and […]
The post BQTLOCK Ransomware Operates as RaaS With Advanced Evasion Techniques appeared first on Cyber Security News.
CVE-2025-54799 | go-acme lego up to 4.25.1 ACME Protocol api cleartext transmission (GHSA-q82r-2j7m-9rv4 / Nessus ID 253527)
CVE-2021-3524 | Red Hat Ceph Storage RadosGW up to 14.2.20 CORS ExposeHeader Tag injection (Nessus ID 253528)
中国人民大学高瓴人工智能学院 | 通过知识精炼和动态提示调整增强医疗对话生成
Will the Real Executive Please Stand Up?
It’s like some sort of digital age version of To Tell the Truth, the ancient TV show where three challengers claim to be the same person and the contestants have to guess which one is the real deal—typically with dismal results. So it goes with deepfakes, like in the recent spate of cyberattacks related to..
The post Will the Real Executive Please Stand Up? appeared first on Security Boulevard.
2M+ Application Attacks Blocked in Real Time | July ADR Report | Contrast Security
July’s Application Detection and Response data revealed two standout events: a concentrated malicious campaign using multiple attack types against one organization, and an unprecedented spike that hit another organization with more than 2 million attacks in a single month. In both cases, ADR blocked every attempt in real time.
The post 2M+ Application Attacks Blocked in Real Time | July ADR Report | Contrast Security appeared first on Security Boulevard.
ClickFix Exploit Emerges: Microsoft Flags Cross-Platform Attacks Targeting Windows and macOS
Microsoft Threat Intelligence has spotlighted the escalating adoption of the ClickFix social engineering technique, a sophisticated method that manipulates users into executing malicious commands on their devices, bypassing traditional automated security defenses. Observed since early 2024, this tactic has targeted thousands of enterprise and end-user systems daily, delivering payloads such as Lumma Stealer infostealers, remote […]
The post ClickFix Exploit Emerges: Microsoft Flags Cross-Platform Attacks Targeting Windows and macOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.