Aggregator
Submit #580323: Part-DB 1.17.0 Cross-Site Scripting [Accepted]
4 月中国智能手机出口暴跌 72%
Submit #580248: Campcodes Online Shopping Portal V1.0 SQL Injection [Accepted]
WordPress Plugin Vulnerability Exposes 22,000 Sites to Cyber Attacks
A critical security vulnerability discovered in the popular Motors WordPress theme has exposed approximately 22,000 websites to significant risk. Security researchers have identified a privilege escalation vulnerability that allows unauthenticated attackers to take over administrative accounts, potentially compromising the entire website. This vulnerability (CVE-2025-4322) carries a critical CVSS score of 9.8 and affects all versions […]
The post WordPress Plugin Vulnerability Exposes 22,000 Sites to Cyber Attacks appeared first on Cyber Security News.
Submit #580201: projectworlds Online Time Table Generator PHP MYSQL V1.0 /admin/add_course.php SQL injection v1.0 SQL Injection [Accepted]
Submit #580195: Projectworlds Online Time Table Generator PHP MYSQL V1.0 /semester_ajax.php SQL injection v1.0 SQL Injection [Accepted]
Submit #580198: projectworlds Online Time Table Generator PHP MYSQL V1.0 /staff/index.php SQL injection v1.0 SQL Injection [Duplicate]
Submit #580197: projectworlds Online Time Table Generator PHP MYSQL V1.0 /student/index.php SQL injection v1.0 SQL Injection [Duplicate]
CISA Includes MDaemon Email Server XSS Flaw in KEV Catalog
Cybersecurity and Infrastructure Security Agency (CISA) has added a cross-site scripting (XSS) vulnerability affecting MDaemon Email Server to its Known Exploited Vulnerabilities (KEV) Catalog on May 19, 2025. This critical addition, identified as CVE-2024-11182, highlights a security flaw that allows attackers to inject malicious JavaScript code via crafted HTML emails. Federal agencies now have until […]
The post CISA Includes MDaemon Email Server XSS Flaw in KEV Catalog appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #580196: projectworlds Online Time Table Generator PHP MYSQL V1.0 /course_ajax.php SQL injection v1.0 SQL Injection [Duplicate]
Submit #580192: SourceCodester Client Database Management System v1.0 SQL injection [Accepted]
Microsoft to Integrate AI With Windows 11 File Explorer
Microsoft is introducing artificial intelligence capabilities directly into Windows 11’s File Explorer, allowing users to manipulate files without opening dedicated applications. Announced in Windows 11 Insider Preview Build 26200.5603 (KB5058488) released to the Dev Channel on May 19, 2025, this integration represents a significant advancement in Microsoft’s AI strategy for its flagship operating system. AI […]
The post Microsoft to Integrate AI With Windows 11 File Explorer appeared first on Cyber Security News.
Cynet boosts AI-powered threat detection accuracy
Cynet announced a major update to CyAI, its proprietary AI engine that powers advanced threat detection across the Cynet platform. By reducing false positives by 90%, CyAI advances Cynet’s mission to maximize purpose-built protection for managed service providers and small-to-medium businesses, backed by 24/7 SOC support. Leveraging machine learning models trained on millions of samples, CyAI continuously analyzes every executable file across all endpoints to detect known and zero-day threats before damage can be done. … More →
The post Cynet boosts AI-powered threat detection accuracy appeared first on Help Net Security.
How Adversary Telegram Bots Help to Reveal Threats: Case Study
While analyzing malware samples uploaded to ANY.RUN’s Interactive Sandbox, one particular case marked as “phishing” and “Telegram” drew the attention of our security analysts. Although this analysis session wasn’t attributed to any known malware family or threat actor group, the analysis revealed that Telegram bots were being used for data exfiltration. This led us to […]
The post How Adversary Telegram Bots Help to Reveal Threats: Case Study appeared first on ANY.RUN's Cybersecurity Blog.
Hackers Use Weaponized RAR Archives to Deliver Pure Malware in Targeted Attacks
Russian organizations have become prime targets of a sophisticated malware campaign deploying the Pure malware family, first identified in mid-2022. Distributed via a Malware-as-a-Service (MaaS) model, Pure malware allows cybercriminals to purchase and deploy it with ease. While the campaign began in March 2023, the first third of 2025 witnessed a staggering fourfold increase in […]
The post Hackers Use Weaponized RAR Archives to Deliver Pure Malware in Targeted Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.