ZCyberNews
中文

Articles

432 articles

TrickMo Android Trojan Uses TON Blockchain for C2, SOCKS5 PivotsHIGH
Malware

TrickMo Android Trojan Uses TON Blockchain for C2, SOCKS5 Pivots

ThreatFabric tracked a TrickMo variant using The Open Network (TON) for C2 and SOCKS5 proxies to pivot into victim networks, targeting banking and crypto users in France, Italy,...

3 min readTrickMo
UK Fines South Staffordshire Water $1.3M for 2022 BreachHIGH
Industry News

UK Fines South Staffordshire Water $1.3M for 2022 Breach

ICO fined South Staffordshire Water £963,900 after Cl0p ransomware gang leaked data of 663,887 customers — phishing attack went undetected for 20 months.

3 min readCl0p
Unauthenticated SQL Injection in MuuCMF T6 Allows Database TakeoverCRITICAL
Vulnerabilities

Unauthenticated SQL Injection in MuuCMF T6 Allows Database Takeover

CVE-2026-36962: Unauthenticated SQL injection in MuuCMF T6 v1.9.4.20260115 lets attackers dump databases, gain admin access, and achieve RCE via file writes.

CVE-2026-36962
3 min read
West Pharma Hit by Ransomware, Systems Disrupted GloballyHIGH
Industry News

West Pharma Hit by Ransomware, Systems Disrupted Globally

West Pharmaceutical Services took systems offline globally after a May 4 ransomware attack with data exfiltration. Unit 42 is investigating; ransom may have been paid.

2 min readLockBit
Active Directory Password Resets Fail to Expel AttackersHIGH
Industry News

Active Directory Password Resets Fail to Expel Attackers

Specops Software explains how cached credentials, Kerberos tickets, and ACL persistence let attackers survive password resets in AD and hybrid Entra ID environments.

3 min read
Angular Expressions Sandbox Escape CVE-2026-44643 Allows RCECRITICAL
Vulnerabilities

Angular Expressions Sandbox Escape CVE-2026-44643 Allows RCE

CVE-2026-44643 in Angular Expressions <1.5.2 lets attackers escape the sandbox via malicious filter expressions to execute arbitrary code on the system.

CVE-2026-44643
3 min read
Casdoor LFS Flaw CVE-2026-6815 Lets Admins Write Files AnywhereCRITICAL
Vulnerabilities

Casdoor LFS Flaw CVE-2026-6815 Lets Admins Write Files Anywhere

CVE-2026-6815 in Casdoor's Local File System storage provider lets authenticated admins traverse paths to write arbitrary files outside the sandbox. No patch yet.

CVE-2026-6815
3 min read
Corteza SQL Injection Flaw CVE-2026-6093 Lets Attackers Dump DatabasesCRITICAL
Vulnerabilities

Corteza SQL Injection Flaw CVE-2026-6093 Lets Attackers Dump Databases

CVE-2026-6093: A SQL injection vulnerability in Corteza's MSSQL backend allows unauthenticated attackers to extract database contents via Compose record meta-field filters.

CVE-2026-6093
3 min read
Custom css-js-php WordPress Plugin SQLi Leads to RCE (CVE-2026-6433)CRITICAL
Vulnerabilities

Custom css-js-php WordPress Plugin SQLi Leads to RCE (CVE-2026-6433)

CVE-2026-6433: Unauthenticated SQL injection in Custom css-js-php plugin ≤2.0.7 lets attackers execute arbitrary PHP via eval(). No patch available.

CVE-2026-6433
3 min read
CVE-2025-61314: Reflected XSS in Mecury Managed Print ServicesHIGH
Vulnerabilities

CVE-2025-61314: Reflected XSS in Mecury Managed Print Services

CVE-2025-61314: Reflected XSS in GmbH Mecury Managed Print Services docuForm v11.11c allows attackers to execute arbitrary JS via crafted payload in dfm-menu_orderopt.php.

CVE-2025-61314
3 min read
CVE-2025-65417: docuFORM MPS Client Reflected XSS in Login PageHIGH
Vulnerabilities

CVE-2025-65417: docuFORM MPS Client Reflected XSS in Login Page

CVE-2025-65417: A reflected XSS flaw in docuFORM Managed Print Service Client 11.11c lets unauthenticated attackers execute arbitrary scripts via the login page.

CVE-2025-65417
3 min read
CVE-2026-5084: WebDyne Session IDs Generated with Weak MD5/rand()HIGH
Vulnerabilities

CVE-2026-5084: WebDyne Session IDs Generated with Weak MD5/rand()

CVE-2026-5084: WebDyne::Session through 2.075 for Perl generates session IDs from an MD5 hash seeded with rand(), enabling session prediction and hijacking.

CVE-2026-5084
3 min read
← PrevPage 8 of 36Next →