Aggregator
每周高级威胁情报解读(2025.06.27~07.03)
每周高级威胁情报解读(2025.06.27~07.03)
CVE-2025-6740 | Contact Form 7 Database Addon Plugin up to 1.3.1 on WordPress tmpD cross site scripting
CVE-2025-6663 | GStreamer H266 Codec Parser stack-based overflow
CVE-2025-49005 | vercel next.js up to 15.3.2 React Server Component request smuggling (ID 79346 / EUVD-2025-19911)
CVE-2025-53367 | DjvuNet DjVuLibre up to 3.5.28 MMRDecoder::scanruns out-of-bounds write (GHSL-2025-055 / EUVD-2025-19908)
CVE-2025-49826 | vercel next.js up to 15.1.7 request smuggling (GHSA-67rr-84xm-4c7r / EUVD-2025-19910)
Africa’s cybersecurity crisis and the push to mobilizing communities to safeguard a digital future
While Africa hosts some of the fastest-growing digital economies globally, it also faces persistent challenges in cybersecurity preparedness. Many organizations and individuals remain unaware of the risks they face online. Phishing schemes and social engineering tactics continue to succeed at alarming rates, often due to limited awareness of basic digital hygiene practices. Compounding the threat is a severe shortage of trained professionals. Africa has a small share of certified professionals, fewer than 25,000 across a … More →
The post Africa’s cybersecurity crisis and the push to mobilizing communities to safeguard a digital future appeared first on Help Net Security.
CVE-2014-5521 | XRMS CRM 1.99.2 fingeruser.php Username sql injection (ID 128030 / EDB-34452)
CVE-2002-2312 | Opera Web Browser 6.0.1 event.shiftKey privileges management (EDB-21636 / BID-5290)
网安结款难:从上海观安不结款事件到整个环境的延伸以及对普通人的建议
100 лет считали: нет энергии — нет движения. Квантовый мир сказал "неправильно"
Exposed and unaware? Smart buildings need smarter risk controls
75% of organizations have building management systems (BMS) affected by known exploited vulnerabilities (KEVs), according to Claroty.
The post Exposed and unaware? Smart buildings need smarter risk controls appeared first on Help Net Security.
CVE-2009-4497 | Malcom Box LXR Cross Referencer 0.9.5 cross site scripting (EDB-33469 / Nessus ID 46244)
CVE-2013-5019 | Vector Ultra Mini HTTPD 1.21 memory corruption (EDB-26739 / XFDB-85599)
CVE-2015-2094 | Webgateinc Winrds WebGate SaveSiteImage memory corruption (ID 131069 / EDB-36517)
New Hpingbot Abusing Pastebin for Payload Delivery and Hping3 Tool to Launch DDoS Attacks
A sophisticated new botnet family has emerged in the cybersecurity landscape, demonstrating unprecedented innovation in malware design and attack methodologies. The hpingbot malware, first detected in June 2025, represents a significant departure from traditional botnet architectures by leveraging legitimate online services and network testing tools to orchestrate distributed denial-of-service attacks while maintaining operational stealth. Unlike […]
The post New Hpingbot Abusing Pastebin for Payload Delivery and Hping3 Tool to Launch DDoS Attacks appeared first on Cyber Security News.
Internet outages are costing companies millions every month
To ensure resilience across the internet stack, organizations need to protect and manage four key areas: reachability, availability, reliability, and performance, according to Catchpoint. The negative economic impact of incidents 51% report monthly losses of over $1 million due to internet outages or degradations, up from 43% in 2024. And 1 in 8 now lose over $10 million each month, a noticeable rise since last year. One way to justify the cost of resilience is … More →
The post Internet outages are costing companies millions every month appeared first on Help Net Security.