Aggregator
CVE-2025-4559 | Netvision ISOinsight prior 2.9.0.250501/3.0.0.250501 sql injection (EUVD-2025-14271)
CVE-2025-4561 | Kinfor KFOX up to 2.6 unrestricted upload
CVE-2025-3597 | Firelight Lightbox Plugin up to 2.3.14 on WordPress jQuery Metadata Library cross site scripting
Не хочешь дружить с ИИ — тогда освободи рабочее место
雷神众测漏洞周报2025.5.6-2025.5.11
雷神众测漏洞周报2025.5.6-2025.5.11
deepin 社区表示将改进安全响应和修复安全问题
奇安信安全研究员在 Off-by-One 2025大会发表研究成果
奇安信安全研究员在 Off-by-One 2025大会发表研究成果
业内招聘 | 这里有你无法拒绝的安全挑战与丰厚回报
美国警告:黑客计划攻击石油和天然气公司的 ICS/SCADA
业内招聘 | 这里有你无法拒绝的安全挑战与丰厚回报
美国警告:黑客计划攻击石油和天然气公司的 ICS/SCADA
Hackers Abuse Copilot AI in SharePoint to Steal Passwords and Sensitive Data
Microsoft’s Copilot for SharePoint, designed to streamline enterprise collaboration through generative AI, has become an unexpected weapon for cybercriminals targeting organizational secrets. Recent findings from cybersecurity researchers reveal that attackers are exploiting AI agents embedded in SharePoint sites to bypass traditional security controls, extract passwords, and access restricted files-all while evading detection. This novel attack […]
The post Hackers Abuse Copilot AI in SharePoint to Steal Passwords and Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Defendnot: A Tool That Disables Windows Defender by Registering as Antivirus
Cybersecurity developers have released a new tool called “defendnot,” a successor to the previously DMCA-takedown-affected “no-defender” project. This innovative utility leverages undocumented Windows Security Center APIs to disable Windows Defender by registering itself as a third-party antivirus solution. The developer recently shared their journey implementing this technical workaround while traveling abroad with limited development resources. […]
The post Defendnot: A Tool That Disables Windows Defender by Registering as Antivirus appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
介绍《Hacking the Hacker》
介绍《Hacking the Hacker》
2 миллиарда ушли из-под носа брокеров, а всё выглядело как обычная торговля
Mitel SIP Phone Flaws Allow Attackers to Inject Malicious Commands
A pair of vulnerabilities in Mitel’s 6800 Series, 6900 Series, and 6900w Series SIP Phones-including the 6970 Conference Unit-could enable attackers to execute arbitrary commands or upload malicious files to compromised devices, posing significant risks to enterprise communication systems. The flaws, disclosed in Mitel’s Product Security Advisory MISA-2025-0004, include a critical-severity command injection bug (CVE-2025-47188) […]
The post Mitel SIP Phone Flaws Allow Attackers to Inject Malicious Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.