Aggregator
CVE-2024-48705 | Wavlink AC1200 M32A3_V1410_230602/M32A3_V1410_240222 adm.cgi set_sys_adm newpass command injection
CVE-2025-50757 | Wavlink WN535K3 20191010 set_sys_adm Username command injection
CVE-2025-50755 | Wavlink WN535K3 20191010 set_sys_cmd command command injection
CVE-2025-54599 | Bevy Event Service up to 2025-07-22 privilege escalation
CVE-2025-57616 | rust-ffmpeg up to 0.3.0 Data Structure write_interleaved use after free (Issue 192)
CVE-2025-57615 | rust-ffmpeg 0.3.0 sws_allocVec usize null pointer dereference (Issue 192)
CVE-2025-57614 | rust-ffmpeg 0.3.0 Dimension Parameter denial of service (Issue 192)
CVE-2025-57613 | rust-ffmpeg 0.3.0 avio_alloc_context null pointer dereference (Issue 192)
CVE-2025-57612 | rust-ffmpeg 0.3.0 av_get_sample_fmt_name null pointer dereference (Issue 192)
CVE-2025-57611 | rust-ffmpeg 0.3.0 avfilter_graph_dump null pointer dereference (Issue 192)
INC
You must login to view this content
Stop Panicking: The FIDO ‘Bypass’ That Never Actually Bypassed FIDO
The cybersecurity world exploded in August 2025 when SquareX dropped a bombshell at Black Hat USA: passkeys were “pwned.” Headlines screamed. Twitter erupted. CTOs panicked. But here’s what actually happened: absolutely nothing changed about FIDO’s security. The Anatomy of a Media Meltdown SquareX’s presentation, “Passkeys Pwned: Turning WebAuthn Against Itself,” sent shockwaves through enterprise security..
The post Stop Panicking: The FIDO ‘Bypass’ That Never Actually Bypassed FIDO appeared first on Security Boulevard.
DieNet Targeted the Website of Shaare Zedek Medical Center
Salesloft Drift Attacks Exposed Zscaler Customer Data
Threat researchers report that "a widespread data theft campaign" traces to attackers stealing OAuth access tokens for applications integrated with Salesloft's AI chatbot Drift, then exfiltrating data. Victims include Salesforce customers Zscaler and Palo Alto Networks.
Место удара: установлено. Орудие: Солнце. Цель: всё, что выше атмосферы
IOC Alert: Suspicious Crypto Wallet Domain Used for Payload Delivery – ashigaruwallet[.]rs
How IOC Feeds Streamline Incident Response and Threat Hunting for Best SOC Teams
When you’re in a SOC, speed is everything. The earlier you detect and confirm an intrusion, the faster you can contain it, and the less damage it does to your organization. But raw indicators of compromise (IOCs) like hashes, IPs, or domains often fall short on their own. They raise a flag, but without context, […]
The post How IOC Feeds Streamline Incident Response and Threat Hunting for Best SOC Teams appeared first on Cyber Security News.