Aggregator
CVE-2023-24728 | SourceCodester Simple Customer Relationship Management System 1.0 User Profile Update Contact sql injection
CVE-2023-24730 | SourceCodester Simple Customer Relationship Management System 1.0 User Profile Update company sql injection
CVE-2023-24732 | SourceCodester Simple Customer Relationship Management System 1.0 User Profile Update gender sql injection
Slavery, torture, human trafficking discovered at 53 Cambodian online scamming compounds
Pig butchering scams were the most common activity carried out at the facilities identified in the Amnesty International investigation.
The post Slavery, torture, human trafficking discovered at 53 Cambodian online scamming compounds appeared first on CyberScoop.
Taking over millions of developers exploiting an Open VSX Registry flaw
Microsoft security updates address CrowdStrike crash, kill ‘Blue Screen of Death’
Third-party antivirus software will no longer have access to the Windows kernel as Microsoft rolls out changes to reduce IT downtime from unexpected crashes or disruptions.
The post Microsoft security updates address CrowdStrike crash, kill ‘Blue Screen of Death’ appeared first on CyberScoop.
Threat Actors Leverage Windows Task Scheduler to Embed Malware and Maintain Persistence
A comprehensive follow-up analysis to the FortiGuard Incident Response Team’s (FGIR) investigation titled “Intrusion into Middle East Critical National Infrastructure” has revealed a protracted cyberattack that targeted critical national infrastructure (CNI) in the Middle East. This is a startling revelation. The report, part of the 2025 Global Threat Landscape Report, exposes how threat actors exploited […]
The post Threat Actors Leverage Windows Task Scheduler to Embed Malware and Maintain Persistence appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Scattered Spider strikes again? Aviation industry appears to be next target for criminal group
Hawaiian Airlines announced a cybersecurity incident Friday as security experts warned of a sector-wide threat.
The post Scattered Spider strikes again? Aviation industry appears to be next target for criminal group appeared first on CyberScoop.
MongoDB security advisory (AV25-380)
Exploitation of Microsoft 365 Direct Send to Deliver Phishing Emails as Internal Users
A sophisticated phishing campaign targeting over 70 organizations, predominantly in the US, has been uncovered by Varonis’ Managed Data Detection and Response (MDDR) Forensics team. This campaign, active since May 2025, exploits a lesser-known feature of Microsoft 365 called Direct Send, which allows devices and applications within a tenant to send emails without authentication. Designed […]
The post Exploitation of Microsoft 365 Direct Send to Deliver Phishing Emails as Internal Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
ДНК не врёт: древние турки 7000 лет жили на одном месте, но весь мир копировал их лайфхаки
CVE-2025-6850 | code-projects Simple Forum 1.0 /forum1.php File sql injection (EUVD-2025-19475)
CVE-2025-6849 | code-projects Simple Forum 1.0 /forum_edit1.php text cross site scripting (EUVD-2025-19476)
CVE-2025-6848 | code-projects Simple Forum 1.0 /forum1.php File unrestricted upload
CVE-2025-6847 | code-projects Simple Forum 1.0 /forum_edit.php iii sql injection (EUVD-2025-19474)
CVE-2025-6846 | code-projects Simple Forum 1.0 /forum_viewfile.php Name sql injection (EUVD-2025-19472)
CVE-2025-6845 | code-projects Simple Forum 1.0 /register1.php User sql injection (EUVD-2025-19473)
CVE-2025-6844 | code-projects Simple Forum 1.0 /signin.php User sql injection
STRATEGIC REEL: APIs are the new perimeter — and business logic attacks are slipping through
APIs have become the digital glue of the enterprise — and attackers know it.
Related: API security – the big picture
In this debut edition of the Last Watchdog Strategic Reel (LWSR), A10 Networks’ Field CISO Jamison Utter cuts … (more…)
The post STRATEGIC REEL: APIs are the new perimeter — and business logic attacks are slipping through first appeared on The Last Watchdog.
The post STRATEGIC REEL: APIs are the new perimeter — and business logic attacks are slipping through appeared first on Security Boulevard.