Aggregator
Проверьте свой iPhone: утекшие файлы Apple доказали, что политика сильнее кода
《不要因为走得太远而忘记为什么出发》
算书评?
CVE-2024-12604 | Tapandsign Tap&Sign App prior 1.025 Environment Variable exposure of sensitive information through environmental variables
CVE-2024-11142 | Gosoft Proticaret E-Commerce up to 5.x cross-site request forgery
CVE-2025-1301 | Yordam Informatics Library Automation System up to 21.5 cross site scripting
CVE-2025-2421 | Profelis Informatics SambaBox up to 5.0 code injection
CVE-2024-8262 | Proliz OBS up to 24.926 path traversal
核心API未授权监控
How Everyday Apps Leak More Data Than You Realize
Most mobile apps silently leak personal data to third parties, even trusted ones. From trackers in Google Play apps to high-profile breaches like Strava and British Airways, app data leakage is a growing privacy risk. Learn why apps leak data and how to protect yourself.
The post How Everyday Apps Leak More Data Than You Realize appeared first on Security Boulevard.
UK train operator LNER (London North Eastern Railway) discloses a data breach
Malware Campaign Uses SVG Email Attachments to Deploy XWorm and Remcos RAT
Recent threat campaigns have revealed an evolving use of BAT-based loaders to deliver Remote Access Trojans (RATs), including XWorm and Remcos. These campaigns typically begin with a ZIP archive—often hosted on seemingly legitimate platforms such as ImgKit—designed to entice user interaction by mimicking benign content. Once opened, the archive unpacks a highly obfuscated BAT script […]
The post Malware Campaign Uses SVG Email Attachments to Deploy XWorm and Remcos RAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-7337 | GitLab Community Edition/Enterprise Edition up to 18.1.5/18.2.5/18.3.1 allocation of resources (Patch 554062 / EUVD-2025-29022)
CVE-2025-10340 | WhatCD Gazelle up to 63b337026d49b5cf63ce4be20fdabdc880112fa3 Commit Message change_log.php cross site scripting (EUVD-2025-29089)
Школьники — главные хакеры. Каждый пятый подросток совершал незаконные действия в сети
Addressing CISA Advisory on Rockwell Automation ThinManager SSRF Vulnerability (CVE-2025-9065)
Critical Security Alert: If you are an organization using Rockwell’s ThinManager software version 13.0 or below, you are vulnerable. If you cannot upgrade immediately, please scroll to the section on compensating controls below and contact our team without delay. On September 9, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a critical advisory […]
The post Addressing CISA Advisory on Rockwell Automation ThinManager SSRF Vulnerability (CVE-2025-9065) appeared first on ColorTokens.
The post Addressing CISA Advisory on Rockwell Automation ThinManager SSRF Vulnerability (CVE-2025-9065) appeared first on Security Boulevard.