ZCyberNews
中文

Articles

460 articles

CISA Warns of Actively Exploited Windows, Adobe Acrobat VulnerabilitiesHIGH
Vulnerabilities

CISA Warns of Actively Exploited Windows, Adobe Acrobat Vulnerabilities

CISA adds two new vulnerabilities to its KEV catalog: a Windows SmartScreen bypass (CVE-2024-21412) and an Adobe Acrobat Reader code execution flaw (CVE-2024-20662), both under active exploitation.

CVE-2024-21412CVE-2024-20662
4 min read
Fake Ledger Live App on Apple App Store Steals $9.5M in CryptocurrencyHIGH
Malware

Fake Ledger Live App on Apple App Store Steals $9.5M in Cryptocurrency

A malicious Ledger Live app distributed via Apple's official App Store for macOS stole approximately $9.5 million from 50 victims by harvesting recovery phrases.

4 min read
Janela RAT Campaign Targets Latin American Finance with Fake MSI InstallersHIGH
Malware

Janela RAT Campaign Targets Latin American Finance with Fake MSI Installers

A new campaign deploying the Janela RAT uses fake MSI installers and malicious browser extensions to target financial and cryptocurrency entities in Latin America for data theft.

3 min read
Malicious Chrome Extensions Hijack OAuth Tokens, Deploy BackdoorsHIGH
Malware

Malicious Chrome Extensions Hijack OAuth Tokens, Deploy Backdoors

Over 100 malicious extensions in the official Chrome Web Store are stealing Google OAuth2 tokens, deploying backdoors, and committing ad fraud, impacting millions of users.

3 min read
Microsoft Patches Exploited SharePoint Zero-Day Among 161 VulnerabilitiesHIGH
Vulnerabilities

Microsoft Patches Exploited SharePoint Zero-Day Among 161 Vulnerabilities

Microsoft's April 2025 Patch Tuesday addresses 161 CVEs, including an actively exploited zero-day in SharePoint Server (CVE-2025-27088) and a critical RCE in Windows DNS (CVE-2025-27080).

CVE-2025-27088CVE-2025-27080
4 min read
Mirax Android RAT Steals Credentials, Enslaves Phones for Proxy NetworkHIGH
Malware

Mirax Android RAT Steals Credentials, Enslaves Phones for Proxy Network

The Mirax Android RAT steals banking credentials and covertly turns infected devices into residential proxy nodes for criminal traffic, creating a dual-threat mobile botnet.

4 min read
Critical PHP Composer Flaws Allow Remote Command Execution via Perforce DriverHIGH
Vulnerabilities

Critical PHP Composer Flaws Allow Remote Command Execution via Perforce Driver

Two high-severity command injection vulnerabilities (CVE-2026-40176, CVE-2026-40177) in PHP Composer's Perforce driver enable arbitrary command execution on developer systems during package operations.

CVE-2026-40176CVE-2026-40177
3 min read
PlugX USB Worm Evolves with DLL Sideloading for Cross-Continent SpreadHIGH
Malware

PlugX USB Worm Evolves with DLL Sideloading for Cross-Continent Spread

A new PlugX USB worm variant uses DLL sideloading to propagate across Asia and Africa, targeting removable drives for initial access and establishing persistence.

4 min read
ShowDoc RCE Vulnerability CVE-2025-0520 Under Active ExploitationCRITICAL
Vulnerabilities

ShowDoc RCE Vulnerability CVE-2025-0520 Under Active Exploitation

Attackers are actively exploiting CVE-2025-0520, a critical RCE flaw in ShowDoc, to compromise unpatched servers via unrestricted file upload. The vulnerability has a CVSS score of 9.4.

CVE-2025-0520
3 min read
Zero Trust Architecture as a Critical Defense Against Credential-Based AttacksINFORMATIONAL
Industry News

Zero Trust Architecture as a Critical Defense Against Credential-Based Attacks

Specops analysis details how an identity-first Zero Trust model counters the primary breach vector of stolen credentials by enforcing least privilege, device trust, and blocking lateral movement.

3 min read
Adobe Patches Acrobat Zero-Day Exploited via Malicious PDFs for MonthsCRITICAL
Vulnerabilities

Adobe Patches Acrobat Zero-Day Exploited via Malicious PDFs for Months

Adobe patches CVE-2024-34102, a critical zero-day vulnerability in Acrobat and Reader exploited via malicious PDFs for at least four months prior to discovery.

CVE-2024-34102
4 min read
AI Chatbots as Political Advisors Raise Security and Transparency ConcernsMEDIUM
AI Security

AI Chatbots as Political Advisors Raise Security and Transparency Concerns

A U.S. Senator's use of an AI chatbot for policy consultation highlights emerging risks in AI-assisted governance, including data privacy, model integrity, and accountability gaps.

4 min read
← PrevPage 36 of 39Next →