Aggregator
«Wow!» — и больше тишина. 47 лет загадки самого мощного радиосигнала из космоса
CVE-2019-0192 | Oracle Primavera Unifier up to 18.8 Apache HTTP Server deserialization (Nessus ID 257994 / ID 13434)
CVE-2019-0192 | Oracle Big Data Graph up to 2.x Spatial/Graph deserialization (Nessus ID 257994 / ID 13434)
CVE-2022-0717 | mruby up to 3.1 out-of-bounds (Nessus ID 257993)
CVE-2019-0192 | Apache Solr up to 5.0.5/6.6.5 Config API HTTP POST Request deserialization (RHSA-2019:2413 / Nessus ID 257994)
CVE-2021-33361 | GPAC 1.0.1 MP4Box afra_box_read memory leak (Nessus ID 257995)
Citrix forgot to tell you CVE-2025–6543 has been used as a zero day since May 2025
Salesloft Drift compromised en masse, impacting all third-party integrations
Researchers said Google Workspace customers were hit, and noted other platforms are impacted as well. Fresh evidence proves impact was not limited to Salesforce, as Salesloft previously claimed.
The post Salesloft Drift compromised en masse, impacting all third-party integrations appeared first on CyberScoop.
Hackers Steal 4M+ TransUnion Customers' Data
CVE-2025-58049 | XWiki xwiki-platform up to 16.4.7/16.10.6/17.3.x improper removal of sensitive information before storage or transfer (GHSA-9m7c-m33f-3429 / WID-SEC-2025-1919)
CVE-2025-57759 | Contao CMS up to 5.3.37/5.6.0 privileges management (GHSA-qqfq-7cpp-hcqj / WID-SEC-2025-1920)
CVE-2025-57757 | Contao CMS up to 5.3.37/5.6.0 information disclosure (GHSA-w53m-gxvg-vx7p / WID-SEC-2025-1920)
CVE-2025-57758 | Contao CMS up to 5.3.37/5.6.0 Corresponding access control (GHSA-7m47-r75r-cx8v / WID-SEC-2025-1920)
CVE-2025-57756 | Contao CMS up to 4.13.55/5.3.37/5.6.0 information disclosure (GHSA-2xmj-8wmq-7475 / WID-SEC-2025-1920)
CISA Adds Citrix and Git Flaws to KEV Catalogue Amid Active Exploitation
Safepay
You must login to view this content
Windsurf MCP Integration: Missing Security Controls Put Users at Risk
Part of my default test cases for coding agents is to check how MCP integration looks like, especially if the agent can be configured to allow setting fine-grained controls for tools.
Sometimes there are basic security controls missing.
Especially when running an agent on your local computer. Stakes are much higher. And it seems important to empower users to be able to configure which actions an AI should be able to take automatically, and which ones should be suggestions that the user reviews before executing.
Pear
You must login to view this content