Aggregator
CVE-2025-29840 | Microsoft Windows up to Server 2022 23H2 Media stack-based overflow (EUVD-2025-14425)
McLaren Health Care data breach impacted over 743,000 people
Okta Cross App Access secures AI agents in the enterprise
Okta announced Cross App Access, a new protocol to help secure AI agents. As an extension of OAuth, it brings visibility and control to both agent-driven and app-to-app interactions, allowing IT teams to decide what apps are connecting and what information AI agents can access. Why it matters More AI tools are using protocols like Model Context Protocol (MCP) and Agent2Agent (A2A) to connect their AI learning models to relevant data and apps within the … More →
The post Okta Cross App Access secures AI agents in the enterprise appeared first on Help Net Security.
CVE-2009-4785 | Bhavesh Chauhan Com Quicknews index.php newsid sql injection (EDB-10252 / BID-37161)
Israeli officials say Iran exploiting security cameras to guide missile strikes
North Korean Hackers Weaponize GitHub Infrastructure to Distribute Malware
Cybersecurity researchers have uncovered a sophisticated spearphishing campaign orchestrated by the North Korean threat group Kimsuky, leveraging GitHub as a critical piece of attack infrastructure to distribute malware since March 2025. This operation, identified through analysis of a malicious PowerShell script posted on X, showcases an alarming abuse of legitimate platforms like GitHub and Dropbox […]
The post North Korean Hackers Weaponize GitHub Infrastructure to Distribute Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers Allegedly Selling Intelbras Router 0-Day Exploit on Hacker Forums
A notorious threat actor has allegedly listed a previously unknown—or “0day”—exploit for Intelbras routers on a prominent hacker forum. This exploit poses significant risks for many users and organizations that rely on Intelbras hardware for their networking needs. The sale of such a zero-day exploit is prompting close monitoring from security researchers and professionals, given […]
The post Hackers Allegedly Selling Intelbras Router 0-Day Exploit on Hacker Forums appeared first on Cyber Security News.
Steelmaker Nucor Hacked – Attackers Gained Unauthorized Access to IT Systems
Charlotte-based steel giant Nucor Corporation disclosed a significant cybersecurity incident where threat actors gained unauthorized access to the company’s information technology infrastructure. The breach prompted temporary production shutdowns across multiple facilities as the company implemented emergency containment protocols and engaged federal law enforcement authorities to investigate the intrusion. According to the SEC filing report, Nucor’s […]
The post Steelmaker Nucor Hacked – Attackers Gained Unauthorized Access to IT Systems appeared first on Cyber Security News.
CoinMarketCap, Cointelegraph compromised to serve pop-ups to drain crypto wallets
The CoinMarketCap and CoinTelegraph websites have been compromised over the weekend to serve clever phishing pop-ups to visitors, asking them to verify/connect their crypto wallets. The CoinMarketCap compromise CoinMarketCap (aka CMC) is a website popular with crypto investors as it tracks cryptocurrency prices, market capitalizations, and trading volumes. On June 20, 2025, visitors to the site’s homepage were faced with a pop-up that urged them to connect their wallets to maintain access to their CMC … More →
The post CoinMarketCap, Cointelegraph compromised to serve pop-ups to drain crypto wallets appeared first on Help Net Security.
CVE-2025-28367 | mojoPortal up to 2.9.0.1 BetterImageGallery API Controller Web.Config ImageHandler path traversal
CVE-2025-27086 | HPE Performance Cluster Manager up to 1.12 GUI improper authentication
CVE-2025-28102 | flaskBlog 2.6.1 /createpost postContent cross site scripting (Issue 130 / EUVD-2025-12361)
CVE-2025-3841 | wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9 Jinja2 Template jam.py config['template'] special elements used in a template engine
CVE-2025-52920 | Innoshop up to 0.4.1 _ORDER_ID_ shipping_address_id/billing_address_id direct request (EUVD-2025-18869)
CVE-2025-52921 | InnoShop up to 0.4.1 File Manager Rename unprotected alternate channel (EUVD-2025-18868)
CVE-2025-52922 | Innoshop up to 0.4.1 FileManager API Endpoint /api/file_manager/files base_folder path traversal (EUVD-2025-18867)
Confucius Hackers Target Government and Military Entities Using WooperStealer Malware
The notorious Confucius hacking organization, first exposed by foreign security vendors in 2016, continues to pose a significant threat to government and military entities across South and East Asia. With attack activities dating back to 2013, this group has recently escalated its operations, targeting critical domestic units and industries with advanced tactics. Unveiling a Sophisticated […]
The post Confucius Hackers Target Government and Military Entities Using WooperStealer Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Data of more than 740,000 stolen in ransomware attack on Michigan hospital network
Critical Teleport Vulnerability Allows Remote Authentication Bypass
A critical security vulnerability, tracked as CVE-2025-49825, has been discovered in Teleport, a widely used open-source platform for secure access to servers, cloud applications, and infrastructure. This flaw enables remote attackers to bypass authentication controls, potentially granting unauthorized access to sensitive systems managed by Teleport. The Vulnerability The vulnerability affects Teleport Community Edition versions up […]
The post Critical Teleport Vulnerability Allows Remote Authentication Bypass appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.