Aggregator
CVE-2025-46784 | Entr'ouvert Lasso 2.5.1 SAML Response lasso_node_init_from_message_with_format memory leak (TALOS-2025-2195 / Nessus ID 274083)
CVE-2025-46705 | Entr'ouvert Lasso 2.5.1/2.8.2 SAML Response g_assert_not_reached assertion (TALOS-2025-2196 / Nessus ID 274084)
CVE-2025-46404 | Entr'ouvert Lasso 2.5.1 SAML Response lasso_provider_verify_saml_signature null pointer dereference (TALOS-2025-2194 / Nessus ID 274080)
CVE-2025-60753 | libarchive bsdtar up to 3.8.0 tar/subst.c apply_substitution resource consumption (Issue 2725 / EUVD-2025-37900)
CVE-2025-47151 | Entr'ouvert Lasso 2.5.1/2.8.2 SAML Response lasso_node_impl_init_from_xml type confusion (TALOS-2025-2193 / Nessus ID 274086)
CVE-2025-64459 | Django up to 4.2.25/5.1.13/5.2.7 QuerySet.filter/QuerySet.exclude/QuerySet.get sql injection (EUVD-2025-37763 / Nessus ID 274081)
CVE-2025-63601 | Snipe-IT up to 8.3.2 Backup File privilege escalation (EUVD-2025-37899)
Rethinking Cyber Resilience in the Age of AI
AI has fundamentally changed how we think about both innovation and risk. It’s driving new breakthroughs in medicine, design, and productivity, but it’s also giving attackers a sharper edge. Ransomware isn’t just about encrypting data anymore. It’s about double extortion, data theft, and the erosion of trust that organizations depend on to operate. As threat..
The post Rethinking Cyber Resilience in the Age of AI appeared first on Security Boulevard.
CVE-2025-64458 | Django up to 4.2.25/5.1.13/5.2.7 on Windows algorithmic complexity (EUVD-2025-37765 / Nessus ID 274082)
Китай обгоняет Boston Dynamics. Xpeng показала гуманоидного робота IRON с «кошачьей» походкой
Best Application Security Testing Services to Know
Discover the best Application Security Testing (AST) services in 2025.
The post Best Application Security Testing Services to Know appeared first on Security Boulevard.
Квартира с подвохом. Как не попасться на удочку фейковых арендодателей в интернете
Operation Chargeback Uncovers €300m Fraud Scheme in 193 Countries
HackedGPT – 7 New Vulnerabilities in GPT-4o and GPT-5 Enables 0-Click Attacks
Seven critical vulnerabilities in OpenAI’s ChatGPT, affecting both GPT-4o and the newly released GPT-5 models, that could allow attackers to steal private user data through stealthy, zero-click exploits. These flaws exploit indirect prompt injections, enabling hackers to manipulate the AI into exfiltrating sensitive information from user memories and chat histories without any user interaction beyond […]
The post HackedGPT – 7 New Vulnerabilities in GPT-4o and GPT-5 Enables 0-Click Attacks appeared first on Cyber Security News.