Aggregator
CVE-2025-40598 | SonicWALL SMA 100 Web Interface cross site scripting (SNWLID-2025-0012 / Nessus ID 242692)
CVE-2025-1079 | Google Web Designer prior 16.2.0.0128 on macOS/Linux symlink (EUVD-2025-14276)
CVE-2025-20216 | Cisco Catalyst SD-WAN Manager up to 20.15.1_LI_Images Web Interface injection (cisco-sa-vmanage-html-inj-GxVtK6zj / Nessus ID 235490)
20 лет без движения — и 1 надпись, созданная мыслью. Neuralink снова показал, на что способен
Microsoft Teams New Meeting Join Bar Reminds You to Join Meeting On-time
Microsoft Teams is rolling out a significant enhancement to its meeting experience with the introduction of a new meeting join banner designed to streamline user access to scheduled meetings. The feature, identified by message code MC1115979, represents Microsoft’s continued effort to improve productivity and reduce meeting delays across enterprise environments. Key Takeaways1. Automatic meeting join […]
The post Microsoft Teams New Meeting Join Bar Reminds You to Join Meeting On-time appeared first on Cyber Security News.
【动态】埃及近24小时动态分析报告
【情报实战】AI挖掘基孔肯雅热病暴发脉络
经济学家称挪威人太富裕且太舒坦了
Critical CodeIgniter Vulnerability Exposes Million of Webapps to File Upload Attacks
A critical security vulnerability has been discovered in CodeIgniter4’s ImageMagick handler, exposing potentially millions of web applications to command injection attacks through malicious file uploads. The vulnerability, tracked as CVE-2025-54418, received a CVSS score of 9.8, indicating the highest severity level and immediate risk to affected systems. Key Takeaways1. Critical vulnerability in CodeIgniter4 <4.6.2 ImageMagick […]
The post Critical CodeIgniter Vulnerability Exposes Million of Webapps to File Upload Attacks appeared first on Cyber Security News.
Unveiling the Lumma Password Stealer Attack: Infection Chain and Escalation Tactics Exposed
Lumma, a sophisticated C++-based information stealer, has surged in prevalence over recent years, posing significant risks to both individuals and organizations by exfiltrating sensitive data such as browser credentials, cryptocurrency wallets, and personal files. Developed since December 2022 and distributed as Malware-as-a-Service (MaaS) via Telegram channels with tiered subscriptions, Lumma relies on initial access brokers […]
The post Unveiling the Lumma Password Stealer Attack: Infection Chain and Escalation Tactics Exposed appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Poland says more than 30 suspects face trial over pro-Russian sabotage
Auto-Color Backdoor Malware Exploits SAP Vulnerability
SonicWall SMA100 Series N-day Vulnerabilities Technical Details Revealed
Multiple critical vulnerabilities affecting SonicWall’s SMA100 series SSL-VPN appliances, highlighting persistent security flaws in network infrastructure devices. The vulnerabilities, designated CVE-2025-40596, CVE-2025-40597, and CVE-2025-40598, demonstrate fundamental programming errors that enable pre-authentication attacks against firmware version 10.2.1.15. Key Takeaways1. Stack overflow, heap overflow, and XSS in SonicWall SMA100 SSL-VPN devices.2. Both overflows triggered without authentication via […]
The post SonicWall SMA100 Series N-day Vulnerabilities Technical Details Revealed appeared first on Cyber Security News.