Cybersecurity News

Aggregated daily from 10 sources. Updated automatically every morning.

CISA NCSC UK SANS ISC The Hacker News Bleeping Computer Krebs on Security Dark Reading SecurityWeek Exploit-DB CERT-In
245 items Last updated:
Krayin CRM v2.2.x - Authenticated Remote Code Execution
Exploit-DB Exploits
Why the UK is pioneering an initiative to develop a national scale, sovereign defence capability
NCSC UK Advisories
iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter
Exploit-DB Exploits
WordPress Bricks Builder Theme - RCE
Exploit-DB Exploits
Tenable Nessus 10.12.1 - SQL Injection
Exploit-DB Exploits
Discuz! X5.0 - Authentication Bypass
Exploit-DB Exploits
Hydra - Stack Buffer Overflow
Exploit-DB Exploits
Flowise 3.1.3 - arbitrary code execution
Exploit-DB Exploits
ProtonVPN v4.4.1 - Unquoted Service Path
Exploit-DB Exploits
MCPJam Inspector - Remote Code Execution
Exploit-DB Exploits
WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
Exploit-DB Exploits
Windows Defender (MsMpEng.exe) - Race Condition
Exploit-DB Exploits
KNX visualisering - Broken Access Control
Exploit-DB Exploits
KeepInMind 0.8.4.2 - Stored XSS
Exploit-DB Exploits
MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation
Exploit-DB Exploits
Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
Exploit-DB Exploits
Joomla Extension 4.1.4 - PHP Object injection
Exploit-DB Exploits
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.
Krebs on Security News
Pen testers suggest what organisations can do to make their job more difficult.
NCSC UK Advisories
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.
Krebs on Security News
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
NCSC UK Advisories
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].
Krebs on Security News
Different code deserves different levels of oversight, so calibrate your approach to ‘vibe coding’ accordingly.
NCSC UK Advisories
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
NCSC UK Advisories
Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.
NCSC UK Advisories
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.
Krebs on Security News
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available.
Krebs on Security News
OpenEMR 7.0.2 - Arbitrary File Read
Exploit-DB Exploits
WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
Exploit-DB Exploits
Attackers are compromising open-source packages to spread malware. Cyber defenders are asked to review dependencies to reduce risks
NCSC UK Advisories