Aggregator
CVE-2026-25201 | Samsung Electronics MagicINFO 9 Server 21.1050/21.1052/21.1080.0 unrestricted upload
CVE-2026-24788 | RaspAP raspap-webgui up to 3.3.5 os command injection
CVE-2025-15030 | User Profile Builder Plugin up to 3.15.1 on WordPress Password Reset privileges management
CVE-2026-1531 | Red Hat Satellite 6 foreman_kubevirt certificate validation
CVE-2026-1530 | Red Hat Satellite 6 fog-kubevirt certificate validation
767 млн украденных записей, 250 взломов и 27 новых APT-групп. Главное из отчета F6 о кибервойне против России в 2025 году
StrongestLayer: Top ‘Trusted’ Platforms are Key Attack Surfaces
Explore StrongestLayer's threat intelligence report highlighting the rise of email security threats exploiting trusted platforms like DocuSign and Google Calendar. Learn how organizations can adapt to defend against these evolving cyber risks.
The post StrongestLayer: Top ‘Trusted’ Platforms are Key Attack Surfaces appeared first on Security Boulevard.
CVE-2025-15447 | Seeyon Zhiyuan OA Web Application System up to 20251223 assetsService.j%73p unitCode sql injection (EUVD-2026-0924 / CNNVD-202601-804)
CVE-2025-15446 | Seeyon Zhiyuan OA Web Application System up to 20251223 fixedAssetsList.j%73p unitCode sql injection (EUVD-2026-0923 / CNNVD-202601-796)
CVE-2025-15427 | Seeyon Zhiyuan OA Web Application System up to 20251222 carUseDetailList.j%73p CAR_BRAND_NO sql injection
最大动漫盗版网站被关,运营者被捕
Хаос отменяется. Мы научились направлять тепло в одну сторону, чтобы навсегда избавить смартфоны от перегрева
CVE-2023-42336 | Netis WF2409Ev4 1.0.1.705 /etc/shadow.sample Password hard-coded credentials (EUVD-2023-46789)
CVE-2023-42335 | Fl3xx Dispatch/Crew 2.10.37 unrestricted upload (EUVD-2023-46788)
CVE-2023-42331 | EliteCMS 1.01 manage_uploads.php unrestricted upload (EUVD-2023-46784)
CVE-2023-42334 | Fl3xx Dispatch/Crew 2.10.37 User resource injection (EUVD-2023-46787)
CVE-2023-42328 | PeppermintLabs Peppermint up to 0.2.4 Session Cookie information disclosure (EUVD-2023-46781)
CVE-2023-42323 | DouHaocms 3.3 adminAction.class.php cross-site request forgery (EUVD-2023-46776)
Open-source AI pentesting tools are getting uncomfortably good
AI has come a long way in the pentesting world. We are now seeing open-source tools that can genuinely mimic how a human tester works, not just fire off scans. I dug into three of them, BugTrace-AI, Shannon, and CAI, the Cybersecurity AI framework, and put them up against real-world targets in a lab environment. The results were better than I expected. Below is a breakdown of what each tool did well, where they fell … More →
The post Open-source AI pentesting tools are getting uncomfortably good appeared first on Help Net Security.