1010.cx

  • jsPDF Flaw Exposes Millions of Developers to Object Injection

    ·

    cyber security, Cyber Security News, vulnerability

    A serious security flaw in jsPDF, a widely used JavaScript library for generating PDFs in web browsers, puts millions of developers and their users at risk. CVE-2026-25755 allows attackers to perform PDF Object Injection through the library’s addJS method. This vulnerability affects countless web applications that rely on jsPDF to create dynamic PDF documents from […]

    The post jsPDF Flaw Exposes Millions of Developers to Object Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HPE Telco Service Activator Vulnerability Allows Attackers to Bypass Access Controls

    ·

    cyber security, Cyber Security News, vulnerability

    Hewlett Packard Enterprise (HPE) has issued a security bulletin warning customers of a serious vulnerability in its Telco Service Activator product that could allow attackers to remotely bypass access restrictions. The vulnerability, identified as CVE-2025-12543, carries a CVSS base score of 9.6 (Critical) and affects versions prior to 10.5.0. This improper input validation could enable attackers to manipulate the server’s handling […]

    The post HPE Telco Service Activator Vulnerability Allows Attackers to Bypass Access Controls appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

    ·

    The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several organizations and individuals mainly located across the Middle East and North Africa (MENA) region as part of a new campaign codenamed Operation Olalampo. The activity, first observed on January 26, 2026, has resulted in the deployment of new malware families that share

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • North Korean Hackers Exploit Fake IT Worker Schemes and Malicious Interview Lures

    ·

    cyber security, Cyber Security News

    North Korean state-backed hackers are running large-scale fake IT worker and “Contagious Interview” campaigns that abuse developer hiring workflows to deliver JavaScript-based malware, steal code and credentials, and covertly generate revenue for the regime. Since at least 2022, North Korean threat actors have impersonated recruiters and hiring managers, luring software developers into executing booby-trapped code […]

    The post North Korean Hackers Exploit Fake IT Worker Schemes and Malicious Interview Lures appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • DPRK-Linked Hackers Continue Aggressive Crypto Attacks One Year After Bybit Breach

    ·

    cyber security, Cyber Security News

    DPRK-linked operators are maintaining a relentless focus on the crypto sector, with activity accelerating rather than slowing in the year since the record-breaking Bybit breach. On 21 February 2025, threat actors linked to North Korea stole around 1.46 billion dollars in cryptoassets from Dubai-based exchange Bybit, in what remains the largest confirmed crypto theft to date. By […]

    The post DPRK-Linked Hackers Continue Aggressive Crypto Attacks One Year After Bybit Breach appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Silver Fox APT Deploys DLL Sideloading and BYOVD in Advanced Malware Campaign

    ·

    cyber security, Cyber Security News, Malware

    Silver Fox APT is running a new wave of targeted attacks in Taiwan that combine DLL sideloading and Bring Your Own Vulnerable Driver (BYOVD) techniques to deploy Winos 4.0 (ValleyRat) while aggressively disabling security tools. The campaigns rely on highly localized tax and e‑invoice lures and fast‑changing infrastructure, making them difficult to block with static […]

    The post Silver Fox APT Deploys DLL Sideloading and BYOVD in Advanced Malware Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • 128M Users Exposed as Popular VS Code Extensions Reveal Critical Flaws

    ·

    cyber security, Cyber Security News, VSCodeExtensions, vulnerability

    Serious vulnerabilities in four popular Visual Studio Code (VS Code) extensions, affecting over 128 million downloads. These flaws, including three assigned CVEs CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717, highlight IDEs as the weakest link in organizational supply chain security. Developers often store sensitive data like API keys, business logic, database configs, and even customer info right in […]

    The post 128M Users Exposed as Popular VS Code Extensions Reveal Critical Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Researchers Demonstrate 27 Attacks Against Major Password Managers

    ·

    Bitwarden, cybersecurity, Dashlane, Lastpass, Password, Password manager, Privacy, Security, vulnerability
    Researchers demonstrate multiple attacks against major password managers, showing how compromised servers and design flaws can expose encrypted vault data.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cache Deception Flaw in SvelteKit And Vercel Stack Exposes User Data

    ·

    cyber security, Cyber Security News, vulnerability

    A cache deception vulnerability in SvelteKit apps deployed on Vercel exposes sensitive user data to attackers. The flaw allows publicly cached responses to be authenticated. SvelteKit, a full-stack JavaScript framework, often pairs with Vercel for deployment. The issue stems from the Vercel adapter in SvelteKit, where the __pathname query parameter overrides the request path without any checks. […]

    The post Cache Deception Flaw in SvelteKit And Vercel Stack Exposes User Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Japanese Semiconductor Supplier Hit by Ransomware, Multiple Systems Impacted

    ·

    Cyber Attack, cyber security, Cyber Security News, Ransomware, vulnerability

    Feb. 20, 2026 – Advantest Corporation, a top supplier of semiconductor test equipment, revealed it is battling a ransomware attack that struck its network last weekend. The incident, detected on February 15 (JST), has disrupted multiple systems and raised alarms in the global chip industry, where supply chain attacks can ripple through tech giants building […]

    The post Japanese Semiconductor Supplier Hit by Ransomware, Multiple Systems Impacted appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

Previous Page
1 … 76 77 78 79 80 … 651
Next Page

1010.cx

cybersecurity / defense / intelligence