Aggregator
CVE-2025-63608 | CSZ CSZ-CMS up to 1.3.0 Form Builder View Field sql injection
Lampion Stealer Resurfaces with ClickFix Attack to Steal User Credentials Stealthily
A Brazilian cybercriminal group has refined its long-running malware distribution campaign by incorporating innovative social engineering techniques and multi-stage infection chains to deliver the Lampion banking trojan. The campaign, which has operated continuously since at least June 2024 following its initial discovery in 2019, demonstrates the threat actor’s commitment to operational stealth and evasion. The […]
The post Lampion Stealer Resurfaces with ClickFix Attack to Steal User Credentials Stealthily appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-10317 | OpenSolution Quick.Cart 6.7 cross-site request forgery
CVE-2025-53883 | SUSE Container Manager prior 5.0.28-150600.3.36.8 Search cross site scripting (Nessus ID 271943)
Доминирование США подходит к концу: 35,6 млн программистов за 5 лет — и Индия становится новым центром мировой разработки
Critical Vulnerability in Chromium’s Blink Let Attackers Crash Chromium-based Browsers Within Seconds
Security researcher Jofpin has disclosed “Brash,” a critical flaw in Google’s Blink rendering engine that enables attackers to crash Chromium-based browsers almost instantly. Affecting billions of users worldwide, this architectural weakness exploits unchecked updates to the document.title API, overwhelming the browser’s main thread and triggering system-wide denial of service without sophisticated tools or privileges. The […]
The post Critical Vulnerability in Chromium’s Blink Let Attackers Crash Chromium-based Browsers Within Seconds appeared first on Cyber Security News.
CVE-2025-53880 | SUSE Container Manager path traversal
Upwind unveils AI-powered Exposure Validation Engine to redefine dynamic CSPM
Upwind has launched its Exposure Validation Engine, a capability that introduces dynamic, real-time validation into the Cloud Security Posture Management (CSPM) layer. This innovation enables security, engineering, and compliance teams to validate live cloud exposures with precision under real-world conditions. “Cloud security teams are tasked to do the impossible, to protect digital assets in ever changing cloud environment.” said Amiram Shachar, CEO of Upwind. “Our job is to simplify the work of cloud security leaders … More →
The post Upwind unveils AI-powered Exposure Validation Engine to redefine dynamic CSPM appeared first on Help Net Security.
CVE-2025-54471 | SUSE neuvector up to 5.4.6 hard-coded key (GHSA-h773-7gf7-9m2x)
CVE-2025-54469 | SUSE neuvector up to 5.3.4/5.4.6 popen CLUSTER_RPC_PORT/CLUSTER_LAN_PORT os command injection (GHSA-c8g6-qrwh-m3vp)
G.O.S.S.I.P 阅读推荐 2025-10-30 开始的开始,是谁在唱歌
CVE-2025-54470 | SUSE neuvector up to 5.3.4/5.4.6 certificate validation (GHSA-qqj3-g7mx-5p4w)
CVE-2025-40102 | Linux Kernel up to 6.17.4/6.18-rc1 arm64 uninitialized pointer
CVE-2025-40101 | Linux Kernel up to 6.12.54/6.17.4/6.18-rc1 btrfs_load_block_group_zone_info memory leak
Drupal security advisory (AV25-709)
CVE-2025-40099 | Linux Kernel up to 6.1.157/6.6.113/6.12.54/6.17.4/6.18-rc1 cifs parse_dfs_referrals out-of-bounds
CVE-2025-40098 | Linux Kernel up to 6.17.4/6.18-rc1 ALSA cs35l41_get_acpi_mute_state Return null pointer dereference
Critical Blink Vulnerability Lets Attackers Crash Chromium Browsers in Seconds
Security researchers have discovered a critical architectural flaw in the Blink rendering engine that powers Chromium-based browsers, exposing over 3 billion users to denial-of-service attacks. The vulnerability, called Brash, allows malicious actors to completely crash Chrome, Edge, Brave, Opera, and other Chromium browsers within 15 to 60 seconds through a simple code injection. The attack exploits […]
The post Critical Blink Vulnerability Lets Attackers Crash Chromium Browsers in Seconds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.