Aggregator
CVE-2012-4957 | Novell File Reporter 1.0.2 NFRAgent.exe path traversal (VU#273371 / EDB-23323)
CVE-2012-1464 | NetMechanica NetDecision 4.5.1 Installation information disclosure (EDB-18543 / Nessus ID 10297)
CVE-2012-5932 | Novell NetIQ 2.3.0/2.3.1 Privileged User Manager unifid.exe ldapagnt_eval Perl Code code injection (EDB-22738 / Nessus ID 63185)
Azure AD Vulnerability Leaks Credentials, Lets Attackers Deploy Malicious Apps
Exposing an ASP.NET Core appsettings.json file containing Azure Active Directory (Azure AD) credentials poses a critical attack vector, effectively handing adversaries the keys to an organization’s cloud environment. During a recent cybersecurity assessment by Resecurity’s HUNTER Team, researchers discovered that a publicly accessible appsettings.json file had exposed the ClientId and ClientSecret of an Azure AD application, […]
The post Azure AD Vulnerability Leaks Credentials, Lets Attackers Deploy Malicious Apps appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Threat Actors Exploit Windows Search in AnyDesk ClickFix Attack to Spread MetaStealer
In a novel twist on the year-long trend of ClickFix scams, threat actors have blended human-verification social engineering with the Windows search protocol to deliver MetaStealer, a commodity infostealer notorious for harvesting credentials and exfiltrating sensitive files. While the attack superficially resembles classic ClickFix and FileFix techniques, its unique infection chain—from a fake AnyDesk installer […]
The post Threat Actors Exploit Windows Search in AnyDesk ClickFix Attack to Spread MetaStealer appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Когда трубка молчит: как наладить связь с бабушкой после блокировки звонков в мессенджерах
Rovo Dev CLI – 可使用 Claude Sonnet 4、GPT-5 的免费 Claude Code,每天 2000 万 Token
CVE-2002-1677 | mrtgconfig 0.5.9 Error Message 14all.cgi cfg Path information disclosure (ID 10782 / XFDB-8070)
CVE-2002-1678 | Jelsoft vBulletin up to 2.2.4 memberlist.php $letterbits cross site scripting (ID 10547 / XFDB-8619)
CVE-2002-1707 | phpBB up to 2.0.1 install.php phpbb_root_dir privileges management (ID 10740 / XFDB-9370)
CVE-2002-1702 | Deltascripts Php Classifieds 6.0.5 URL cross site scripting (EDB-21552 / ID 10742)
OnionC2: The New C&C Framework for Anonymous Cyber Operations
OnionC2 is a command and control (C2) framework with communications over Tor network. It’s packed with privacy &
The post OnionC2: The New C&C Framework for Anonymous Cyber Operations appeared first on Penetration Testing Tools.
CVE-2023-20912 | Google Android 13.0 AvatarPickerActivity.java onActivityResult permission (A-246301995 / EUVD-2023-25080)
CVE-2023-20911 | Google Android 11.0/12.0/13.0 PermissionManagerServiceImpl.java addPermission resource consumption (A-242537498 / EUVD-2023-25079)
CVE-2023-20910 | Google Android 11.0/12.0/13.0 WifiManager.java addNetworkSuggestions resource consumption (A-245299920 / EUVD-2023-25078)
Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely
Multiple critical vulnerabilities in Qualcomm Technologies’ proprietary Data Network Stack and Multi-Mode Call Processor that permit remote attackers to execute arbitrary code. These flaws, tracked as CVE-2025-21483 and CVE-2025-27034, each carry a CVSS score of 9.8 and exploit buffer-corruption weaknesses to compromise device security. Key Takeaways1. CVE-2025-21483 & CVE-2025-27034 allow remote RCE.2. Affects Snapdragon 8 […]
The post Critical Qualcomm Vulnerabilities Allow Attackers to Execute Arbitrary Code Remotely appeared first on Cyber Security News.
CVE-2025-7734 | GitLab Community Edition/Enterprise Edition up to 18.0.5/18.1.3/18.2.1 cross site scripting (Issue 556090 / Nessus ID 260160)
CVE-2025-8770 | GitLab Enterprise Edition up to 18.0.5/18.1.3/18.2.1 Merge Request authorization (Issue 549105 / Nessus ID 260161)
Azure Active Directory Vulnerability Exposes Credentials and Enables Attackers to Deploy Malicious Apps
A critical security vulnerability has emerged in Azure Active Directory (Azure AD) configurations that exposes sensitive application credentials, providing attackers with unprecedented access to cloud environments. This vulnerability centers around the exposure of appsettings.json files containing ClientId and ClientSecret credentials, effectively handing adversaries the keys to entire Microsoft 365 tenants. The vulnerability was identified during […]
The post Azure Active Directory Vulnerability Exposes Credentials and Enables Attackers to Deploy Malicious Apps appeared first on Cyber Security News.