Aggregator
CVE-2025-25110 | Metagauss Event Kikfyre Plugin up to 2.1.8 on WordPress authorization
CVE-2009-0457 | Magtrb AJA Portal 1.2 case.php module_name path traversal (EDB-7939 / BID-33565)
DeepSeek应用未加密传输敏感用户和设备数据,引发安全担忧
Microsoft исправила по-настоящему серьёзную проблему Windows 11
CVE-2012-1507 | OrangeHRM up to 2.6.12.1 uri cross site scripting (EDB-37143 / XFDB-75473)
新产品
新产品
Attackers compromise IIS servers by leveraging exposed ASP.NET machine keys
A ViewState code injection attack spotted by Microsoft threat researchers in December 2024 could be easily replicated by other attackers, the company warned. “In the course of investigating, remediating, and building protections against this activity, we observed an insecure practice whereby developers have incorporated various publicly disclosed ASP.NET machine keys from publicly accessible resources, such as code documentation and repositories, which threat actors have used to perform malicious actions on target servers.” The attack ASP.NET … More →
The post Attackers compromise IIS servers by leveraging exposed ASP.NET machine keys appeared first on Help Net Security.
Шифратор речи «Делайла»: всплыли документы о секретном изобретении Тьюринга
DMARC на подъёме: Google и Yahoo задали новые стандарты защиты для электронной почты
RansomHub
Trimble Releases Security Updates to Address a Vulnerability in Cityworks Software
CISA is collaborating with private industry partners to respond to reports of exploitation of a vulnerability (CVE-2025-0994) discovered by Trimble impacting its Cityworks Server AMS (Asset Management System). Trimble has released security updates and an advisory addressing a recently discovered deserialization vulnerability enabling an external actor to potentially conduct remote code execution (RCE) against a customer’s Microsoft Internet Information Services (IIS) web server.
CISA has added CVE-2025-0994 to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
CISA strongly encourages users and administrators to search for indicators of compromise (IOCs) and apply the necessary updates and workarounds.
Review the following article for more information:
The Symantec Threat Hunter team, part of Broadcom, contributed to this guidance.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2025-0994 Trimble Cityworks Deserialization Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
0-day в Cityworks: хакеры атакуют инфраструктуру городов
Microsoft has finally fixed Date & Time bug in Windows 11
从零构建高仿真网络钓鱼测试
7-Zip 0-Day Flaw Added to CISA’s List of Actively Exploited Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical 0-day vulnerability affecting the popular file compression utility, 7-Zip, to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability, identified as CVE-2025-0411, highlights a severe flaw that allows attackers to bypass the Mark-of-the-Web (MotW) security feature and execute arbitrary code on targeted systems. Details […]
The post 7-Zip 0-Day Flaw Added to CISA’s List of Actively Exploited Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.