Aggregator
CVE-2025-42911 | SAP NetWeaver up to 816 authorization
CVE-2025-58745 | LabRedesCefetRJ WeGIA up to 3.4.10 PHP File controla_xlsx.php code injection (GHSA-hq96-gvmx-qrwp)
CVE-2025-58449 | MahoCommerce maho up to 25.8.x PHP File Parser reliance on file name or extension of externally-supplied file (GHSA-vgmm-27fc-vmgp)
CVE-2025-42958 | SAP NetWeaver up to KRNL64UC 7.22 unnecessary privileges
Connected cars are racing ahead, but security is stuck in neutral
Connected cars are already on Europe’s roads, loaded with software, sensors, and constant data connections. Drivers love the features these vehicles bring, from remote apps to smart navigation, but each new connection also opens a door to potential cyber risks. What makes cars smarter is the same thing that makes them more vulnerable. A new study from Óbuda University in Budapest and the University of Oslo sheds light on these threats, where current rules fall … More →
The post Connected cars are racing ahead, but security is stuck in neutral appeared first on Help Net Security.
CVE-2025-42927 | SAP NetWeaver AS Java 7.50 Adobe Document Service vulnerable third-party component
虚假PDF编辑器暗藏TamperedChef信息窃取恶意软件
«СёрчИнформ» проведет серию бесплатных ИБ-конференций
Kill
You must login to view this content
Lynx
You must login to view this content
Chinese Hackers Salt Typhoon and UNC4841 Team Up to Breach Critical Infrastructure
Cybersecurity researchers at Silent Push have uncovered a sophisticated Chinese espionage operation linking two prominent threat actors, Salt Typhoon and UNC4841, revealing previously unreported infrastructure used to target government and corporate networks across more than 80 countries. The discovery of 45 malicious domains dating back to 2020 demonstrates the extensive reach and long-term persistence of […]
The post Chinese Hackers Salt Typhoon and UNC4841 Team Up to Breach Critical Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Yurei
You must login to view this content
【安全圈】黑客武器化 Amazon SES,每日发送超 5 万封恶意邮件
【安全圈】史上最大 npm 供应链攻击:周下载量超 20 亿的 18 个包被植入恶意代码
【安全圈】民警非法倒卖公民个人信息获刑
【安全圈】福建莆田13.3亿元特大非法虚拟货币换汇
LunaLock Ransomware threatens victims by feeding stolen data to AI models
Hackers Hijack 18 Popular npm Packages Downloaded Over 2 Billion Times Weekly
Hackers have hijacked 18 extremely popular npm packages, downloaded more than 2 billion times every week, injecting them with sophisticated malware that targets cryptocurrency users and developers. Early on September 8th, a security feed flagged the sudden update of 18 npm packages—including favorites like chalk, debug, chalk-template, and supports-color—with malicious code, as per a report by Aikio. These packages […]
The post Hackers Hijack 18 Popular npm Packages Downloaded Over 2 Billion Times Weekly appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.