Aggregator
CVE-2025-9201 | Lenovo Browser 5.1.110.5082 uncontrolled search path
CVE-2025-55319 | Microsoft Visual Studio Code 1.99.1 Agentic AI command injection (EUVD-2025-29000)
CVE-2025-59055 | instantsoft icms2 up to 2.17.3 HTTPS Request package server-side request forgery (GHSA-79hh-mhvg-whrw)
CVE-2025-9319 | Lenovo Wallpaper Client up to 3.0.70.3301 code download
CVE-2025-9214 | Lenovo LJ2206W Printer prior 1.05 CUPS Service missing authentication
CVE-2025-8061 | Lenovo Dispatcher Driver 3.0/3.1 exposed ioctl with insufficient access control
CVE-2025-56556 | Subrion CMS 4.2.1 SQL Query Feature authorization bypass through user-controlled sql primary key (Issue 913)
CVE-2025-58754 | Axios up to 1.11.x allocation of resources (GHSA-4hjh-wcwx-xvwj / EUVD-2025-28992)
CVE-2025-43789 | Liferay Portal/DXP JSON Web Service authorization (WID-SEC-2025-2041)
CVE-2025-10127 | Daikin Security Gateway password recovery (icsa-25-254-10)
CVE-2025-8557 | Lenovo XClarity Orchestrator up to 2.1.x LXCO API Service unprotected alternate channel
CVE-2025-43788 | Liferay Portal/DXP Organization Selector authorization (EUVD-2025-29005 / WID-SEC-2025-2041)
CVE-2025-10094 | GitLab Community Edition/Enterprise Edition up to 18.1.5/18.2.5/18.3.1 Token improper validation of specified quantity in input (Patch 528469 / EUVD-2025-29016)
CVE-2025-36222 | IBM Fusion/Fusion HCI/Fusion HCI for Watsonx up to 2.10.1 insecure default initialization of resource
Vimeo 以 13.8 亿美元出售给 Bending Spoons
AMD, Intel и все облачные провайдеры. Уязвимость в популярных процессорах ставит под угрозу безопасность виртуальных машин по всему миру.
CISOs brace for a new kind of AI chaos
AI is being added to business processes faster than it is being secured, creating a wide gap that attackers are already exploiting, according to the SANS Institute. The scale of the problem Attackers are using AI to work at speeds that humans cannot match. Phishing messages are more convincing, privilege escalation happens faster, and automated scripts can adjust mid-attack to avoid detection. The report highlights research showing that AI-driven attacks can move more than 40 … More →
The post CISOs brace for a new kind of AI chaos appeared first on Help Net Security.
Attackers are coming for drug formulas and patient data
In the pharmaceutical industry, clinical trial data, patient records, and proprietary drug formulas are prime targets for cybercriminals. These high-value assets make the sector a constant focus for attacks. Disruptions to research or medicine distribution can have life-threatening consequences. “During global health crises, cyber attackers swiftly exploit vulnerabilities. The COVID-19 pandemic saw a fivefold increase in phishing attempts targeting WHO, with attackers impersonating leadership to distribute malware,” said Flavio Aggio, CISO at the World Health … More →
The post Attackers are coming for drug formulas and patient data appeared first on Help Net Security.