Aggregator
多年补丁难及终端,固件漏洞持续困扰供应链
SharePoint zero-day CVE-2025-53770 actively exploited in the wild
SharePoint zero-day CVE-2025-53770 actively exploited in the wild
Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability
Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are actively exploiting. The vulnerabilities, assigned as CVE-2025-53770 and CVE-2025-53771, pose immediate risks to organizations running SharePoint infrastructure and require immediate remediation. Key Takeaways1. Active zero-day attacks targeting on-premises SharePoint servers via CVE-2025-53770 and CVE-2025-53771.2. Apply security updates […]
The post Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability appeared first on Cyber Security News.
你家宽带真达标了?开源项目 MySpeed 帮你自动后台测速,可保留30天数据
CVE-2025-7939 | jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 GoodsController.java addGoods unrestricted upload
CVE-2025-7938 | jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 GoodsController.java updateGoods authorization
三父母 IVF 帮助 8 名婴儿健康出生
Submit #618986: Gitee 蛋糕商城JPA版 1.0 Unrestricted Upload [Accepted]
Submit #618985: Gitee 蛋糕商城JPA版 1.0 Incorrect Privilege Assignment [Accepted]
Who’s Watching You? FBI IG Looks to Plug Holes in Ubiquitous Technical Surveillance
Security gaps, coupled with savvy cybercriminals, lend urgency to mitigating the potential for exploitation posed by surveillance tech.
The post Who’s Watching You? FBI IG Looks to Plug Holes in Ubiquitous Technical Surveillance appeared first on Security Boulevard.
Who’s Watching You? FBI IG Looks to Plug Holes in Ubiquitous Technical Surveillance
CVE-2025-7343 | Digiwin SFT up to 3.7.12 sql injection (EUVD-2025-22055)
CVE-2025-24937 | Nokia WaveSuite NOC stack-based overflow
CVE-2025-7921 | ASKEY RTF8207w/RTF8217 prior R82XXR250718 stack-based overflow (EUVD-2025-22058)
CVE-2025-7344 | Digiwin EAI incorrect privileged apis (EUVD-2025-22057)
CVE-2025-24938 | Nokia WaveSuite NOC User Management os command injection
Critical SharePoint Zero-Day (CVE-2025-53770) Actively Exploited in the Wild
A critical vulnerability has been discovered in Microsoft SharePoint Server, now actively exploited as part of a widespread cyberattack campaign. The flaw, identified as CVE-2025-53770, carries a staggering severity score of 9.8 out of...
The post Critical SharePoint Zero-Day (CVE-2025-53770) Actively Exploited in the Wild appeared first on Penetration Testing Tools.
CISA Issues Alert on Microsoft SharePoint 0-Day RCE Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent security alert regarding a critical zero-day vulnerability in Microsoft SharePoint Server that is being actively exploited in cyberattacks. The vulnerability, tracked as CVE-2025-53770, represents a significant threat to organizations running on-premises SharePoint installations. The flaw stems from a deserialization of untrusted data vulnerability within […]
The post CISA Issues Alert on Microsoft SharePoint 0-Day RCE Exploited in Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.