Aggregator
CVE-2024-56342 | IBM Verify Identity Access Digital Credentials 24.06 information exposure (EUVD-2024-54648)
CVE-2025-36513 | i-PRO Surveillance Camera cross-site request forgery (EUVD-2025-17048)
CVE-2025-5719 | Vivo Wallet missing authentication (EUVD-2025-17051)
PrimeCache: бэкдор, который живёт по принципу "не трогай — не заметят"
Hackers Exploit Roundcube Vulnerability to Steal User Credentials via XSS Attack
A recent spearphishing campaign targeting Polish entities has been attributed with high confidence to the UNC1151 threat actor, a group linked to Belarusian state interests and, according to some sources, Russian intelligence services. CERT Polska reports that the attackers leveraged a critical vulnerability in the Roundcube webmail platform—CVE-2024-42009—to steal user credentials with minimal user interaction. […]
The post Hackers Exploit Roundcube Vulnerability to Steal User Credentials via XSS Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Переговоры с вымогателями: спасение или ловушка?
ATAG:AI 代理应用威胁评估与攻击图
Pathlock helps organizations protect their SAP environments from development to deployment
Pathlock announced a major expansion of its SAP cybersecurity offerings, introducing a new portfolio of value-driven and easy-to-deploy SAP cybersecurity solutions, including a Free Edition. Designed to deliver maximum value and fast time-to-protection, the launch marks a significant step toward democratizing SAP security for organizations of all sizes. Meeting the urgent need for SAP cybersecurity As SAP ERP continues to serve as the digital core for thousands of enterprises worldwide, the need for easy, effective … More →
The post Pathlock helps organizations protect their SAP environments from development to deployment appeared first on Help Net Security.
亚马逊测试用人形机器人送包裹
ViperSoftX мутировал: хакеры создали неуязвимый криптовор
Hackers Using New Sophisticated iMessage 0-Click Exploit to Attack iPhone Users
A previously unknown zero-click vulnerability in Apple’s iMessage appears to have been exploited by sophisticated threat actors targeting high-profile individuals across the United States and the European Union. The vulnerability, dubbed “NICKNAME,” affected iOS versions up to 18.1.1 and was silently patched by Apple in iOS 18.3. The discovery, made by cybersecurity firm iVerify, reveals […]
The post Hackers Using New Sophisticated iMessage 0-Click Exploit to Attack iPhone Users appeared first on Cyber Security News.
CVE-2023-2921 | Short URL Plugin up to 1.6.8 on WordPress sql injection
Claroty enhances xDome platform with Device Purpose and Risk Benchmarking capabilities
Claroty announced new capabilities in its SaaS-based Claroty xDome platform that provide organizations with an impact-centric view of their CPS environment. The new additions, Device Purpose and Risk Benchmarking, allow users to see how the overall risk of an environment is affected by the processes involved in a device’s use – as production lines, building floors, hospital wings, and more – and prioritize risk reduction efforts based on potential impact to business outcomes, while bridging … More →
The post Claroty enhances xDome platform with Device Purpose and Risk Benchmarking capabilities appeared first on Help Net Security.