Aggregator
Microsoft Patches SharePoint Flaws as Hackers Rush to Exploit Them
As Microsoft puts the final patch in place, a growing number of hackers, including several China state-sponsored threat groups, are quickly pushing forward to exploit the security flaws that will allow them compromise on-premises SharePoint servers to steal data and maintain persistence.
The post Microsoft Patches SharePoint Flaws as Hackers Rush to Exploit Them appeared first on Security Boulevard.
ETQ Reliance RCE Flaw Grants Full SYSTEM Access with a Single Space
Hexagon ETQ’s Java-based quality management system, ETQ Reliance, has several serious flaws, according to a new security research revelation by Assetnote. The software, which facilitates document and form management with integrations like Microsoft Word macros and Jython scripting, has been found susceptible to exploits ranging from reflected cross-site scripting (XSS) to XML External Entity (XXE) […]
The post ETQ Reliance RCE Flaw Grants Full SYSTEM Access with a Single Space appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Microsoft pins on-prem SharePoint attacks on Chinese threat actors
As Microsoft continues to update its customer guidance for protecting on-prem SharePoint servers against the latest in-the-wild attacks, more security firms have begun sharing details about the ones they have detected. Most intriguingly, Check Point Research says that they observed the first exploitation attempts on July 7th, with the target being a major Western government. That date not only precedes the publication of the screenshot of the ToolShell exploit chain (CVE-2025-49706 + CVE-2025-49704) in action … More →
The post Microsoft pins on-prem SharePoint attacks on Chinese threat actors appeared first on Help Net Security.
Взлом громкий, файлы липовые. Хакеры стащили из Dell 1,3 ТБ мусора... и требуют миллионы
CVE-2025-51859 | Chaindesk up to 2025-05-26 Agent Chat cross site scripting (EUVD-2025-22327)
CVE-2025-51858 | ChatPlayground.ai up to 2025-05-24 Chat cross site scripting
CVE-2025-6214 | Omnishop Plugin up to 1.0.9 on WordPress REST Endpoint /users/delete permission_callback cross-site request forgery
CISA Warns of Interlock Ransomware With Double Extortion Tactics Attacking Windows and Linux Systems
The Cybersecurity and Infrastructure Security Agency (CISA), FBI, Department of Health and Human Services, and Multi-State Information Sharing and Analysis Center have issued an urgent joint advisory warning of escalating attacks by the Interlock ransomware group, which has been targeting businesses and critical infrastructure sectors since late September 2024. The newly emerged Interlock variant represents […]
The post CISA Warns of Interlock Ransomware With Double Extortion Tactics Attacking Windows and Linux Systems appeared first on Cyber Security News.