Aggregator
CVE-2025-48290 | bslthemes kaffen Theme on WordPress file inclusion
CVE-2025-48290 | bslthemes Kinsley Theme on WordPress file inclusion
CVE-2025-48290 | bslthemes Ashley Theme on WordPress file inclusion
CVE-2025-48290 | bslthemes Builty Theme on WordPress file inclusion
SecWiki News 2025-05-29 Review
90sec还在啊,回忆。。。
十几年前上大学的时候经常混90sec,逛逛看雪,当时经常拿个破电脑扫sql漏洞,毕业了以后做牛马了这些东西就都放下了。以前全靠兴趣去玩这些,从脚本小子到crud boy,写过php,搞过golang,做过python,写过前端,只是再也没有以前的热情了。
偶尔回想起来,以前在90sec的岁月还是怀念啊,怀念以前的人和事,有遗憾有释怀,就是青春再也回不去了。。。。
6 个帖子 - 5 位参与者
CVE-2025-45474 | Maccms10 2025.1000.4047 Email Setting server-side request forgery
CVE-2025-48472 | freescout-help-desk freescout up to 1.8.178 authorization
CVE-2025-3913 | Mattermost up to 9.11.12/10.5.3/10.6.2/10.7.0 Team Privacy Setting /api/v4/teams/ authorization
CVE-2025-48473 | freescout-help-desk freescout up to 1.8.178 Conversation authorization
CVE-2025-48389 | freescout-help-desk freescout up to 1.8.177 set deserialization
CVE-2025-48471 | freescout-help-desk freescout up to 1.8.178 unrestricted upload
CVE-2025-48390 | freescout-help-desk freescout up to 1.8.177 tools.php file_exists php_path code injection
天问二号将执行小行星取样任务
安全的本质是代码质量
Cybercriminals Target AI Users with Malware-Loaded Installers Posing as Popular Tools
AutoGen Studio 容器化部署与维护指南
US sanctions firm linked to cyber scams behind $200 million in losses
Threat Actors Abused Nifty[.]com Infrastructure for Sophisticated Phishing Attack
Cybersecurity researchers have uncovered a sophisticated phishing campaign that leveraged the legitimate infrastructure of Nifty[.]com, a popular project management platform, to conduct targeted attacks against organizations worldwide. The campaign, which remained active for several months before detection, demonstrates an evolving trend where threat actors exploit trusted web services to bypass traditional security measures and establish […]
The post Threat Actors Abused Nifty[.]com Infrastructure for Sophisticated Phishing Attack appeared first on Cyber Security News.