Aggregator
CVE-2025-64489 | SuiteCRM up to 7.14.7/8.9.0 Deactivation privileges management (GHSA-j6jg-9jj3-q2ph / EUVD-2025-38349)
CVE-2025-64490 | SuiteCRM up to 7.14.7/8.9.0 Related authorization (GHSA-jh8v-wqgj-hhc2 / EUVD-2025-38348)
CVE-2025-64491 | SuiteCRM up to 7.14.7 cross site scripting (GHSA-prfm-6667-x3mv / WID-SEC-2025-2516)
CVE-2025-12727 | Google Chrome up to 142.0.7444.59 V8 out-of-bounds write (Nessus ID 274070 / WID-SEC-2025-2491)
朱文雷:AI Secure Coding赋能网络安全学科建设新路
ClickFix攻击借仿冒Windows更新界面推送恶意软件
ClickFix攻击借仿冒Windows更新界面推送恶意软件
朱文雷:AI Secure Coding赋能网络安全学科建设新路
Your critical infrastructure is running out of time
Cyber attackers often succeed not because they are inventive, but because the systems they target are old. A new report by Cisco shows how unsupported technology inside national infrastructure creates openings that attackers can exploit repeatedly. The findings show how widespread this problem has become and how much it influences national resilience. A growing problem that is hard to ignore Nearly half of global business network assets were already ageing or obsolete as far back … More →
The post Your critical infrastructure is running out of time appeared first on Help Net Security.
ZDI-CAN-28558: Foxit
ZDI-CAN-28570: pdfforge
ZDI-CAN-28044: VMware
China Software Developer Network - 6,414,990 breached accounts
New Malware-as-a-Service Olymp Loader Advertised on Hacker Forums with It’s Anti-analysis and Detection Features
A new Malware-as-a-Service (MaaS) threat named “Olymp Loader” appeared in June 2025, aggressively advertised on underground hacker forums like XSS and HackForums. Advertised by an operator known as “OLYMPO,” this malware is marketed as a sophisticated tool written entirely in Assembly language. This marketing strategy aims to attract cybercriminals by claiming high performance and resistance […]
The post New Malware-as-a-Service Olymp Loader Advertised on Hacker Forums with It’s Anti-analysis and Detection Features appeared first on Cyber Security News.