Aggregator
Scavenger Malware Hijacks Popular npm Packages to Attack Developers
A sophisticated supply chain attack targeting JavaScript developers emerged on Friday, July 18th, 2025, when cybercriminals compromised multiple popular npm packages to distribute the newly identified “Scavenger” malware. The attack primarily focused on eslint-config-prettier, a widely-used code formatting package, along with several other development tools including eslint-plugin-prettier, snyckit, @pkgr/core, and napi-postinstall. The compromise was discovered […]
The post Scavenger Malware Hijacks Popular npm Packages to Attack Developers appeared first on Cyber Security News.
Defending Against ToolShell: SharePoint’s Latest Critical Vulnerability
Defending Against ToolShell: SharePoint’s Latest Critical Vulnerability
Pavel Durov Warns: New Extortion Wave Targets Telegram Users for Digital Assets
Pavel Durov, the founder of Telegram, has issued a warning about a new wave of extortion emerging within the platform. The scheme involves fraudsters demanding that users surrender valuable digital assets—rare Telegram gifts, premium...
The post Pavel Durov Warns: New Extortion Wave Targets Telegram Users for Digital Assets appeared first on Penetration Testing Tools.
安全通告 - 涉及华为EnzoH产品的系统命令注入漏洞
派早报:Nothing 发布 CMF Watch 3 Pro、任天堂召开宝可梦 7 月直面会等
威努特超融合系统解决方案,重塑高校数据中心云化架构
CVE-2025-47053 | Adobe Experience Manager up to 6.5.22 cross site scripting (apsb25-48 / EUVD-2025-21721)
CVE-2024-32124 | Fortinet FortiIsolator up to 2.3.4/2.4.4 HTTP Request access control (FG-IR-24-045 / EUVD-2024-29945)
CVE-2025-2425 | ESET NOD32 Antivirus toctou (EUVD-2025-21865)
CVE-2025-50058 | rsjoomla RSDirectory Component up to 2.2.8 on Joomla Review Reply cross site scripting (EUVD-2025-21869)
CVE-2025-7444 | LoginPress Pro Plugin up to 5.0.1 on WordPress OAuth Provider improper authentication (EUVD-2025-21859)
CVE-2025-50056 | rsjoomla RSMail Component up to 1.22.28 on Joomla crafted cross site scripting (EUVD-2025-21871)
CVE-2025-50057 | rsjoomla RSFiles Component up to 1.17.7 on Joomla Search resource consumption (EUVD-2025-21870)
CVE-2025-49485 | Balbooa Forms Component up to 2.3.1.1 on Joomla ID sql injection (EUVD-2025-21872)
CVE-2025-49486 | Balbooa Gallery Component up to 2.4.0 on Joomla Gallery Item cross site scripting (EUVD-2025-21873)
APT41’s New Frontier: Chinese Cyberespionage Group Targets African Governments
The China-linked cyber-espionage group APT41 has launched a new surveillance campaign targeting government IT services in Africa—an unexpected turn for a region previously considered an unlikely target. Researchers at Kaspersky Lab uncovered the operation...
The post APT41’s New Frontier: Chinese Cyberespionage Group Targets African Governments appeared first on Penetration Testing Tools.
Silent Scourge: Over 3,500 Websites Infected by New Covert Browser Cryptominer
Cybersecurity specialists at cside have uncovered a vast and covert cryptocurrency mining campaign that has compromised over 3,500 websites—marking the largest incident of its kind in recent years and signaling the resurgence of tactics...
The post Silent Scourge: Over 3,500 Websites Infected by New Covert Browser Cryptominer appeared first on Penetration Testing Tools.
Snake Keylogger Strikes Turkish Aerospace & Defense, Evades Detection with Stealthy Tactics
Turkish cybersecurity experts at Malwation have uncovered a large-scale phishing campaign targeting enterprises in the defense and aerospace sectors. Threat actors are disguising malicious attachments as official documents purportedly issued by TUSAŞ, Turkey’s state-owned...
The post Snake Keylogger Strikes Turkish Aerospace & Defense, Evades Detection with Stealthy Tactics appeared first on Penetration Testing Tools.