Aggregator
CVE-2025-9715 | O2OA up to 10.0-410 Personal Profile Page script name/alias/description cross site scripting (Issue 181)
Submit #637247: o2oa ≤ 10.0-410-g3d5e0d2 XSS [Accepted]
Submit #637246: o2oa ≤ 10.0-410-g3d5e0d2 XSS [Accepted]
Submit #637245: o2oa ≤ 10.0-410-g3d5e0d2 XSS [Accepted]
Submit #637244: o2oa ≤ 10.0-410-g3d5e0d2 XSS [Accepted]
Submit #637243: o2oa ≤ 10.0-410-g3d5e0d2 XSS [Accepted]
iPhone без RuStore теперь «товар с дефектом». Как новый закон превратил все смартфоны Apple в России в бракованную технику
CVE-2025-38677 | Linux Kernel up to 6.16.3 f2fs_get_dnode_of_data out-of-bounds
【安全圈】FreePBX零日漏洞遭利用,官方通告:请立即锁定管理员访问
【安全圈】新型AI攻击借助图像植入恶意提示词窃取用户数据
【安全圈】当心!你的身份证照片可能被AI生成了动态视频
Any way to get invited to expl0it[dot]in site
New ‘Sindoor Dropper’ Malware Targets Linux Systems with Weaponized .desktop Files
A new malware campaign, dubbed “Sindoor Dropper,” is targeting Linux systems using sophisticated spear-phishing techniques and a multi-stage infection chain. The campaign leverages lures themed around the recent India-Pakistan conflict, known as Operation Sindoor, to entice victims into executing malicious files. This activity’s standout feature is its reliance on weaponized .desktop files, a method previously […]
The post New ‘Sindoor Dropper’ Malware Targets Linux Systems with Weaponized .desktop Files appeared first on Cyber Security News.
从「卖设备」到「建关系」,AI 硬件的破局点到底在哪里?
从「卖设备」到「建关系」,AI 硬件的破局点到底在哪里?
Top 10 Best API Penetration Testing Companies In 2025
API penetration testing has evolved dramatically in 2025. While traditional, human-led penetration testing remains critical, the scale and complexity of modern APIs have necessitated a new approach. The companies on this list are not just offering one-time testing services; they provide automated, continuous, and intelligent API security platforms that perform dynamic testing, behavioral analysis, and […]
The post Top 10 Best API Penetration Testing Companies In 2025 appeared first on Cyber Security News.