Aggregator
Vulnerabilities in Preinstalled Android Apps Expose PIN Codes and Allow Command Injection
Significant vulnerabilities were uncovered in pre-installed applications on Ulefone and Krüger&Matz Android smartphones that expose users to significant risks, including unauthorized factory resets, PIN code theft, and malicious command injection. These flaws, published on May 30, 2025, demonstrate how Improper Export of Android Application Components (CWE-926) can compromise device security at the system level. Factory […]
The post Vulnerabilities in Preinstalled Android Apps Expose PIN Codes and Allow Command Injection appeared first on Cyber Security News.
朝鲜智能手机会自动替换禁词每 5 分钟截屏
Dell security advisory (AV25-306)
CVE-2024-40114 | Sitecom WLX-2006 Wall Mount Range Extender N300 up to 1.5 Cookie Language cross site scripting (EUVD-2024-54620)
CVE-2024-40113 | Sitecom WLX-2006 Wall Mount Range Extender N300 up to 1.5 default credentials (EUVD-2024-54621)
CVE-2024-40112 | Sitecom WLX-2006 Wall Mount Range Extender N300 up to 1.5 Cookie Language file inclusion (EUVD-2024-54623)
Pro-Ukraine hacker group Black Owl poses ‘major threat’ to Russia, Kaspersky says
US Sanctions Philippines’ Funnull Technology Over $200M Crypto Scam
CVE-2025-4047 | Broken Link Checker Plugin up to 2.4.4 on WordPress ajax_full_status/ajax_dashboard_status improper authentication
CVE-2025-2939 | Ninja Tables Plugin up to 5.0.18 on WordPress deserialization
CVE-2025-44172 | Tenda AC6 15.03.05.16 setSmartPowerManagement Time stack-based overflow (EUVD-2025-16664)
CVE-2025-37096 | HPE StoreOnce Software up to 4.3.10 command injection
CVE-2024-54028 | catdoc 0.95 OLE Document DIFAT Parser integer underflow (TALOS-2024-2132 / EUVD-2024-54622)
CVE-2024-52035 | catdoc 0.95 OLE Document File Allocation Table Parser integer overflow (TALOS-2024-2131)
CVE-2024-48877 | xls2csv 0.95 Shared String Table Record Parser integer overflow to buffer overflow (TALOS-2024-2128 / EUVD-2024-54625)
CVE-2025-20001 | High-Logic FontCreator 15.0.0.3015 Font File out-of-bounds (TALOS-2025-2157 / EUVD-2025-16663)
CVE-2024-28995 | SolarWinds Serv-U up to 15.4.2 HF 1 path traversal (EDB-52311)
2nd June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 2nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IT management software company ConnectWise confirmed that a sophisticated nation-state cyberattack had compromised its environment, affecting a limited number of customers using its ScreenConnect remote access tool. The company launched a forensic […]
The post 2nd June – Threat Intelligence Report appeared first on Check Point Research.
MediaTek Vulnerabilities Let Attackers Escalate Privileges Without User Interaction
Multiple critical security vulnerabilities affecting MediaTek smartphones, tablets, and IoT chipsets could allow attackers to escalate privileges and compromise device security without requiring any user interaction. The Taiwan-based chipset manufacturer published its June 2025 Product Security Bulletin, revealing seven Common Vulnerabilities and Exposures (CVEs) with severity ratings from high to medium severity, according to CVSS […]
The post MediaTek Vulnerabilities Let Attackers Escalate Privileges Without User Interaction appeared first on Cyber Security News.