Aggregator
CVE-2025-46803 | GNU screen 5.0.0 PTY access control
8 months 2 weeks ago
A vulnerability was found in GNU screen 5.0.0. It has been classified as critical. Affected is an unknown function of the component PTY. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2025-46803. An attack has to be approached locally. There is no exploit available.
vuldb.com
【AI挖情报】比尔和梅林达·盖茨基金会、全球疫苗免疫联盟、疫苗联盟、威康信托基金和流行病防范创新联盟是啥关系?
8 months 2 weeks ago
比尔和梅林达·盖茨基金会、全球疫苗免疫联盟、疫苗联盟、威康信托基金和流行病防范创新联盟是啥关系?
Chinese Hackers Exploit Cityworks 0-Day to Hit US Local Governments
8 months 2 weeks ago
Cisco Talos warns of active exploitation of a zero-day vulnerability (CVE-2025-0994) in Cityworks supposedly by Chinese hackers from…
Deeba Ahmed
Alleged Sale of 100,000 Credit Cards
8 months 2 weeks ago
Alleged Sale of 100,000 Credit Cards
Dark Web Informer - Cyber Threat Intelligence
CVE-2017-7049 | Apple tvOS up to 10.2.1 WebKit memory corruption (HT207924 / EDB-42363)
8 months 2 weeks ago
A vulnerability was found in Apple tvOS up to 10.2.1. It has been classified as critical. This affects an unknown part of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2017-7049. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-37992 | Linux Kernel up to 5.15.183/6.1.139/6.6.91/6.12.29/6.14.7 net_sched change null pointer dereference
8 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 5.15.183/6.1.139/6.6.91/6.12.29/6.14.7. It has been rated as critical. This issue affects the function Change of the component net_sched. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2025-37992. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #583012: https://codeastro.com https://codeastro.com/membership-management-system-in-php-with-source-code/#unlock 8.2.12 Information Disclosure / Hardcoded Credentials [Duplicate]
8 months 2 weeks ago
Submit #583012 / VDB-278773
honest_corrupt
Building a Secure LLM Gateway (and an MCP Server) with GitGuardian & AWS Lambda
8 months 2 weeks ago
How I wrapped large-language-model power in a safety blanket of secrets-detection, chunking, and serverless scale.
The post Building a Secure LLM Gateway (and an MCP Server) with GitGuardian & AWS Lambda appeared first on Security Boulevard.
Andy Rea
技术预警:蓝牙模块崩溃、WiFi 强制重启,智能设备协议漏洞修复迫在眉睫!
8 months 2 weeks ago
中科固源
Firefox убрал https://, но добавил кое-что поинтереснее
8 months 2 weeks ago
Браузер стал умнее, а меню — короче.
CVE-2025-39498 | Spotlight Plugin up to 1.7.1 on WordPress information disclosure
8 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Spotlight Plugin up to 1.7.1 on WordPress. This issue affects some unknown processing. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2025-39498. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2014-6235 | Kennziffer ke DomPDF up to 0.0.2 memory corruption (EDB-35443 / ID 11600)
8 months 2 weeks ago
A vulnerability was found in Kennziffer ke DomPDF up to 0.0.2 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2014-6235. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
[Control systems] CISA ICS security advisories (AV25–295)
8 months 2 weeks ago
Canadian Centre for Cyber Security
Laatste F-16’s voor Oekraïne uit Nederland vertrokken
8 months 2 weeks ago
De laatste Nederlandse F-16’s die bestemd zijn voor Oekraïne, hebben Nederland verlaten. De toestellen zijn vandaag van Vliegbasis Volkel naar België vertrokken, waar ze worden voorbereid voor de levering. In totaal heeft Nederland daarmee 24 jachtvliegtuigen aan Oekraïne gedoneerd.
Unlocking the Gates: REST API Authentication Methods for Modern Security
8 months 2 weeks ago
From Basic Auth’s simplicity to OAuth 2.0’s delegated muscle, this quick-read unpacks the strengths, gaps, and best-fit use cases of the four core REST API authentication methods—so you pick security that scales, not slows.
The post Unlocking the Gates: REST API Authentication Methods for Modern Security appeared first on Security Boulevard.
Deepak Gupta - Tech Entrepreneur, Cybersecurity Author
SRC实战案例分享
8 months 2 weeks ago
CVE-2004-1385 | phpGroupWare up to 0.9.16.003 Error Message preferences.php menuaction privileges management (EDB-24847 / Nessus ID 16399)
8 months 2 weeks ago
A vulnerability has been found in phpGroupWare and classified as critical. This vulnerability affects unknown code of the file preferences.php of the component Error Message Handler. The manipulation of the argument menuaction leads to improper privilege management.
This vulnerability was named CVE-2004-1385. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-41992
8 months 2 weeks ago
Currently trending CVE - Hype Score: 8 - The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against ...
Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto
8 months 2 weeks ago
As many as 60 malicious npm packages have been discovered in the package registry with malicious functionality to harvest hostnames, IP addresses, DNS servers, and user directories to a Discord-controlled endpoint.
The packages, published under three different accounts, come with an install‑time script that's triggered during npm install, Socket security researcher Kirill Boychenko said in a
The Hacker News