Aggregator
CVE-2025-62719 | Kovah LinkAce up to 2.3.x server-side request forgery (GHSA-473x-rmm6-mc8c)
CVE-2025-59595 | Absolute Secure Access up to 14.11 Packet denial of service
CVE-2025-64108 | Cursor up to 1.7.44 path traversal (GHSA-6r98-6qcw-rxrw)
CVE-2025-12735 | silentmatt expr-eval up to 2.0.2 Variables evaluate code injection
CVE-2025-62369 | xibosignage xibo-cms up to 4.3.0 Module Templating code injection (GHSA-7rmm-689c-gjgv)
CVE-2025-64107 | Cursor up to 1.7.52 on Windows path traversal (GHSA-2jr2-8wf5-v6pf)
CVE-2025-64109 | Cursor up to 15.4.1 Model Context Protocol Server cursor/mcp.json os command injection (GHSA-4hwr-97q3-37w2 / CNNVD-202511-362)
CVE-2025-62507 | Redis up to 8.2.2 XACKDEL Command stack-based overflow (GHSA-jhjx-x4cf-4vm8)
Microsoft случайно «похоронила» LTSC-редакции Windows 10, которые обещала поддерживать до 2032 года
CVE-2025-62520 | mantisbt Mantis Bug Tracker up to 2.27.1 Private Project manage_config_columns_page.php improper authorization (GHSA-g582-8vwr-68h2)
Connected homes: Is bystander privacy anyone’s responsibility?
Smart doorbells, connected cameras, and home monitoring systems have become common sights on doorsteps and living rooms. They promise safety and convenience, but they also raise a problem. These devices record more than their owners. They capture neighbors, visitors, and anyone passing by. Overlooking bystander privacy A new study from researchers at the Budapest University of Technology and Economics shows that while companies selling these products talk about privacy, they rarely protect those who never … More →
The post Connected homes: Is bystander privacy anyone’s responsibility? appeared first on Help Net Security.
WordPress Post SMTP Plugin Vulnerability Exposes 400,000 Websites to Account Takeover Attacks
A critical security flaw in the WordPress Post SMTP plugin has left more than 400,000 websites vulnerable to account takeover attacks. The vulnerability, identified as CVE-2025-11833, enables unauthenticated attackers to access email logs containing sensitive password reset information, potentially compromising administrator accounts and entire websites. The flaw stems from a missing authorization check in the […]
The post WordPress Post SMTP Plugin Vulnerability Exposes 400,000 Websites to Account Takeover Attacks appeared first on Cyber Security News.
Bugcrowd Purchases Mayhem to Expand AppSec Testing Platform
Bugcrowd acquired Mayhem Security to integrate automated application testing with human-led testing capabilities. The company plans to embed Pittsburgh-based Mayhem's reinforcement learning tech and AI models into its broader platform to speed up vulnerability detection.
Lawsuits, Investigations Piling Up in Conduent Hack
Proposed federal class action litigation and various investigations are piling up against Conduent Business Solutions following its recent public disclosure that an October 2024 hacking incident potentially compromised personal and health information of more than 10.5 million people.
'It's Been a Mess': Shutdown Slows Federal F5 Hack Response
Current and former federal officials tell Information Security Media Group furloughs and leadership gaps across the federal cyber ecosystem have hindered the U.S. government's ability to coordinate response efforts after a nation-state actor exploited flaws in F5’s BIG-IP systems amid the shutdown.
Cyber Physical Systems Face Rising Geopolitical Risks
Global conflicts and tariff wars provide new opportunities for cyber adversaries, especially those targeting operational technology systems. Now attackers are focusing on fragile supply chains. Claroty researchers predict attackers will breach at least one major cyber-physical system in the next year.