Aggregator
Safepay
CVE-2002-1656 | Xqus X-News 1.0/1.1 Cookie missing encryption (VU#162723 / EDB-3043)
RCE в Marvel Rivals: как игра превратилась в троян с правами администратора
CVE-2024-20066 | MediaTek MT8798 Modem out-of-bounds write (MOLY01267281)
CVE-2024-20075 | MediaTek MT8789 eemgpu out-of-bounds write (ALPS08713302)
CVE-2024-20079 | MediaTek MT8678 Gnss Service out-of-bounds write (MSV-1491 / ALPS08044040)
CVE-2024-20081 | MediaTek MT8678 Gnss Service out-of-bounds write (MSV-1412 / ALPS08719602)
CVE-2024-4785 | zephyrproject-rtos Zephyr up to 3.6 LL_CONNECTION_UPDATE_IND Packet null pointer dereference (GHSA-xcr5-5g98-mchp)
CVE-2024-20111 | MediaTek MT8195 Ccu out-of-bounds write (MSV-1754 / ALPS09065033)
CVE-2024-11263 | zephyrproject-rtos Zephyr up to 3.7 Global Pointer privilege context switching error (GHSA-jjf3-7x72-pqm9)
CVE-2024-53438 | ChurchCRM 5.7.0 EventAttendance.php Event sql injection
CVE-2024-8798 | zephyrproject-rtos Zephyr up to 3.7 ots_client.c olcp_ind_handler heap-based overflow (GHSA-r7pm-f93f-f7fp)
CVE-2024-48886 | Fortinet FortiOS/FortiProxy weak authentication (FG-IR-24-221 / Nessus ID 214077)
CVE-2024-48884 | Fortinet FortiManager/FortiOS/FortiProxy Packet path traversal (FG-IR-24-259 / Nessus ID 214079)
CVE-2024-48890 | Fortinet FortiSOAR 7.5.0 Playbook os command injection (FG-IR-24-415)
CVE-2024-48893 | Fortinet FortiSOAR up to 7.2.2/7.3.3 Playbook cross site scripting (FG-IR-24-405)
CVE-2024-20129 | MediaTek MT6580 Telephony out-of-bounds (MSV-2025 / ALPS09289881)
Canadian National Charged with Stealing $65 Million in Crypto
A Canadian man has been charged with exploiting decentralized finance (DeFi) protocols to steal approximately $65 million from unsuspecting investors. A five-count criminal indictment, unsealed today in a federal court in New York, accuses 22-year-old Andean Medjedovic of targeting vulnerabilities in automated smart contracts used by two prominent DeFi platforms: KyberSwap and Indexed Finance. Alleged […]
The post Canadian National Charged with Stealing $65 Million in Crypto appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Critical Microsoft Accounts Authentication Bypass Vulnerability Let Attackers Gain Remote Access
Microsoft has issued a security advisory for CVE-2025-21396, a critical authentication bypass vulnerability that could allow attackers to spoof credentials and gain unauthorized access to Microsoft accounts. Cybersecurity experts are urging users and organizations to swiftly address this issue by applying relevant updates and following Microsoft’s guidance. The vulnerability is linked to CWE-290, Authentication Bypass […]
The post Critical Microsoft Accounts Authentication Bypass Vulnerability Let Attackers Gain Remote Access appeared first on Cyber Security News.