-
TorNet Backdoor Detection: An Ongoing Phishing Email Campaign Uses PureCrypter Malware to Drop Other Payloads
Financially motivated hackers are behind an ongoing malicious campaign targeting Poland and Germany. These phishing attacks aim to deploy multiple payloads, including Agent Tesla, Snake Keylogger, and a novel backdoor dubbed TorNet, which is delivered via PureCrypter malware. Detect TorNet Backdoor A significant rise in phishing campaigns, with a 202% increase in phishing messages over…
-
Lumma Stealer Detection: Sophisticated Campaign Using GitHub Infrastructure to Spread SectopRAT, Vidar, Cobeacon, and Other Types of Malware
Lumma Stealer, nefarious info-stealing malware, resurfaces in the cyber threat arena. Defenders recently uncovered an advanced adversary campaign distributing Lumma Stealer through GitHub infrastructure along with other malware variants, including SectopRAT, Vidar, and Cobeacon. Detect Lumma Stealer, SectopRAT, Vidar, Cobeacon Deployed via GitHub Lumma Stealer is a notorious data-stealing malware that extracts credentials, cryptocurrency wallets,…
-
CVE-2025-0804 – WordPress ClickWhale Link Manager Stored XSS
CVE ID : CVE-2025-0804 Published : Jan. 29, 2025, 4:15 a.m. | 2 hours, 46 minutes ago Description : The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to…
-
CVE-2024-12749 – WordPress Competition Form XSS Vulnerability
CVE ID : CVE-2024-12749 Published : Jan. 29, 2025, 6:15 a.m. | 45 minutes ago Description : The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. Severity:…
-
CVE-2025-23362 – Adobe EXIF Viewer Classic Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-23362 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered and crafted EXIF meta data is processed, an arbitrary script may be executed…
-
CVE-2025-0806 – Code-projects Job Recruitment Cross Site Scripting Vulnerability
CVE ID : CVE-2025-0806 Published : Jan. 29, 2025, 3:15 a.m. | 3 hours, 46 minutes ago Description : A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the file _call_job_search_ajax.php. The manipulation of the argument job_type leads to cross site scripting. The attack…
-
CVE-2025-0802 – SourceCodester Best Employee Management System Remote Improper Access Control Vulnerability
CVE ID : CVE-2025-0802 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of the component Administrative Endpoint. The manipulation leads to improper access controls.…
-
CVE-2025-0803 – Codezips Gym Management System SQL Injection Vulnerability
CVE ID : CVE-2025-0803 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/submit_plan_new.php. The manipulation of the argument planid leads to sql injection.…
-
CVE-2025-0800 – SourceCodester Online Courseware Cross Site Scripting
CVE ID : CVE-2025-0800 Published : Jan. 29, 2025, 2:15 a.m. | 4 hours, 45 minutes ago Description : A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. The manipulation of the argument fname leads to cross site scripting.…
-
CVE-2025-0798 – MicroWorld eScan Antivirus os Command Injection Vulnerability
CVE ID : CVE-2025-0798 Published : Jan. 29, 2025, 2:15 a.m. | 5 hours, 44 minutes ago Description : A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command…