Aggregator
CVE-2025-52767 | lisensee NetInsight Analytics Implementation Plugin up to 1.0.3 on WordPress cross-site request forgery
CVE-2025-54054 | AA Web Servant 12 Step Meeting List Plugin up to 3.18.3 on WordPress cross site scripting
CVE-2025-53347 | Laborator Kalium Plugin up to 3.18.3 on WordPress cross-site request forgery
CVE-2025-52765 | lisensee NetInsight Analytics Implementation Plugin up to 1.0.3 on WordPress cross-site request forgery
CVE-2025-53582 | WordLift Plugin up to 3.54.5 on WordPress cross site scripting
CVE-2025-53330 | WpEstate WP Rentals Plugin up to 3.13.1 on WordPress cross site scripting
CVE-2025-21110 | Dell Data Lakehouse up to 1.5.0.0 unnecessary privileges (dsa-2025-313)
CVE-2025-53219 | pl4g4 WP-Database-Optimizer-Tools Plugin up to 0.2 on WordPress cross-site request forgery
CVE-2025-53342 | GoodLayers Modernize Plugin up to 3.4.0 on WordPress cross site scripting
CVE-2025-53581 | artiosmedia RSS Feed Pro Plugin up to 1.1.8 on WordPress cross site scripting
CVE-2025-53575 | primersoftware Primer MyData for Woocommerce Plugin up to 4.2.5 on WordPress cross site scripting
CVE-2025-53341 | Themovation Stratus Plugin up to 4.2.5 on WordPress authorization
CVE-2025-52771 | bcupham Video Expander Plugin up to 1.0 on WordPress cross site scripting
CVE-2025-53343 | GoodLayers Modernize Plugin up to 3.4.0 on WordPress authorization
CVE-2025-53221 | CodeablePress Plugin up to 1.0.0 on WordPress authorization
Threat Actors Leverage CrossC2 to Extend Cobalt Strike to Linux and macOS
JPCERT/CC verified a number of events in which threat actors were seen using CrossC2, an unofficial extension tool that creates Cobalt Strike Beacons that work with Linux and macOS. This campaign, which targeted Active Directory (AD) infrastructures, involved the use of CrossC2 alongside established tools such as PsExec for lateral movement, Plink for SSH tunneling, […]
The post Threat Actors Leverage CrossC2 to Extend Cobalt Strike to Linux and macOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
ServiceNow security advisory (AV25-516)
BSidesSF 2025: Don’t Trust, Verify! – How I Found A CSRF Bug Hiding In Plain Sight
Creator, Author and Presenter: Patrick O'Doherty
Our deep appreciation to Security BSides - San Francisco and the Creators, Authors and Presenters for publishing their BSidesSF 2025 video content on YouTube. Originating from the conference’s events held at the lauded CityView / AMC Metreon - certainly a venue like no other; and via the organization's YouTube channel.
Additionally, the organization is welcoming volunteers for the BSidesSF Volunteer Force, as well as their Program Team & Operations roles. See their succinct BSidesSF 'Work With Us' page, in which, the appropriate information is to be had!
The post BSidesSF 2025: Don’t Trust, Verify! – How I Found A CSRF Bug Hiding In Plain Sight appeared first on Security Boulevard.