Aggregator
CVE-2023-44857 | Cobham SAILOR VSAT Ku 164B019 acu_web sub_21D24 code injection
CVE-2024-31621 | FlowiseAI Flowise up to 1.6.2 api/v1 code injection (Exploit 52001 / EDB-52001)
CVE-2023-31493 | ZoneMinder up to 1.36.33 Languages Folder unrestricted upload
CVE-2025-3346 | Tenda AC7 15.03.06.44 /goform/SetPptpServerCfg formSetPPTPServer pptp_server_start_ip/pptp_server_end_ip buffer overflow
CVE-2025-46627 | Tenda RX2 Pro 16.03.30.14 Telnet Service weak password (EUVD-2025-13232)
CVE-2025-46628 | Tenda RX2 16.03.30.14 UDP Packet ate improper authorization (EUVD-2025-13234)
CVE-2025-46629 | Tenda RX2 Pro 16.03.30.14 UDP ate access control (EUVD-2025-13236)
CVE-2025-46626 | Tenda RX2 Pro 16.03.30.14 hard-coded key (EUVD-2025-13235)
CVE-2025-46625 | Tenda RX2 Pro 16.03.30.14 API Endpoint setLanCfg command injection (EUVD-2025-13260)
CVE-2025-46630 | Tenda RX2 Pro 16.03.30.14 Web Management Portal /goform/ate access control (EUVD-2025-13266)
CVE-2024-27967 | Michael Leithold DSGVO All in One for WP Plugin up to 4.3 on WordPress cross-site request forgery
Threat Actors Use Fake DocuSign Notifications to Steal Corporate Data
DocuSign has emerged as a cornerstone for over 1.6 million customers worldwide, including 95% of Fortune 500 companies, and boasts a user base exceeding one billion. However, this widespread adoption has made DocuSign a prime target for cybercriminals. Leveraging the platform’s trusted reputation, threat actors are increasingly deploying sophisticated phishing campaigns to harvest corporate credentials, […]
The post Threat Actors Use Fake DocuSign Notifications to Steal Corporate Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
The Browser Company 停止开发 Arc 转向 AI 驱动浏览器 Dia
Unsophisticated Actors, Poor Hygiene Prompt CI Alert for Oil & Gas
An alert from CISA, FBI, EPA and DOE came after CISA observed attacks by “unsophisticated” cyber actors leveraging “basic and elementary intrusion techniques” against ICS/SCADA systems.
The post Unsophisticated Actors, Poor Hygiene Prompt CI Alert for Oil & Gas appeared first on Security Boulevard.
DragonForce Ransomware Leveraged in MSP Attack Using RMM Tool
BSidesLV24 – PasswordsCon – Combating Phone Spoofing With STIR/SHAKEN
Author/Presenter: Per Thorsheim
Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel.
The post BSidesLV24 – PasswordsCon – Combating Phone Spoofing With STIR/SHAKEN appeared first on Security Boulevard.