Aggregator
Submit #505754: https://gitee.com/shishuo/CMS_old shishuocms 1.1 Cross-site Scripting [Accepted]
Submit #505741: https://gitee.com/shishuo/CMS_old shishuocms 1.1 Cross-Site Request Forgery [Accepted]
CVE-2024-51091 | seajs 2.2.3 cross site scripting
CVE-2025-27371 | OpenID Connect IETF OAuth 2.0 authorization
A Threat Actor Claims to be Selling Admin Access to a Magento 2-Based Online Store in the UK
Submit #505736: https://gitee.com/shishuo/CMS_old shishuocms 1.1 Unrestricted Upload of File with Dangerous Type [Accepted]
CVE-2024-53388 | mavo 0.3.2 HTML Element HTML injection
CVE-2024-53387 | umeditor 1.2.3 HTML Element HTML injection
CVE-2023-49031 | Advanced eMarketing Platform 6.8.3.0 OpenLogFile Endpoint filename path traversal
CVE-2025-27370 | OpenID Connect up to 1.0 errata set 2 private_key_jwt authorization
Submit #505525: ZIONCOM Electronics TOTOLINK T10 V4.1.8cu.5241_B20210927 Buffer Overflow [Duplicate]
CVE-2024-53384 | tsup 8.3.4 cjs_shims.js document.currentScript Privilege Escalation
CVE-2025-27498 | RustCrypto AEADs up to 0.4.2 aes-gcm signature verification (GHSA-r38m-44fw-h886)
CVE-2025-25303 | ttop32 MouseTooltipTranslator up to 0.1.127 URL Parameter viewer.html server-side request forgery (GHSL-2024-018)
Randall Munroe’s XKCD ‘Giants’
via the comic humor & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Giants’ appeared first on Security Boulevard.
Метаповерхность-хамелеон: одновременно связь и сенсор для сетей будущего
Threat Actors Exploiting AES Encryption for Stealthy Payload Protection
Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES) encryption by threat actors to shield malicious payloads from detection. This technique, combined with code virtualization and staged payload delivery, is being employed by malware families such as Agent Tesla, XWorm, and FormBook/XLoader to evade static analysis tools and sandbox environments. […]
The post Threat Actors Exploiting AES Encryption for Stealthy Payload Protection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge
Kaspersky’s latest report on mobile malware evolution in 2024 reveals a significant increase in cyber threats targeting mobile devices. The security firm’s products blocked a staggering 33.3 million attacks involving malware, adware, or unwanted mobile software throughout the year. Mobile Malware Landscape Evolves with New Distribution Schemes Adware continued to dominate the mobile threat landscape, […]
The post 33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.