Category: Vulnerabilities
Critical Joomla Extension Flaws Under Active Exploitation, CISA Adds to KEV
Unauthenticated file upload vulnerabilities in the Balbooa Forms and iCagenda Joomla extensions, both scoring a maximum CVSS of 10, are being exploited…
US and Allies Warn Russian FSB Hackers Are Hunting Weak Router Configs
A joint advisory from CISA, the NSA, FBI, and agencies in eight allied nations warns that Russia's FSB Center 16 group is…
Attackers Exploit Critical Auth Bypass in Gitea’s Official Docker Image
A misconfigured default in Gitea's Docker image lets unauthenticated attackers impersonate any user, including admins, and exploitation began before public disclosure.
Six New U-Boot Bugs Could Crash Devices or Enable Boot-Time Code Execution
Firmware security firm Binarly has disclosed six flaws in the widely used U-Boot bootloader, four that can crash affected devices and two…
Injective Labs GitHub Breach Spawns Malicious npm Package to Steal Crypto Wallets
Attackers compromised the Injective Labs SDK repository on GitHub and published a tampered npm package designed to exfiltrate wallet private keys and…
Ryuk Ransomware Operator Pleads Guilty as BlackCat Insider Gets Nearly 6 Years
U.S. prosecutors notched two wins against ransomware ecosystems this week: an Armenian national admitted deploying Ryuk against victims including a Michigan firm…
Armenian Man Pleads Guilty to Deploying Ryuk Ransomware in US Attacks
Karen Serobovich Vardanyan admitted to helping breach US companies and deploy Ryuk ransomware in 2019 and 2020, part of a scheme that…
European Parliament Revives CSAM Scanning Law Amid Procedural Controversy
A last-minute vote using an unusual absolute-majority procedure has extended legal cover for voluntary CSAM scanning by tech platforms through 2028, even…
Malicious jscrambler npm Package Drops Rust Infostealer at Install Time
A compromised 8.14.0 release of the jscrambler npm package used a preinstall hook to silently execute native infostealer binaries on Windows, macOS,…
Six U-Boot Flaws Could Let Attackers Hijack Devices Before the OS Even Loads
Firmware security firm Binarly has disclosed six vulnerabilities in U-Boot's image signature verification code, two of which allow arbitrary code execution during…
Critical Zimbra Classic Web Client Flaw Lets Emails Execute Malicious Code
Zimbra is pushing urgent updates for a critical stored XSS vulnerability in its Classic Web Client that lets specially crafted emails run…
Zimbra Patches Critical XSS Flaw in Classic Web Client After Google TAG Report
Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, flagged by Google's Threat Analysis…