Aggregator
Submit #591127: code-projects Patient Record Management System 1.0 SQL Injection [Accepted]
在传出 OpenAI 准备收购 Windsurf 后 Anthropic 切断了该公司对其大模型的访问
Submit #591110: 1000 Projects ABC Courier Management System V1.0 SQL Injection [Accepted]
June 2025 Patch Tuesday forecast: Second time is the charm?
Microsoft has been busy releasing more out-of-band (OOB) patches than usual throughout May. The May Patch Tuesday release of updates was typical in number of vulnerabilities addressed with 41 in both Windows 10 and 11, and their associated servers. They also did a great job finally fixing most of the reported issues that have been carried out for a while. But it appears something was not quite right, because there were some issues reported from … More →
The post June 2025 Patch Tuesday forecast: Second time is the charm? appeared first on Help Net Security.
CVE-2024-46941 | Vivo SystemUI Component Protection Setting permissions (EUVD-2024-54649)
CVE-2024-56342 | IBM Verify Identity Access Digital Credentials 24.06 information exposure (EUVD-2024-54648)
CVE-2025-36513 | i-PRO Surveillance Camera cross-site request forgery (EUVD-2025-17048)
CVE-2025-5719 | Vivo Wallet missing authentication (EUVD-2025-17051)
PrimeCache: бэкдор, который живёт по принципу "не трогай — не заметят"
Hackers Exploit Roundcube Vulnerability to Steal User Credentials via XSS Attack
A recent spearphishing campaign targeting Polish entities has been attributed with high confidence to the UNC1151 threat actor, a group linked to Belarusian state interests and, according to some sources, Russian intelligence services. CERT Polska reports that the attackers leveraged a critical vulnerability in the Roundcube webmail platform—CVE-2024-42009—to steal user credentials with minimal user interaction. […]
The post Hackers Exploit Roundcube Vulnerability to Steal User Credentials via XSS Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Переговоры с вымогателями: спасение или ловушка?
ATAG:AI 代理应用威胁评估与攻击图
Pathlock helps organizations protect their SAP environments from development to deployment
Pathlock announced a major expansion of its SAP cybersecurity offerings, introducing a new portfolio of value-driven and easy-to-deploy SAP cybersecurity solutions, including a Free Edition. Designed to deliver maximum value and fast time-to-protection, the launch marks a significant step toward democratizing SAP security for organizations of all sizes. Meeting the urgent need for SAP cybersecurity As SAP ERP continues to serve as the digital core for thousands of enterprises worldwide, the need for easy, effective … More →
The post Pathlock helps organizations protect their SAP environments from development to deployment appeared first on Help Net Security.
亚马逊测试用人形机器人送包裹
ViperSoftX мутировал: хакеры создали неуязвимый криптовор
Hackers Using New Sophisticated iMessage 0-Click Exploit to Attack iPhone Users
A previously unknown zero-click vulnerability in Apple’s iMessage appears to have been exploited by sophisticated threat actors targeting high-profile individuals across the United States and the European Union. The vulnerability, dubbed “NICKNAME,” affected iOS versions up to 18.1.1 and was silently patched by Apple in iOS 18.3. The discovery, made by cybersecurity firm iVerify, reveals […]
The post Hackers Using New Sophisticated iMessage 0-Click Exploit to Attack iPhone Users appeared first on Cyber Security News.
CVE-2023-2921 | Short URL Plugin up to 1.6.8 on WordPress sql injection
Claroty enhances xDome platform with Device Purpose and Risk Benchmarking capabilities
Claroty announced new capabilities in its SaaS-based Claroty xDome platform that provide organizations with an impact-centric view of their CPS environment. The new additions, Device Purpose and Risk Benchmarking, allow users to see how the overall risk of an environment is affected by the processes involved in a device’s use – as production lines, building floors, hospital wings, and more – and prioritize risk reduction efforts based on potential impact to business outcomes, while bridging … More →
The post Claroty enhances xDome platform with Device Purpose and Risk Benchmarking capabilities appeared first on Help Net Security.