Aggregator
CVE-2025-22265 | mgplugin EMI Calculator Plugin up to 1.1 on WordPress authorization
CVE-2024-13157 | sonaar MP3 Audio Player Plugin up to 5.9.3 on WordPress cross site scripting
CRLF injection via TryAddWithoutValidation in .NET
The push for 47-day certificates: a win for digital security and trust
By 2028, SSL/TLS certificate lifecycles may be cut down to just 47 days - a dramatic shift from the current 398-day maximum. Apple’s recent ballot submission to the CA/Browser Forum proposes this change, and it’s gaining traction among industry leaders, including Sectigo. While some enterprises may see this as an operational burden, the reality is clear: shorter certificate lifespans are a necessary and positive step for digital security and trust.
The post The push for 47-day certificates: a win for digital security and trust appeared first on Security Boulevard.
CVE-2024-13566 | samsk WP DataTable Plugin up to 0.2.6 on WordPress id cross site scripting
AI驱动新一轮社交工程攻击:该如何应对?
CVE-2024-53007 | Bentley ProjectWise Integration Server prior 10.00.03.288 incorrect privileged apis
go-proxy/README_CHT.md at v. · yusing/go-proxy
The Evolution of iOS Passcode Security
CVE-2024-2961 | GNU C Library up to 2.39 iconv out-of-bounds write (DLA 3807-1 / Nessus ID 214840)
CVE-2023-30536 | slim psr7 up to 1.6.0 Header interpretation conflict (GHSA-q2qj-628g-vhfw / Nessus ID 214840)
巴塞尔税务机关因域名错误不得不购买巴哈马域名
CVE-2001-0324 | Microsoft Windows 98/2000 Java Applet UDP Socket denial of service (EDB-20613 / BID-2340)
CVE-2007-1355 | Apache Tomcat up to 4.0.0 hello.jsp test cross site scripting (EDB-30052 / Nessus ID 25289)
Microsoft to Boost M365 Bounty Program With New Products & Rewards Up to $27,000
A significant extension of Microsoft’s Microsoft 365 (M365) Bounty Program has been announced. The program now includes new Viva products under its scope for identifying vulnerabilities, with rewards reaching up to $27,000 for critical submissions. This update underscores Microsoft’s commitment to enhancing the security of its software ecosystem and encouraging global collaboration in vulnerability detection. […]
The post Microsoft to Boost M365 Bounty Program With New Products & Rewards Up to $27,000 appeared first on Cyber Security News.
D-Link Routers Vulnerability Let Attackers Gain Full Router Control Remotely
A critical unauthenticated Remote Code Execution (RCE) vulnerability has been affecting DSL-3788 routers, allowing attackers to acquire complete control over the router remotely. The flaw has been detected in firmware versions v1.01R1B036_EU_EN and below. This vulnerability was reported by Max Bellia of SECURE NETWORK BVTECH. The vulnerability resides in the webproc CGI component of the […]
The post D-Link Routers Vulnerability Let Attackers Gain Full Router Control Remotely appeared first on Cyber Security News.
CVE-2015-4181 | phpMyBackupPro 2.1/2.2/2.3/2.4/2.5 Incomplete Fix get_file.php view path traversal (EDB-10169)
Authorities Take Down Cracked & Nulled Hacking Forums Used by 10 Million Users
In a law enforcement operation dubbed “Operation Talent,” an international coalition of law enforcement agencies led by Germany’s Bundeskriminalamt (BKA) and Europol has dismantled two of the world’s largest cybercrime forums: Cracked.io and Nulled.to. These platforms, which collectively hosted over 10 million users, served as hubs for illicit activities, including selling stolen data, malware, hacking […]
The post Authorities Take Down Cracked & Nulled Hacking Forums Used by 10 Million Users appeared first on Cyber Security News.