Aggregator
成果分享 | [USENIX Security 2025] XSSky:融合动静态分析,精准狙击XSS漏洞的新一代“利剑”
CVE-2025-5497 | slackero phpwcms up to 1.9.45/1.10.8 Feedimport processing.inc.php cnt_text deserialization (EUVD-2025-16727)
Hackers Exploiting Apache ActiveMQ Vulnerability to Gain Access to Cloud Linux Systems
A sophisticated campaign uncovered where adversaries are exploiting CVE-2023-46604, a critical remote code execution vulnerability in Apache ActiveMQ, to compromise cloud-based Linux systems. In this case, attackers are patching the very vulnerability they exploited to maintain exclusive access and evade detection, demonstrating advanced operational security practices typically reserved for nation-state actors. Key Takeaways1. Attackers exploit […]
The post Hackers Exploiting Apache ActiveMQ Vulnerability to Gain Access to Cloud Linux Systems appeared first on Cyber Security News.
CVE-2025-9228 | Mobile Industrial Robots MiR Robots/MiR Fleet up to 2.x Note authorization
CVE-2025-9225 | Mobile Industrial Robots MiR Robots/MiR Fleet up to 2.x Web Interface cross site scripting
CVE-2025-5260 | Pik Online Yazılım Çözümleri up to 3.1.4 server-side request forgery
Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware
Cybersecurity researchers have uncovered a sophisticated campaign by the Paper Werewolf threat actor group, also known as GOFFEE, targeting Russian organizations through the exploitation of critical vulnerabilities in WinRAR archiving software. The campaign, active since July 2025, demonstrates the group’s advanced capabilities in leveraging both known and previously undiscovered security flaws to establish persistent access […]
The post Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware appeared first on Cyber Security News.
CVE-2025-37925 | Linux Kernel up to 6.14.1 jfs fs/inode.c clear_inode information disclosure (EUVD-2025-11828 / Nessus ID 240657)
CVE-2025-38049 | Linux Kernel up to 6.12.22/6.13.10/6.14.1 resctrl dom_data_init null pointer dereference (Nessus ID 240657 / WID-SEC-2025-0861)
CVE-2025-9167 | SolidInvoice up to 2.4.0 Recurring Invoice /invoice/recurring client name cross site scripting
CVE-2025-9168 | SolidInvoice up to 2.4.0 Invoice Creation /invoice Client Name cross site scripting
CVE-2025-8364 | Mozilla Firefox up to 140 on Android blob URL ui layer (EUVD-2025-25231)
CVE-2025-8041 | Mozilla Firefox up to 140 on Android Address Bar clickjacking (EUVD-2025-25233)
CVE-2025-8042 | Mozilla Firefox up to 140 on Android iFrame access control (EUVD-2025-25232)
CVE-2025-37893 | Linux Kernel up to 6.1.133/6.6.86/6.12.22/6.13.10/6.14.1 LoongArch build_prologue off-by-one (WID-SEC-2025-0861)
CVE-2025-37838 | Linux Kernel up to 4.19.309 HSI ssi_protocol_probe use after free (Nessus ID 234884 / WID-SEC-2025-0861)
Google fixed Chrome flaw found by Big Sleep AI
CodeRabbit’s Production Servers RCE Vulnerability Enables Write Access on 1M Repositories
A critical remote code execution (RCE) vulnerability in CodeRabbit’s production infrastructure that provided unauthorized access to over one million code repositories, including private ones. The vulnerability, discovered in December 2024 and responsibly disclosed in January 2025, exploited the platform’s static analysis tool integration to leak sensitive API credentials and gain write access to GitHub repositories […]
The post CodeRabbit’s Production Servers RCE Vulnerability Enables Write Access on 1M Repositories appeared first on Cyber Security News.
New Salty 2FA PhaaS Platform Targets Microsoft 365 Users to Steal Login Credentials
The majority of events globally are caused by phishing, which continues to be the most common vector for cyberattacks in the constantly changing world of cyber threats. The proliferation of affordable Phishing-as-a-Service (PhaaS) platforms such as Tycoon2FA, EvilProxy, and Sneaky2FA has exacerbated this issue, enabling even novice attackers to deploy sophisticated campaigns. These services are […]
The post New Salty 2FA PhaaS Platform Targets Microsoft 365 Users to Steal Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.