Aggregator
Submit #583562: TOTOLINK X15 V1.0.0-B20230714.1105 Stack-based Buffer Overflow and Command Injection [Accepted]
Vet: Open-source software supply chain security tool
Vet is an open source tool designed to help developers and security engineers spot risks in their software supply chains. It goes beyond traditional software composition analysis by detecting known vulnerabilities and flagging malicious packages. Vet supports several ecosystems, including npm, PyPI, Maven, Go, Docker, and GitHub Actions, making it useful across many types of projects. One of Vet’s key features is its use of real-time malicious package detection, powered by SafeDep Cloud. It also … More →
The post Vet: Open-source software supply chain security tool appeared first on Help Net Security.
微软 Google 等将统一国家支持的黑客组织的绰号
CVE-2025-5501 | Open5GS up to 2.7.3 NGAP PathSwitchRequest Message src/smf/ngap-handler.c ngap_handle_path_switch_request_transfer assertion (Issue 3909)
Submit #582265: Open5GS <=2.7.3 Reachable Assertion [Accepted]
CVE-2025-5499 | slackero phpwcms up to 1.9.45/1.10.8 image_resized.php is_file/getimagesize imgfile deserialization
CVE-2025-5498 | slackero phpwcms up to 1.9.45/1.10.8 Custom Source Tab cnt21.readform.inc.php file_get_contents/is_file cpage_custom deserialization
CVE-2025-5497 | slackero phpwcms up to 1.9.45/1.10.8 Feedimport Module processing.inc.php cnt_text deserialization (EUVD-2025-16727)
Submit #578083: phpwcms 1.10.8 phar/php filter vulnerability [Duplicate]
Submit #578082: phpwcms 1.10.8 phar/php filter vulnerability [Accepted]
Submit #578055: phpwcms 1.10.8 phar/php filter vulnerability [Duplicate]
Submit #578054: phpwcms 1.10.8 phar/php filter vulnerability [Accepted]
Submit #577999: phpwcms 1.10.8 phar deserialization vulnerability [Accepted]
CVE-2025-5495 | Netgear WNR614 1.1.0.28_1.0.1WW URL improper authentication (EUVD-2025-16726)
F5 Buys Startup Fletch to Automate Security With Agentic AI
With its acquisition of San Francisco-based startup Fletch, F5 is embedding agentic AI into its security platform to automate threat detection and response. The technology provides real-time context, filters irrelevant alerts and helps security teams prioritize urgent risks and mitigation tasks.
Dutch Minister Warns of Heightened Chinese Espionage Threats
Chinese nation state groups ramped up espionage campaigns against Dutch critical infrastructure in recent months, said a state official who added that discussions are underway in the European Union on how to minimize Chinese threats.
Flaw in Cisco Wireless LAN Controller Raises Exploit Fears
Technical details for a recently patched maximum-severity vulnerability in Cisco IOS XE reveal how hackers can enable remote code execution if the flaw is exploited. The vulnerability is an arbitrary file upload triggered by a hardcoded JSON Web Token.
Trump Homeland Security Budget Guts CISA Staff, Key Programs
The Trump administration’s 2026 Homeland Security Department budget would cut $500 million from the Cybersecurity and Infrastructure Security Agency, eliminating over a third of its staff and gutting key programs central to federal cybersecurity and private sector engagement efforts.
Bankers Association’s attack on cybersecurity transparency
A coalition of banking industry associations, including SIFA, the American Bankers Association (ABA), Bank Policy Institute (BPI), and several other lobbying groups have made a disgraceful appeal to the SEC to eliminate the rule requiring public disclosure of material cybersecurity incidents within four days of detection. This rule was established to ensure shareholders are properly informed and potential victims receive timely notice so they can take protective action, which wasn’t happening consistently before the rule … More →
The post Bankers Association’s attack on cybersecurity transparency appeared first on Help Net Security.