Aggregator
SecWiki News 2025-05-14 Review
11 months 2 weeks ago
Getting started with Conditional Access: Comparing Entra ID Conditional Access with Okta
11 months 2 weeks ago
Everything you need to know about the differences between conditional access policies in Microsoft Entra ID and Okta.
Sam Straka
CVE-2005-2340 | Apple QuickTime 7.0/7.0.1/7.0.2/7.0.3 GIF Image memory corruption (VU#629845 / Nessus ID 20395)
11 months 2 weeks ago
A vulnerability was found in Apple QuickTime 7.0/7.0.1/7.0.2/7.0.3. It has been classified as critical. Affected is an unknown function of the component GIF Image Handler. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2005-2340. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-6481 | Sun Ray Server Software 3.0 (XFDB-39132 / SBV-25800)
11 months 2 weeks ago
A vulnerability was found in Sun Ray Server Software 3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to an unknown weakness.
This vulnerability is known as CVE-2007-6481. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2009-2673 | Sun JRE/JDK 1.5.0/1.6.0 access control (Nessus ID 43774 / ID 185074)
11 months 2 weeks ago
A vulnerability classified as critical was found in Sun JRE and JDK 1.5.0/1.6.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2009-2673. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-5905 | Adobe ColdFusion 7.0/8.0 credentials management (XFDB-38446 / SBV-29676)
11 months 2 weeks ago
A vulnerability was found in Adobe ColdFusion 7.0/8.0. It has been classified as critical. This affects an unknown part. The manipulation leads to credentials management.
This vulnerability is uniquely identified as CVE-2007-5905. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
As US CVE Database Fumbles, EU ‘Replacement’ Goes Live
11 months 2 weeks ago
Diesen Kuß der ganzen Welt! European Union Vulnerability Database (EUVD) launches this week. And not a moment too soon.
The post As US CVE Database Fumbles, EU ‘Replacement’ Goes Live appeared first on Security Boulevard.
Richi Jennings
Android 16扩展了“高级保护”,具有设备级安全性
11 months 2 weeks ago
安全客
British retailer M&S reportedly set to claim £100 million from insurers after cyberattack
11 months 2 weeks ago
A cyberattack first detected over Easter weekend has reportedly already cost Marks & Spencer more than £60 million.
Adobe security advisory (AV25–271)
11 months 2 weeks ago
Canadian Centre for Cyber Security
CVE-2025-2011 | Depicter Slider & Popup Builder Plugin up to 3.6.1 on WordPress sql injection (EDB-52285)
11 months 2 weeks ago
A vulnerability classified as critical was found in Depicter Slider & Popup Builder Plugin up to 3.6.1 on WordPress. This vulnerability affects unknown code. The manipulation of the argument s leads to sql injection.
This vulnerability was named CVE-2025-2011. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Alleged Sale of Root Access to an Unidentified Mexican Company
11 months 2 weeks ago
Alleged Sale of Root Access to an Unidentified Mexican Company
Dark Web Informer - Cyber Threat Intelligence
微软2025年5月星期二补丁修复了5个被利用的零日、72个缺陷
11 months 2 weeks ago
安全客
Horabot恶意软件通过复杂的网络钓鱼攻击拉丁美洲
11 months 2 weeks ago
安全客
Critical Adobe Illustrator Vulnerability Let Attackers Execute Malicious Code
11 months 2 weeks ago
Adobe has released a critical security update for its popular design software Illustrator, addressing a severe vulnerability that could allow attackers to execute arbitrary code on targeted systems. The security bulletin details a heap-based buffer overflow vulnerability that affects multiple versions of the software on both Windows and macOS platforms. The security flaw, identified as […]
The post Critical Adobe Illustrator Vulnerability Let Attackers Execute Malicious Code appeared first on Cyber Security News.
Kaaviya
ITSM的Ivanti Neurons受到CVSS9.8认证绕过缺陷,允许完全管理员访问
11 months 2 weeks ago
安全客
GovDelivery在TXTAG收费骗局中被利用:印第安纳州政府收件箱帐户被黑客攻击
11 months 2 weeks ago
安全客
Xinbi Telegram Market Tied to $8.4B in Crypto Crime, Romance Scams, North Korea Laundering
11 months 2 weeks ago
A Chinese-language, Telegram-based marketplace called Xinbi Guarantee has facilitated no less than $8.4 billion in transactions since 2022, making it the second major black market to be exposed after HuiOne Guarantee.
According to a report published by blockchain analytics firm Elliptic, merchants on the marketplace have been found to peddle technology, personal data, and money laundering
The Hacker News
Microsoft primes 71 fixes for May Patch Tuesday
11 months 2 weeks ago
Five issues actively exploited in the wild, but the real excitement may have been handled in advance
Angela Gunn