Aggregator
CVE-2024-12258 | shivtiwari WP Service Payment Form With Authorize.net Plugin up to 2.6.3 on WordPress page cross site scripting
CVE-2024-12338 | websitetoolbox Website Toolbox Community Plugin up to 2.0.1 on WordPress websitetoolbox_username cross site scripting
XCSSET信息窃取恶意软件卷土重来,针对macOS用户和开发者
Cybercriminals Exploit Onerror Event in Image Tags to Deploy Payment Skimmers
LibreOffice Vulnerabilities Allow Attackers to Write to Files and Extract Data
Two critical vulnerabilities in LibreOffice (CVE-2024-12425 and CVE-2024-12426) expose millions of users to file system manipulation and sensitive data extraction attacks. These flaws affect both desktop users opening malicious documents and server-side systems using LibreOffice for headless document processing. CVE-2024-12425: Path Traversal Enables Arbitrary File Writes The first vulnerability stems from improper path sanitization when […]
The post LibreOffice Vulnerabilities Allow Attackers to Write to Files and Extract Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
美国国务院全球人员名单数据分析与战略意图研判
马斯克Grok 3接入X平台:一场没有硝烟的“数据战争”,我们将如何突围?
CVE-2002-1983 | QNX RTOS 6.1.0 Timer memory corruption (EDB-21984 / XFDB-10550)
Earth Preta APT Exploit Microsoft Utility Tool & Bypass AV Detection to Control Windows
Researchers from Trend Micro’s Threat Hunting team have uncovered a sophisticated cyberattack campaign by the advanced persistent threat (APT) group Earth Preta, also known as Mustang Panda. The group has been leveraging new techniques to infiltrate systems and evade detection, primarily targeting government entities in the Asia-Pacific region, including Taiwan, Vietnam, Malaysia, and Thailand. Earth […]
The post Earth Preta APT Exploit Microsoft Utility Tool & Bypass AV Detection to Control Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
お知らせ:制御システムセキュリティカンファレンス 2025 講演資料を公開
CVE-2024-11689 | caagsoftware HQ Rental Software Plugin up to 1.5.29 on WordPress Setting displaySettingsPage cross-site request forgery
ChatGPT Operator Prompt Injection Exploit Leaks Private Data
According to recent findings by cybersecurity researcher Johann Rehberger, OpenAI’s ChatGPT Operator, an experimental agent designed to automate web-based tasks, faces critical security risks from prompt injection attacks that could expose users’ private data. In a demonstration shared exclusively with OpenAI last month, Rehberger showcased how malicious actors could hijack the AI agent to extract […]
The post ChatGPT Operator Prompt Injection Exploit Leaks Private Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-11901 | cyberlord92 PowerBI Embed Reports Plugin up to 1.1.7 on WordPress Shortcode MO_API_POWER_BI cross site scripting
Cybersecurity jobs available right now: February 18, 2025
Airport Cybersecurity Engineer II Salt Lake City Corporation | USA | On-site – View job details As an Airport Cybersecurity Engineer II, you will develop and implement policies, procedures, and training plans for security and network administration. Assess and mitigate cybersecurity threats. Manage incident response and recovery plans. Application Security Architect WalkMe | Israel | Hybrid – View job details As an Application Security Architect, you will conduct design and code reviews to ensure secure … More →
The post Cybersecurity jobs available right now: February 18, 2025 appeared first on Help Net Security.