Aggregator
Malware Developers Test AI for Adaptive Code Generation
3 months 1 week ago
Google Details How Attackers Could Use LLMs to Mutate Scripts
Malware authors are experimenting with a new breed of artificial intelligence-driven attacks, with code that could potentially rewrite itself as it runs. Large language models are allowing hackers to generate, modify and execute commands on demand, instead of relying on static payloads
Malware authors are experimenting with a new breed of artificial intelligence-driven attacks, with code that could potentially rewrite itself as it runs. Large language models are allowing hackers to generate, modify and execute commands on demand, instead of relying on static payloads
Cops Cuff 18 Suspects Over $345M Credit Card Fraud Scheme
3 months 1 week ago
German Payment Processor Insiders Accused of Laundering Fake Subscription Proceeds
Police have arrested 18 suspects as part of a global crackdown targeting fraud and money laundering networks tied to the theft of $345 million by using 4.3 million cardholders' stolen data to sign them up to fake dating, pornography or streaming sites that billed monthly.
Police have arrested 18 suspects as part of a global crackdown targeting fraud and money laundering networks tied to the theft of $345 million by using 4.3 million cardholders' stolen data to sign them up to fake dating, pornography or streaming sites that billed monthly.
Randall Munroe’s XKCD ‘’Physics Paths”
3 months 1 week ago
via the comic artistry and dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘’Physics Paths” appeared first on Security Boulevard.
Marc Handelman
WordPress的AI引擎插件中存在严重漏洞(CVE-2025-11749),可致网站被攻击者完全控制
3 months 1 week ago
安全客
深度解析Tycoon 2FA钓鱼工具包针对Microsoft 365与Gmail账户的攻击手法
3 months 1 week ago
安全客
新型NGate NFC恶意软件通过中继受害者手机的EMV数据与PIN码,对ATM实施盗刷
3 months 1 week ago
安全客
CISA发布关键漏洞紧急警报:Gladinet LFI/RCE漏洞与控制面板CWP管理员权限接管漏洞正遭积极利用
3 months 1 week ago
安全客
全球网络间谍组织利用ZipperDown漏洞及Android零日漏洞,通过邮件客户端实现一键远程代码执行与账户接管
3 months 1 week ago
安全客
React Native CLI 中存在严重漏洞(CVE-2025-11953,CVSS 9.8),攻击者可经由暴露的Metro开发服务器实现RCE
3 months 1 week ago
安全客
Bugcrowd收购自动化测试工具Mayhem,以强化其应用安全测试平台能力
3 months 1 week ago
安全客
Open VSX扩展市场中出现新型“SleepyDck”恶意软件,允许攻击者远程控制Windows系统
3 months 1 week ago
安全客
零信任安全厂商Zscaler收购企业AI安全公司SPLX,以增强其零信任交换平台能力
3 months 1 week ago
安全客
CVE-2025-12560 | Blog2Social Plugin up to 8.6.0 on WordPress getFullContent post_url server-side request forgery (EUVD-2025-37976)
3 months 1 week ago
A vulnerability described as critical has been identified in Blog2Social Plugin up to 8.6.0 on WordPress. Affected is the function getFullContent. The manipulation of the argument post_url results in server-side request forgery.
This vulnerability was named CVE-2025-12560. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-10691 | Easy Email Subscription Plugin up to 1.3 on WordPress show_editsub_page cross-site request forgery (EUVD-2025-37972)
3 months 1 week ago
A vulnerability marked as problematic has been reported in Easy Email Subscription Plugin up to 1.3 on WordPress. This impacts the function show_editsub_page. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-10691. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-11271 | Easy Digital Downloads Plugin up to 3.5.2 on WordPress Transaction ID Remote Code Execution (EUVD-2025-37973)
3 months 1 week ago
A vulnerability labeled as critical has been found in Easy Digital Downloads Plugin up to 3.5.2 on WordPress. This affects an unknown function of the component Transaction ID Handler. Executing manipulation can lead to Remote Code Execution.
This vulnerability is handled as CVE-2025-11271. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2025-12563 | Blog2Social Plugin up to 8.6.0 on WordPress theuploadVideo unrestricted upload (EUVD-2025-37974)
3 months 1 week ago
A vulnerability identified as critical has been detected in Blog2Social Plugin up to 8.6.0 on WordPress. The impacted element is the function theuploadVideo. Performing manipulation results in unrestricted upload.
This vulnerability is known as CVE-2025-12563. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-43990 | Dell Command Monitor 10.9/10.10.0 unnecessary privileges (dsa-2025-414 / EUVD-2025-37943)
3 months 1 week ago
A vulnerability categorized as critical has been discovered in Dell Command Monitor 10.9/10.10.0. The affected element is an unknown function. Such manipulation leads to execution with unnecessary privileges.
This vulnerability is traded as CVE-2025-43990. An attack has to be approached locally. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-10713 | WSO2 Enterprise Integrator XML Parser xml external entity reference
3 months 1 week ago
A vulnerability was found in WSO2 Enterprise Integrator, API Control Plane, Universal Gateway, Traffic Manager, API Manager, Identity Server, Open Banking IAM, Open Banking AM, Identity Server as Key Manager and org.wso2.carbon.mediation:org.wso2.carbon.localentry. It has been rated as problematic. Impacted is an unknown function of the component XML Parser. This manipulation causes xml external entity reference.
This vulnerability appears as CVE-2025-10713. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
你的大模型安全吗?360大模型卫士检测系统,给AI做个全面“体检”
3 months 1 week ago
安全客