ZCyberNews
中文

Articles

460 articles

CVE-2024-38112: BlueHammer PoC Escalates Windows to SYSTEMHIGH
Vulnerabilities

CVE-2024-38112: BlueHammer PoC Escalates Windows to SYSTEM

Researcher Chaotic Eclipse published a PoC for CVE-2024-38112, a Windows zero-day that grants local SYSTEM privileges, citing MS disclosure failures.

CVE-2024-38112
3 min readChaotic Eclipse
ClickFix Mac Malware Campaign Uses Fake Apple Page to Deliver PayloadsMEDIUM
Malware

ClickFix Mac Malware Campaign Uses Fake Apple Page to Deliver Payloads

A new ClickFix-style campaign targets macOS users with fake Apple instructions to run malicious commands.

3 min read
CPUID Software Downloads Compromised, Delivered STX RAT MalwareHIGH
Malware

CPUID Software Downloads Compromised, Delivered STX RAT Malware

Threat actors compromised CPUID's download infrastructure for six hours, redirecting users to malicious sites serving the STX RAT. Official signed files were not affected.

3 min read
CPUID Website Compromised to Distribute Trojanized System UtilitiesHIGH
Malware

CPUID Website Compromised to Distribute Trojanized System Utilities

A Russian-speaking threat actor hacked the CPUID website, replacing legitimate download links for CPU-Z and HWMonitor with trojanized installers delivering the STX RAT malware.

3 min readRussian-speaking threat actor
Critical Android SDK Flaw Exposed Millions of Crypto Wallet Private KeysCRITICAL
Vulnerabilities

Critical Android SDK Flaw Exposed Millions of Crypto Wallet Private Keys

A vulnerability in the EngageLab Push SDK, tracked as CVE-2023-4863, allowed attackers to steal private keys from millions of Android cryptocurrency wallets by intercepting push notifications.

CVE-2023-4863
3 min read
Critical wolfSSL Flaw Allows Attackers to Forge TLS CertificatesCRITICAL
Vulnerabilities

Critical wolfSSL Flaw Allows Attackers to Forge TLS Certificates

A critical vulnerability (CVE-2022-39173) in the wolfSSL library allows attackers to forge TLS certificates, enabling MITM attacks and impersonation of trusted services.

CVE-2022-39173
4 min read
Critical WordPress Plugin Flaw Allows Unauthenticated Admin TakeoverCRITICAL
Vulnerabilities

Critical WordPress Plugin Flaw Allows Unauthenticated Admin Takeover

A critical flaw (CVE-2026-1492) in the User Registration & Membership WordPress plugin allows unauthenticated attackers to bypass login and gain full administrator access, impacting thousands of sites.

CVE-2026-1492
3 min read
Fake Claude AI Website Delivers PlugX RAT via DLL SideloadingHIGH
Malware

Fake Claude AI Website Delivers PlugX RAT via DLL Sideloading

A fraudulent website impersonating Anthropic's Claude AI distributes a self-deleting installer that deploys the PlugX remote access trojan via DLL sideloading.

4 min read
JanelaRAT Evolves with New Anti-Analysis and Data Theft CapabilitiesHIGH
Malware

JanelaRAT Evolves with New Anti-Analysis and Data Theft Capabilities

Kaspersky researchers detail an updated JanelaRAT campaign targeting Latin American users with enhanced anti-analysis, credential theft, and remote access capabilities delivered via phishing.

3 min read
JanelaRAT Malware Campaign Targets Latin American Financial SectorHIGH
Malware

JanelaRAT Malware Campaign Targets Latin American Financial Sector

A modified version of BX RAT, dubbed JanelaRAT, has been deployed in over 14,000 attacks against banks and financial institutions in Brazil and Mexico, stealing financial data and keystrokes.

3 min read
LucidRook Malware Targets NGOs and Universities in Taiwan via Spear-PhishingHIGH
Malware

LucidRook Malware Targets NGOs and Universities in Taiwan via Spear-Phishing

A new Lua-based malware, LucidRook, is being deployed in targeted spear-phishing attacks against NGOs and universities in Taiwan, using decoy documents to establish persistence and exfiltrate data.

4 min read
Critical Marimo RCE Flaw Exploited Within Hours of DisclosureCRITICAL
Vulnerabilities

Critical Marimo RCE Flaw Exploited Within Hours of Disclosure

A critical pre-authentication remote code execution vulnerability (CVE-2026-39987) in the Marimo Python notebook was exploited in the wild within 10 hours of public disclosure, posing a severe risk to data science environments.

CVE-2026-39987
3 min read
← PrevPage 37 of 39Next →