Aggregator
CVE-2019-1761 | Cisco IOS/IOS XE Hot Standby Router Protocol Subystem initialization (cisco-sa-20190327-ios-infoleak / ID 316406)
CVE-2021-1620 | Cisco IOS/IOS XE IKEv2 denial of service (cisco-sa-ikev2-ebFrwMPr)
CVE-2025-10252 | SEAT Queue Ticket Kiosk up to 20250827 Java RMI Registry deserialization
CVE-2025-10253 | openDCIM 23.04 SVG File /scripts/uploadifive.php Filedata cross site scripting
CVE-2025-8743 | Scada-LTS up to 2.7.8.1 Virtual Data Source Property /data_source_edit.shtm Name cross site scripting (EUVD-2025-24024)
CVE-2025-8511 | Portabilis i-Diario 1.5.0 Observações /diario-de-observacoes/ Descrição cross site scripting (EUVD-2025-23479)
Privileged AWS Permissions You Should Restrict Immediately (Top 25 + Bonus)
Drumroll, please… 🥁 After five weeks of countdowns, breakdowns, and some very lively conversations, we’ve finally reached the end of the Top 25 Most Risky AWS Privileged Permissions, plus a special bonus round for AWS Organizations. These permissions aren’t just “potentially risky.” They’ve been abused in real-world incidents to steal data, bypass controls, and escalate […]
The post Privileged AWS Permissions You Should Restrict Immediately (Top 25 + Bonus) appeared first on Security Boulevard.
Akira ransomware affiliates continue breaching organizations via SonicWall firewalls
Over a year after SonicWall patched CVE-2024-40766, a critical flaw in its next-gen firewalls, ransomware attackers are still gaining a foothold in organizations by exploiting it. Like last September and earlier this year, the attackers are affiliates of the Akira ransomware-as-a-service outfit. The July 2025 surge in attacks was, according to SonicWall, facilitated by the fact that organizations has migrated from Gen 6 to Gen 7 firewalls but did not reset local user passwords (as … More →
The post Akira ransomware affiliates continue breaching organizations via SonicWall firewalls appeared first on Help Net Security.
Senator Wyden Urges FTC to Probe Microsoft for Ransomware-Linked Cybersecurity Negligence
Realm.Security Joins Google Cloud Partner Advantage Program to Deliver Cost-Effective Security Data Management at Scale
Realm.Security joins the Google Cloud Partner Advantage program to deliver AI-powered security data pipelines that cut SIEM costs, streamline log management, and improve SOC efficiency for Google Cloud customers.
The post Realm.Security Joins Google Cloud Partner Advantage Program to Deliver Cost-Effective Security Data Management at Scale appeared first on Realm.Security.
The post Realm.Security Joins Google Cloud Partner Advantage Program to Deliver Cost-Effective Security Data Management at Scale appeared first on Security Boulevard.
CVE-2025-23167 | Node.js up to 20.19.1 HTTP Parser request smuggling (Nessus ID 236766 / WID-SEC-2025-1055)
CVE-2025-22150 | nodejs undici up to 5.28.4/6.21.0/7.2.2 Multipart Request Math.random random values (Nessus ID 214633 / WID-SEC-2025-0156)
CVE-2025-23087 | Node.js up to 17.9.1 unmaintained third party components (WID-SEC-2025-0156)
CVE-2025-23084 | Node.js on Windows Drive Name path traversal (Nessus ID 214404 / WID-SEC-2025-0156)
CVE-2025-23085 | Node.js Socket Close memory leak (Nessus ID 214404 / WID-SEC-2025-0156)
CVE-2025-23165 | Node.js up to 20.19.1/22.15.0 UTF-16 Path uv_fs_s.file ReadFileUtf8 denial of service (Nessus ID 236766 / WID-SEC-2025-1055)
Перехват звонков, активация микрофона, копирование переписки. Оружие ФБР теперь продают за $199 любому желающему
Kenyan Filmmakers Installed With FlexiSPY Spyware That Monitors Messages and Social Media
Four Kenyan filmmakers became victims of sophisticated surveillance when FlexiSPY spyware was covertly installed on their devices while in police custody, according to forensic analysis conducted by the University of Toronto’s Citizen Lab. The incident occurred on or around May 21, 2025, after authorities seized the devices during arrests connected to allegations surrounding the BBC […]
The post Kenyan Filmmakers Installed With FlexiSPY Spyware That Monitors Messages and Social Media appeared first on Cyber Security News.