Aggregator
Submit #627335: code-projects Online Medicine Guide V1.0 SQL injection [Accepted]
CVE-2025-8808 | xujeff tianti 天梯 up to 2.3 com.jeff.tianti.controller save exportOrder csv injection (EUVD-2025-24088)
CVE-2025-8807 | xujeff tianti 天梯 up to 2.3 save authorization (EUVD-2025-24089)
Submit #626875: diyhi bbs 6.8 Server-Side Request Forgery [Duplicate]
CVE-2025-8806 | zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 treeData sql injection (EUVD-2025-24086)
Submit #626673: Tianti Project Tianti 2.3 CSV Injection [Accepted]
Submit #626344: Tianti Project Tianti 2.3 Missing Authorization [Accepted]
CVE-2025-8805 | Open5GS up to 2.7.5 SMF src/smf/gsm-sm.c smf_gsm_state_wait_pfcp_deletion denial of service (Issue 4000 / EUVD-2025-24087)
Submit #626189: 智互联(深圳)科技有限公司 ADP应用开发者平台 zhlink V1.0.0 SQL Injection [Accepted]
CVE-2025-8804 | Open5GS up to 2.7.5 AMF ngap_build_downlink_nas_transport assertion (Issue 3950 / EUVD-2025-24084)
Submit #626125: Open5GS <= v2.7.5 Denial of Service [Accepted]
CVE-2025-8803 | Open5GS up to 2.7.5 AMF src/amf/gmm-sm.c gmm_state_de_registered/gmm_state_exception denial of service (Issue 3948 / EUVD-2025-24085)
Submit #626124: Open5GS <=v2.7.5 Denail of Service [Accepted]
Submit #626123: Open5GS <= v2.7.5 Denial of Service [Accepted]
Хотите работу в ИБ? Конкурс — 500 человек за право услышать: «Опыта маловато… даже для стажёра»
CastleBot MaaS Released Diverse Payloads in Coordinated Mass Ransomware Attacks
IBM X-Force has uncovered CastleBot, a nascent malware framework operating as a Malware-as-a-Service (MaaS) platform, enabling cybercriminals to deploy a spectrum of payloads ranging from infostealers to sophisticated backdoors implicated in ransomware operations. First detected in early 2025 with heightened activity since May, CastleBot facilitates the delivery of threats like NetSupport and WarmCookie, which have […]
The post CastleBot MaaS Released Diverse Payloads in Coordinated Mass Ransomware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-4655 | Liferay Portal/DXP FreeMarker Template server-side request forgery (EUVD-2025-24044)
CVE-2025-8802 | Open5GS up to 2.7.5 SMF src/smf/smf-sm.c smf_state_operational stream denial of service (Issue 3978 / EUVD-2025-24082)
ChromeAlone – A Browser Based Cobalt Strike Like C2 Tool That Turns Chrome Into a Hacker’s Playground
At DEF CON 33, security researcher Mike Weber of Praetorian Security unveiled ChromeAlone — a Chromium-based browser Command & Control (C2) framework capable of replacing traditional offensive security implants like Cobalt Strike or Meterpreter. Not long ago, web browsers were little more than wrappers for HTTP requests. Today, they are complex, feature-packed platforms, so sophisticated […]
The post ChromeAlone – A Browser Based Cobalt Strike Like C2 Tool That Turns Chrome Into a Hacker’s Playground appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.