Aggregator
【即刻说】第8期 | 专访蛮犀安全,聚焦APP 安全的那些事儿,诈骗风险、隐私泄露...
共鉴AI新价值新图景,默安科技邀您共襄全球盛会
New ModSecurity WAF Vulnerability Let Attackers Crash the System
A significant denial of service vulnerability has been discovered in ModSecurity, one of the most widely deployed open-source web application firewall (WAF) engines used to protect Apache, IIS, and Nginx web servers. The vulnerability, designated as CVE-2025-48866, affects all ModSecurity versions prior to 2.9.10 and allows attackers to crash systems through exploitation of the sanitiseArg […]
The post New ModSecurity WAF Vulnerability Let Attackers Crash the System appeared first on Cyber Security News.
CVE-2025-5523 | enilu web-flash 1.0 File Upload upload fileService.upload cross site scripting (ICAXTM / EUVD-2025-16781)
Submit #585711: 上海卓卓网络科技有限公司 DedeCMS V5.7.117 Command Injection [Duplicate]
CVE-2025-5522 | jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad User Creation /sa/addUser improper authorization (ICAOOU / EUVD-2025-16775)
Malicious NPM Packages Exploit Ethereum Wallets with Obfuscated JavaScript
A recent wave of malicious NPM packages has emerged as a significant threat to cryptocurrency users, specifically targeting Ethereum wallet holders. Cybersecurity researchers have uncovered a sophisticated campaign where attackers leverage the widely-used Node Package Manager (NPM) ecosystem to distribute harmful code disguised as legitimate libraries. This attack vector exploits the trust developers place in […]
The post Malicious NPM Packages Exploit Ethereum Wallets with Obfuscated JavaScript appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #585342: enilu web-flash 1.0 Arbitrary File Upload [Accepted]
仙女座和银河系未必会相撞
Submit #584986: Jack魏 蓝天幼儿园管理系统 1 Unauthorized access [Accepted]
Submit #584947: Tenda AC6 V15.03.05.19 Stack-based Buffer Overflow [Duplicate]
Не чип, а швейцарский сыр: MediaTek больше не может молчать о своих проблемах
Android Trojan Crocodilus Now Active in 8 Countries, Targeting Banks and Crypto Wallets
CVE-2025-5521 | WuKongOpenSource WukongCRM 9.0 updataPassword cross-site request forgery (EUVD-2025-16779)
New ModSecurity WAF Vulnerability Enables Attackers to Crash Systems
A high-severity denial-of-service (DoS) vulnerability (CVE-2025-48866) has been identified in ModSecurity’s Apache module (mod_security2), threatening web application firewall stability. Rated 7.5/10 on the CVSS scale, this flaw enables attackers to crash servers by exploiting argument sanitization logic, with patches now available in version 2.9.10. Sanitisation Logic Flaw The vulnerability stems from ModSecurity’s sanitiseArg action, designed […]
The post New ModSecurity WAF Vulnerability Enables Attackers to Crash Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.