Aggregator
WinRAR 0‑Day Exploit Listed for $80K on Dark Web Forum
A sophisticated zero-day exploit targeting WinRAR, one of the world’s most popular file compression utilities, has surfaced on a dark web marketplace with a hefty price tag of $80,000. The previously unknown remote code execution (RCE) vulnerability affects both the latest and earlier versions of the widely-used software, raising significant concerns for millions of users […]
The post WinRAR 0‑Day Exploit Listed for $80K on Dark Web Forum appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Why your Microsoft 365 setup might be more vulnerable than you think
60% of organizations rate their Microsoft 365 security as “established” or “advanced”, according to CoreView. Yet, 60% of those same organizations have experienced account compromise attacks. The Microsoft 365 attack surface is wide and unpredictable. Risks can come from any direction, whether it’s the complexity of managing multiple tenants, the explosion of Entra apps with broad permissions, or inconsistent enforcement of security controls like MFA. These issues are often worsened by limited visibility, manual oversight, … More →
The post Why your Microsoft 365 setup might be more vulnerable than you think appeared first on Help Net Security.
ZDI-CAN-21655: Oxford Instruments
CVE-2009-4315 | Nuggetz CMS 1.0 admin/ajaxsave.php pagevalue path traversal (EDB-10378 / XFDB-54699)
谷歌云端硬盘桌面版UI换新 可以在单个视图中查看通知/同步/共享文件等
CVE-2004-1751 | Massive Entertainment Ground Control II: Operation Exodus up to 1.0.0.7 Socket Large Packet denial of service (EDB-429 / XFDB-17130)
LSASS凭证窃取与现代Windows防御深度分析报告
CVE-2025-7564 | LB-LINK BL-AC3600 1.0.22 /etc/shadow hard-coded credentials (EUVD-2025-21303)
Ransomware drops, but don’t relax yet
WatchGuard has released its latest Internet Security Report, covering malware, network, and endpoint threats spotted by its Threat Lab in the first quarter of 2025. The report shows a 171% jump in unique malware detections compared to the previous quarter, the highest number the Threat Lab has seen so far. Along with that, there was a large rise in zero-day malware, pointing to a growing trend in threats designed to slip past traditional security tools … More →
The post Ransomware drops, but don’t relax yet appeared first on Help Net Security.
Dayz Perm Banned
CVE-2010-5280 | Joomla-cbe Com Cbe 1.4.9 File Upload index.php tabname path traversal (EDB-15222 / XFDB-62376)
CVE-2025-32375
CVE-2025-1727
CVE-2025-34085
CVE-2015-1489 | Symantec Endpoint Protection Manager up to 12.1 Management Console access control (EDB-37812 / Nessus ID 85256)
CVE-2012-5048 | Optimalog Optima PLC up to 1.4.10 resource management (EDB-18112 / SBV-36777)
亚洲最大的漫展,没有「AI 入侵」
亚洲最大的漫展,没有「AI 入侵」
Legal gaps in AI are a business risk, not just a compliance issue
A new report from Zendesk outlines a growing problem for companies rolling out AI tools: many aren’t ready to manage the risks. The AI Trust Report 2025 finds that while AI is moving into customer service and support, only 23% of companies feel highly prepared to govern it. The report highlights concerns ranging from data privacy to model bias. But the core challenge is trust: when customers don’t understand or feel comfortable with how AI … More →
The post Legal gaps in AI are a business risk, not just a compliance issue appeared first on Help Net Security.