Aggregator
CVE-2025-7445 | Kubernetes secrets-store-sync-controller up to 0.0.1 Service Account Token log file (Issue 133897)
CVE-2025-55242 | Microsoft Xbox Gaming Services information disclosure
CVE-2025-55238 | Microsoft Dynamics 365 FastTrack Implementation access control (WID-SEC-2025-1972)
CVE-2025-58401 | Pierre-Adrien Vasseur Obsidian GitHub Copilot Plugin up to 1.1.6 cleartext storage
CVE-2025-58352 | weblate up to 5.13.0 session expiration (GHSA-377j-wj38-4728)
CVE-2025-58179 | withastro up to 12.6.5 Generated Image Optimization Endpoint server-side request forgery (GHSA-qpr4-c339-7vq8)
CVE-2025-58362 | honojs hono up to 4.9.5 /admin name resolution (GHSA-9hp6-4448-45g2)
CVE-2025-55190 | argoproj argo-cd up to 2.13.8/2.14.15/3.0.13/3.1.1 API Endpoint role/user information disclosure (GHSA-786q-9hcg-v9ff / WID-SEC-2025-1978)
SQL for Bug Bounty Hunters
File security risks rise as insiders, malware, and AI challenges converge
Breaches tied to file access are happening often, and the costs add up quickly. Many organizations have faced multiple file-related incidents over the last two years, with financial losses stretching into the millions. The fallout often includes stolen customer data, reduced productivity, and exposure of intellectual property. A new study from Ponemon Institute shows that data leakage from insiders is a huge threat. Both negligence and malicious intent drive this risk, leaving organizations exposed when … More →
The post File security risks rise as insiders, malware, and AI challenges converge appeared first on Help Net Security.
«Пшикни и забудь»: как аптечный спрей стал новым хитом против COVID
CVE-2025-55305 | Electron up to 35.7.4/36.8.0/37.3.0 embeddedAsarIntegrityValidation code injection (GHSA-vmqv-hx8q-j7mg)
CVE-2025-55739 | FreePBX up to 15.0.12/16.0.14/17.0.2 OAuth hard-coded credentials (GHSA-3r47-p39v-vqqf)
A Video on Optimizing VLF Loop Antennas
Smart ways CISOs can do more with less
In this Help Net Security video, Jill Knesek, CISO at BlackLine, shares practical strategies for CISOs navigating tighter budgets. From maximizing existing tools and vendor partnerships to leveraging AI and making smart investments, she offers actionable advice for maintaining strong security without overspending. Learn more: eBay CISO on managing long-term cybersecurity planning and ROI How CISOs can talk cybersecurity so it makes sense to executives Smart cybersecurity spending and how CISOs can invest where it … More →
The post Smart ways CISOs can do more with less appeared first on Help Net Security.