Aggregator
CVE-2025-13115 | macrozheng mall-swarm/mall up to 1.0.3 Order Details /order/detail/ detail orderId improper authorization (EUVD-2025-169290)
Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents
Since its release in October, Battlefield 6 has become one of the year’s most anticipated game launches. However, cybercriminals have quickly seized on this popularity to distribute malicious software. Attackers have created fake cracked versions of the game and fraudulent game trainers, spreading them across torrent websites and underground forums to target unsuspecting players and […]
The post Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents appeared first on Cyber Security News.
浏览器扩展合集:实用而有趣的浏览器扩展,我们又为你找到了这 7 款
Бургеры, «хрущевка» и Cybertruck. Илон Маск и Джефф Безос «посидели» в обычной квартире (на самом деле это сделала новая нейросеть Google)
CVE-2025-12758 | Validator up to 13.15.21 isLength incomplete filtering of one or more instances of special elements (SNYK-JS-VALIDATOR-13653476 / EUVD-2025-199795)
CVE-2025-12123 | Customer Reviews Collector for WooCommerce Plugin up to 4.6.1 on WordPress text cross site scripting (EUVD-2025-199793)
CVE-2025-13143 | Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin disconnect_account_action cross-site request forgery (EUVD-2025-199791)
CVE-2025-12185 | StaffList Plugin up to 3.2.6 on WordPress Admin Setting cross site scripting (EUVD-2025-199794)
CVE-2025-13525 | WP Directory Kit Plugin up to 1.4.5 on WordPress order_by cross site scripting (EUVD-2025-199792)
CVE-2025-13762 | CyberArk Secure Web Sessions Extension prior 2.2.30305 on Chrome denial of service (EUVD-2025-199782)
中国药企走向全球
CVE-2023-27922 | Stefano Lissa Newsletter Plugin up to 7.6.8 on WordPress cross site scripting (EUVD-2023-31648)
CVE-2023-27920 | SolarView Compact SV-CPT-MC310/Compact SV-CPT-MC310F up to 8.9 Date Setting access control (EUVD-2023-31646)
CVE-2023-27921 | Jins Meme Core up to 2.2.0 hard-coded key (EUVD-2023-31647)
CVE-2023-27919 | NEXT ENGINE Integration Plugin 2.0 on EC-CUBE improper authentication (EUVD-2023-31645)
攻击链贯穿端边云!边缘网络访问三大核心风险预警
中央网信办召开优化营商网络环境工作经验总结交流会;小模型能否扛起钓鱼网站识别大旗?| 牛览
Threat Actors Allegedly Listed iOS 26 Full‑Chain 0‑Day Exploit on Dark Web
A threat actor operating under the alias ResearcherX has posted what they claim to be a full‑chain zero‑day exploit targeting Apple’s recently released iOS 26 operating system. The listing, which appeared on a prominent dark web marketplace, alleges that the exploit leverages a critical memory‑corruption vulnerability within the iOS Message Parser. If proven genuine, this […]
The post Threat Actors Allegedly Listed iOS 26 Full‑Chain 0‑Day Exploit on Dark Web appeared first on Cyber Security News.