Aggregator
Submit #631120: Scada-LTS 2.7.8.1 Cross Site Scripting (XSS) Stored [Accepted]
Submit #631119: Scada-LTS 2.7.8.1 Cross Site Scripting (XSS) Stored [Accepted]
Submit #631118: Scada-LTS 2.7.8.1 Cross Site Scripting (XSS) Stored [Accepted]
Lenovo AI Chatbot Flaw Allows Remote Script Execution on Corporate Systems
Cybersecurity researchers have uncovered critical vulnerabilities in Lenovo’s AI-powered customer support chatbot that could allow attackers to execute malicious scripts on corporate systems and steal sensitive session data. The discovery highlights significant security gaps in enterprise AI implementations and raises concerns about the rapid deployment of AI systems without adequate security controls. Cybernews Researchers identified […]
The post Lenovo AI Chatbot Flaw Allows Remote Script Execution on Corporate Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #631098: emlog.net Emlog 2.5.18 Unrestricted Upload [Accepted]
ИИ уничтожает фарму: миллионы молекул отсеяны за часы — без пробирок и людей
Microsoft Issues Emergency Patch for Windows Reset and Recovery Bug
Microsoft has released an emergency out-of-band security update to address a critical issue affecting Windows reset and recovery operations across multiple versions of the operating system. The patch, released on August 19, 2025, resolves problems that emerged after users installed the August 2025 Windows security update, causing some reset and recovery attempts to fail on […]
The post Microsoft Issues Emergency Patch for Windows Reset and Recovery Bug appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2020-27223 | Eclipse Jetty up to 9.4.36.v20210114/10.0.0/11.0.0 Accept Header algorithmic complexity
CVE-2020-27223 | Oracle REST Data Services Eclipse Jetty denial of service
CVE-2025-32947 | PeerTube up to 7.1.0 Inbox Endpoint infinite loop
CVE-2025-38402 | Linux Kernel up to 6.12.36/6.15.5/6.16-rc4 idpf size allocation of resources (WID-SEC-2025-1653)
CVE-2025-9132 | Google Chrome up to 139.0.7258.127 V8 out-of-bounds write (ID 436181)
CVE-2024-12223 | Nutanix Prism Central prior 2024.3.1 Events cross site scripting
CVE-2025-9174 | neurobin shc up to 4.0.3 Filename src/shc.c make os command injection (EUVD-2025-25251)
CVE-2025-38398 | Linux Kernel up to 6.15.5/6.16-rc4 spi qcom_nandc_alloc memory corruption (WID-SEC-2025-1653)
Apply Human-Centric Cybersecurity to Solve the Unpatchable Threat
Technology can’t fix the biggest cybersecurity threat — people. Human risk management uses behavioral data, targeted interventions, and measurable outcomes to turn the workforce from weakest link to strongest defense.
The post Apply Human-Centric Cybersecurity to Solve the Unpatchable Threat appeared first on Security Boulevard.
From Impact to Action: Turning BIA Insights Into Resilient Recovery
Kubernetes Capsule Vulnerability Enables Attackers to Inject Arbitrary Labels
Security researchers have disclosed a critical vulnerability in Kubernetes Capsule v0.10.3 and earlier versions that allows authenticated tenant users to inject arbitrary labels into system namespaces, fundamentally breaking multi-tenant isolation. The vulnerability, tracked as CVE-2025-55205 with a CVSS score of 9.9, enables attackers to bypass security boundaries and access cross-tenant resources, potentially leading to cluster-wide compromise. Vulnerability […]
The post Kubernetes Capsule Vulnerability Enables Attackers to Inject Arbitrary Labels appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Exploit for critical SAP Netweaver flaws released (CVE-2025-31324, CVE-2025-42999)
A working exploit concatenating two critical SAP Netweaver vulnerabilities (CVE-2025-31324, CVE-2025-42999) that have been previously exploited in the wild has been made public by VX Underground, Onapsis security researchers have warned. The exploit has allegedly been released on a Telegram channel that claimed to represent a collective of three established cybercrime groups: Scattered Spider, ShinyHunters, and LAPSUS$. Historical exploitation of CVE-2025-31324 Earlier this year, a suspected initial access broker group abused CVE-2025-31324 – a missing … More →
The post Exploit for critical SAP Netweaver flaws released (CVE-2025-31324, CVE-2025-42999) appeared first on Help Net Security.