Aggregator
Submit #645386: itsourcecode Student Information Management System V1.0 SQL injection [Accepted]
CVE-2025-10109 | Campcodes Online Loan Management System 1.0 ajax.php?action=delete_payment ID sql injection
CVE-2025-10108 | Campcodes Online Loan Management System 1.0 ajax.php?action=delete_loan ID sql injection
Submit #645383: https://gitee.com/chancms/ChanCMS ChanCMS 3.3.1 SQL Injection [Accepted]
西安电子科技大学 | GlareShell: 基于图学习的PHP Webshell检测
IBM security advisory (AV25-569)
Submit #645379: Campcodes Online Loan Management System V1.0 SQL Injection [Accepted]
Submit #645378: Campcodes Online Loan Management System V1.0 SQL Injection [Accepted]
Canadian investment platform Wealthsimple disclosed a data breach
MostereRAT Targets Windows, Uses AnyDesk and TightVNC for Full Access
CVE-2025-10106 | yanyutao0402 ChanCMS up to 3.3.1 /cms/collect/search keyword sql injection
CVE-2025-10105 | yanyutao0402 ChanCMS up to 3.3.1 /cms/article/search keyword sql injection
CVE-2025-36853 | Microsoft .NetCore.App.Runtime.win-x86 up to 6.0.36 msdia140.dll malloc integer overflow
Submit #645354: ChanCMS https://github.com/chancms/ChanCMS 3.3.1 SQL Injection [Accepted]
Submit #645341: ChanCMS https://gitee.com/chancms/ChanCMS 3.3.1 SQL Injection [Accepted]
The Critical Failure in Vulnerability Management
Exposed ‘Kim’ Dump Exposes Kimsuky Hackers New Tactics, Techniques, and Infrastructure
A massive data breach in early September 2025 attributed to a cyber actor known simply as “Kim” laid bare an unprecedented view into the operational playbook of Kimsuky (APT43). The leak, comprising terminal history files, phishing domains, OCR workflows, compiled stagers, and a full Linux rootkit, revealed a credential-centric campaign that targeted South Korean government […]
The post Exposed ‘Kim’ Dump Exposes Kimsuky Hackers New Tactics, Techniques, and Infrastructure appeared first on Cyber Security News.
В Citrix NetScaler обнаружена критическая уязвимость переполнения памяти CVE-2025-7775
SentinelOne to acquire Observo AI, enhancing SIEM and security operations
SentinelOne has announced its intent to acquire Observo AI. The deal will serve as an immediate complement and catalyst to SentinelOne’s AI SIEM and data offerings, which are already amongst the company’s fastest growing solutions, delivering a record contribution to quarterly bookings in Q2 FY26. It will also help SentinelOne usher in a new era of open, intelligent, and autonomous security operations, reimagining how SOC teams collect, enrich, and act on data across their entire … More →
The post SentinelOne to acquire Observo AI, enhancing SIEM and security operations appeared first on Help Net Security.