Aggregator
CVE-2024-10581 | designinvento DirectoryPress Frontend Plugin up to 2.7.9 on WordPress dpfl_listingStatusChange cross-site request forgery
CVE-2025-0822 | bitpressadmin Chat Widget Plugin up to 1.5.2 on WordPress fileID path traversal
CVE-2024-13834 | cyberchimps Responsive Plus Plugin up to 3.1.4 on WordPress Setting remote_request server-side request forgery
CVE-2024-40982 | Linux Kernel up to 6.6.35/6.9.6 ssb_device_uevent null pointer dereference (c5dc2d8eb398/7d43c8377c6f/789c17185fb0 / Nessus ID 214739)
Australia bans Kaspersky over national security concerns
IT/OT Convergence Fuels Manufacturing Cyber Incidents
Lynx
Lynx
Smart Bed Security Flaw Lets Hackers Access Other Network Devices
A security researcher has uncovered critical vulnerabilities in Eight Sleep’s internet-connected smart beds, revealing exposed Amazon Web Services (AWS) credentials, remote SSH backdoors, and potential access to users’ entire home networks. The findings underscore growing concerns about IoT device security as consumers increasingly adopt connected appliances for everyday use. Researcher Discovers AWS Keys and Remote […]
The post Smart Bed Security Flaw Lets Hackers Access Other Network Devices appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CodeQL 企业级应用范式:GitHub 安全建设超大规模代码审计体系剖析
CodeQL 企业级应用范式:GitHub 安全建设超大规模代码审计体系剖析
A data leak exposes the operations of the Chinese private firm TopSec, which provides Censorship-as-a-Service
Massive botnet hits Microsoft 365 accounts
A recently discovered botnet of over 130,000 compromised devices is launching coordinated password-spraying attacks against Microsoft 365 (M365) accounts. Security researchers at SecurityScorecard are examining possible connections to China-affiliated threat actors, citing evidence of infrastructure linked to CDS Global Cloud and UCLOUD HK, which have operational ties to China. The attack utilizes command-and-control (C2) servers hosted by SharkTech, a U.S.-based provider previously identified for hosting malicious activity. “These findings from our STRIKE Threat Intelligence team … More →
The post Massive botnet hits Microsoft 365 accounts appeared first on Help Net Security.