Aggregator
CVE-2025-10093 | D-Link DIR-852 up to 1.00CN B09 Device Configuration /getcfg.php phpcgi_main information disclosure (EUVD-2025-27121)
CVE-2025-58422 | Ricoh Streamline NX HTTP Request less trusted source (icoh-2025-000010 / EUVD-2025-27108)
知名安卓启动器Nova Launcher的创始人离开 原本的开源计划应该也没戏了
КИИ Basic от Security Vision
Submit #644935: D-Link DIR-852 1.00CN B09 Exposure of Sensitive Information Through Data Queries [Accepted]
CVE-2025-10092 | Jinher OA up to 1.2 XML ?Type=add xml external entity reference (EUVD-2025-27123)
CVE-2025-10091 | Jinher OA up to 1.2 XML ?Type=add xml external entity reference (EUVD-2025-27120)
CVE-2025-10090 | Jinher OA up to 1.2 GetTreeDate.aspx ID sql injection (EUVD-2025-27119)
Submit #644920: Shenzhen Jixiang Tenda Technology Co., Ltd. Tenda AC6 v2.0_V15.03.06.51 Buffer Overflow [Duplicate]
Cyber defense cannot be democratized
The democratization of AI has fundamentally lowered the barrier for threat actors, creating a bigger pool of people who can carry out sophisticated attacks. The so-called democratization of security, on the other hand, has resulted in chaos. The problem In an earnest attempt to shift left, security teams deputized developers to own remediation. While development teams have legitimately become more security-focused, it’s created a dynamic in which security is still accountable for risk but has … More →
The post Cyber defense cannot be democratized appeared first on Help Net Security.
Critical Argo CD API Flaw Exposes Repository Credentials to Attackers
A major security flaw has been discovered in Argo CD, a popular open-source tool used for Kubernetes GitOps deployments. The vulnerability allows project-level API tokens to expose sensitive repository credentials, such as usernames and passwords, to attackers. The issue has been classified as critical with a CVSS score of 9.8/10 and is tracked as CVE-2025-55190. The […]
The post Critical Argo CD API Flaw Exposes Repository Credentials to Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.