Aggregator
CVE-2025-10771 | jeecgboot JimuReport up to 2.1.2 DB2 JDBC testConnection clientRerouteServerListJNDIName deserialization (Issue 4117 / EUVD-2025-30382)
CVE-2025-10770 | jeecgboot JimuReport up to 2.1.2 MySQL JDBC testConnection deserialization (Issue 4116 / EUVD-2025-30383)
CVE-2025-10769 | h2oai h2o-3 up to 3.46.08 H2 JDBC Driver /99/ImportSQLTable connection_url deserialization (Issue 51 / EUVD-2025-30378)
CVE-2025-10768 | h2oai h2o-3 up to 3.46.08 IBMDB2 JDBC Driver /99/ImportSQLTable connection_url deserialization (Issue 50 / EUVD-2025-30379)
Submit #649793: h2oai h2o-3 3.46.0.7 Deserialization [Duplicate]
Submit #649778: jeecgboot jimureport ≤ v2.1.2 Deserialization [Accepted]
Submit #649755: jeecgboot jimureport ≤ v2.1.2 Deserialization [Accepted]
Submit #649728: h2oai h2o-3 <=v3.46.08 Deserialization [Accepted]
Submit #649508: h2oai h2o-3 <=v3.46.08 Deserialization [Accepted]
CVE-2025-10767 | CosmodiumCS OnlyRAT up to 3.2 Configuration File main.py connect/remote_upload/remote_download configuration["PASSWORD"] os command injection (EUVD-2025-30384)
Submit #648118: CosmodiumCS OnlyRAT Latest version available OS Command Injection [Accepted]
CVE-2025-40925 | Bluefeet Starch up to 0.14 Default Session ID Generator rand generation of predictable numbers or identifiers (EUVD-2025-30364)
18% атак, 100% паралич бизнеса. Xакеры научились убивать ваш «чёрный день» — атакуя резервные копии.
K17 CTF
Date: Sept. 19, 2025, 8 a.m. — 21 Sept. 2025, 08:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.secso.cc/
Rating weight: 24.82
Event organizers: K17
CDCTF 2025
Date: Sept. 20, 2025, 3 p.m. — 21 Sept. 2025, 03:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://uacrimsondefense.github.io/cdctf.html
Rating weight: 25.00
Event organizers: Crimson Defense
Week in review: Chrome 0-day fixed, npm supply chain attack, LinkedIn data used for AI
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Most enterprise AI use is invisible to security teams Most enterprise AI activity is happening without the knowledge of IT and security teams. According to Lanai, 89% of AI use inside organizations goes unseen, creating risks around data privacy, compliance, and governance. Arkime: Open-source network analysis and packet capture system Arkime is an open-source system for large-scale network analysis and … More →
The post Week in review: Chrome 0-day fixed, npm supply chain attack, LinkedIn data used for AI appeared first on Help Net Security.
Steps to Achieve Enterprise Readiness for Software
A detailed guide for CTOs and VP of Engineering on achieving enterprise readiness for software, covering security, scalability, compliance, and integration.
The post Steps to Achieve Enterprise Readiness for Software appeared first on Security Boulevard.
Vulnerability Management and Remediation Solutions
Explore vulnerability management and remediation solutions for enterprise SSO and CIAM. Learn to protect your systems from cyber threats with effective strategies.
The post Vulnerability Management and Remediation Solutions appeared first on Security Boulevard.