Aggregator
Open source умирает на глазах: KubeSphere — ещё один гвоздь в крышку гроба
CVE-2025-48499 | Fujifilm DocuPrint CP225 w Internet Printing Protocol/Line Printer Daemon out-of-bounds write (EUVD-2025-23486)
Submit #579544: Intelbras InControl 2.21.60.9 Information Disclosure [Accepted]
NestJS Vulnerability Allows Code Execution on Developer Machines
A critical remote code execution vulnerability has been discovered in the popular NestJS framework that could allow attackers to execute arbitrary code on developer machines. The vulnerability, tracked as CVE-2025-54782, affects the @nestjs/devtools-integration package and has been assigned the highest severity rating due to its potential for complete system compromise through simple web-based attacks. Vulnerability […]
The post NestJS Vulnerability Allows Code Execution on Developer Machines appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Average global data breach cost now $4.44 million
IBM released its Cost of a Data Breach Report, which revealed AI adoption is greatly outpacing AI security and governance. While the overall number of organizations experiencing an AI-related breach is a small representation of the researched population, this is the first time security, governance and access controls for AI have been studied in this report, which suggests AI is already an easy, high value target. The AI oversight gap 13% of organizations reported breaches … More →
The post Average global data breach cost now $4.44 million appeared first on Help Net Security.
NHIs Continue to Outpace Human Identities and Bump Up Security Risk
NHIs Continue to Outpace Human Identities and Bump Up Security Risk
Unmanaged machine identities have continued to tick up at a rapid clip, furthering a trend that finds non-human identities (NHIs) outpacing human accounts — and, to the chagrin of security experts, exposing credentials, new research on the first half of 2025 reveals.
The post NHIs Continue to Outpace Human Identities and Bump Up Security Risk appeared first on Security Boulevard.
7-Zip 25.01: проверка ссылок, новый флаг -snld20 и защита по умолчанию
CVE-2025-20696 | MediaTek MT8676 DA out-of-bounds write (MSV-3801 / ALPS09915215)
CVE-2025-20698 | MediaTek MT8893 Power HAL out-of-bounds write (MSV-3793 / ALPS09915400)
CVE-2025-20697 | MediaTek MT8893 Power HAL out-of-bounds write (MSV-3795 / ALPS09915681)
Open-source password recovery utility Hashcat 7.0.0 released
Hashcat is an open-source password recovery tool that supports five attack modes and more than 300 highly optimized hashing algorithms. It runs on CPUs, GPUs, and other hardware accelerators across Linux, Windows, and macOS, and includes features for distributed password cracking at scale. Hashcat 7.0.0 touches over 900,000 lines of code and welcoming contributions from 105 developers, including 74 first-timers. The update rolls all previously unannounced 6.2.x features into a single, well-documented release, setting a … More →
The post Open-source password recovery utility Hashcat 7.0.0 released appeared first on Help Net Security.