Aggregator
CVE-2025-2817 | Mozilla Firefox up to 137.x Update access control (Nessus ID 234931)
CVE-2025-2817 | Mozilla Thunderbird up to 137.x Update access control (Nessus ID 234931)
亚马逊将在商品价格中显示关税,白宫谴责
Mozilla security advisory (AV25-240)
CISA Adds Broadcom Brocade Fabric OS Vulnerability to Known Exploited Vulnerabilities Catalog
CISA officially added a significant security flaw affecting Broadcom’s Brocade Fabric OS to its authoritative Known Exploited Vulnerabilities (KEV) Catalog, underscoring the urgent need for remediation across enterprise and government environments. The vulnerability, tracked as CVE-2025-1976, is classified as a code injection vulnerability and carries a high CVSS base score of 8.6 due to its […]
The post CISA Adds Broadcom Brocade Fabric OS Vulnerability to Known Exploited Vulnerabilities Catalog appeared first on Cyber Security News.
Apache Tomcat security advisory (AV25-239)
CISA tags Broadcom Fabric OS, CommVault flaws as exploited in attacks
AirPlay Zero-Click RCE Vulnerability Enables Remote Device Takeover via Wi-Fi
A critical vulnerability in Apple’s AirPlay protocol, dubbed AirBorne, has exposed over 2.35 billion active Apple devices and tens of millions of third-party gadgets to remote code execution (RCE) attacks requiring no user interaction. Researchers at Oligo Security discovered that the flaw allows attackers on the same Wi-Fi network to hijack devices ranging from Macs […]
The post AirPlay Zero-Click RCE Vulnerability Enables Remote Device Takeover via Wi-Fi appeared first on Cyber Security News.
经济学家发现生成式 AI 没有取代工作或影响薪水
CVE-2020-29385 | GNOME gdk-pixbuf up to 2.42.1 LZW Compression lzw.c write_indexes infinite loop
CVE-2025-22925 | OS4ED openSIS up to 9.1 AttendanceCodes.php table sql injection
CVE-2025-22924 | OS4ED openSIS up to 9.1 Student.php stu_id sql injection
CVE-2025-29062 | B-Link BL-AC2100 up to 1.0.4 set_LimitClient_cfg time1/time2 command injection
CVE-2025-29063 | B-Link BL-AC2100 up to 1.0.4 /goform/set_hidessid_cfg enable command injection
CVE-2025-31477 | tauri-apps plugins-workspace up to 2.2.0 on Linux Open Endpoint input validation (GHSA-c9pr-q8gx-3mgp)
CVE-2025-3130 | Drupal Obfuscate up to 2.0.0 cross site scripting (sa-contrib-2025-029)
CVE-2025-31721 | Jenkins permission (Nessus ID 233779)
CVE-2025-31722 | Jenkins Templating Engine Plugin up to 2.5.3 sandbox (Nessus ID 233778)
New Framework Targets Rising Financial Crime Threats
To help financial institutions counter crime, the FS-ISAC earlier this month introduced a major initiative: the Cyberfraud Prevention Framework. This new initiative is designed to unify cybersecurity and fraud prevention teams to more effectively protect customers and secure the enterprise.