Aggregator
Please support the site operations by clicking ads.
With Eyes on AI, African Orgs Push Security Awareness
1 year 2 months ago
Against the backdrop of the artificial intelligence surge, most African organizations have some form of cybersecurity awareness training but fail to test frequently and don't trust the results.
Robert Lemos, Contributing Writer
Beginner here — I want to learn both ethical and unethical hacking (for knowledge), can anyone share a roadmap?
1 year 2 months ago
文章描述了一位完全没有计算机科学背景的新手对网络、网络安全和黑客技术的兴趣,并寻求从零开始的学习路线图。作者希望全面理解攻击与防御,并询问了学习顺序、工具选择、资源推荐以及安全练习环境等问题。
CVE-2025-54642 | Huawei HarmonyOS/EMUI Kernel Gyroscope Module buffer overflow
1 year 2 months ago
A vulnerability, which was classified as critical, has been found in Huawei HarmonyOS and EMUI. Affected by this issue is some unknown functionality of the component Kernel Gyroscope Module. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2025-54642. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2025-54641 | Huawei HarmonyOS/EMUI Kernel Acceleration Module buffer overflow
1 year 2 months ago
A vulnerability classified as critical was found in Huawei HarmonyOS and EMUI. Affected by this vulnerability is an unknown functionality of the component Kernel Acceleration Module. The manipulation leads to buffer overflow.
This vulnerability is known as CVE-2025-54641. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2025-54640 | Huawei HarmonyOS 5.0.1/5.1.0 deserialization
1 year 2 months ago
A vulnerability classified as critical has been found in Huawei HarmonyOS 5.0.1/5.1.0. Affected is an unknown function. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2025-54640. An attack has to be approached locally. There is no exploit available.
vuldb.com
Wuestion about rats
1 year 2 months ago
一个开放的黑客社区,旨在帮助新手成长为资深地下技能掌握者。提供问答学习资源,并通过Discord平台促进交流与合作。
AI Is Transforming Cybersecurity Adversarial Testing - Pentera Founder’s Vision
1 year 2 months ago
文章探讨了AI如何重塑网络安全测试领域,通过自然语言驱动、实时适应和智能报告等功能,使渗透测试更加高效精准,并构建了一个基于API的架构以实现更灵活的攻击模拟。
AI Is Transforming Cybersecurity Adversarial Testing - Pentera Founder’s Vision
1 year 2 months ago
When Technology Resets the Playing Field
In 2015 I founded a cybersecurity testing software company with the belief that automated penetration testing was not only possible, but necessary. At the time, the idea was often met with skepticism, but today, with 1200+ of enterprise customers and thousands of users, that vision has proven itself. But I also know that what we’ve built so far is only
The Hacker News
CVE-2025-8573 | Concrete CMS up to 9.4.2 on Members Members Dashboard Page information disclosure
1 year 2 months ago
A vulnerability was found in Concrete CMS CMS up to 9.4.2 on Members. It has been rated as problematic. This issue affects some unknown processing of the component Members Dashboard Page. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2025-8573. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-54639 | Huawei HarmonyOS 5.0.1/5.1.0 deserialization
1 year 2 months ago
A vulnerability was found in Huawei HarmonyOS 5.0.1/5.1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-54639. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2025-21013 | Samsung Galaxy Watch SemSensorManager access control
1 year 2 months ago
A vulnerability was found in Samsung Galaxy Watch. It has been classified as critical. This affects an unknown part of the component SemSensorManager. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-21013. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2025-32430 | xwiki-platform up to 16.4.7/16.10.5/17.2.x cross site scripting (GHSA-m9x4-w7p9-mxhx)
1 year 2 months ago
A vulnerability was found in xwiki-platform up to 16.4.7/16.10.5/17.2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-32430. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-7399 | Betheme Plugin up to 28.1.3 on WordPress Setting cross site scripting
1 year 2 months ago
A vulnerability classified as problematic was found in Betheme Plugin up to 28.1.3 on WordPress. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-7399. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6994 | Reveal Listing Plugin up to 3.3 on WordPress listing_user_role privileges management
1 year 2 months ago
A vulnerability, which was classified as critical, has been found in Reveal Listing Plugin up to 3.3 on WordPress. Affected by this issue is some unknown functionality. The manipulation of the argument listing_user_role leads to improper privilege management.
This vulnerability is handled as CVE-2025-6994. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-7498 | Exclusive Addons for Elementor Plugin 2.7.9.4 on WordPress Countdown Widget cross site scripting
1 year 2 months ago
A vulnerability has been found in Exclusive Addons for Elementor Plugin 2.7.9.4 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Countdown Widget. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-7498. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Написано «соглашение» — ИИ читает как «выполнить скрипт». LegalPwn учит атаковать словами
1 year 2 months ago
Даже самые умные чат-боты капитулировали перед дебрями из непонятных формулировок.
CVE-2025-54876 | JanssenProject jans up to 1.9.0 cli_cmd.log insufficiently protected credentials (GHSA-2f4x-m695-jvp3)
1 year 2 months ago
A vulnerability has been found in JanssenProject jans up to 1.9.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file cli_cmd.log. The manipulation leads to insufficiently protected credentials.
This vulnerability is known as CVE-2025-54876. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-54125 | xwiki-platform up to 16.4.6/16.10.4/17.1.x templates/xml.vm exposure of private personal information to an unauthorized actor (GHSA-57q2-6cp4-9mq3)
1 year 2 months ago
A vulnerability, which was classified as problematic, was found in xwiki-platform up to 16.4.6/16.10.4/17.1.x. Affected is an unknown function of the file templates/xml.vm. The manipulation leads to exposure of private personal information to an unauthorized actor.
This vulnerability is traded as CVE-2025-54125. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
AI in the SOC: Game-changer or more noise?
1 year 2 months ago
In this Help Net Security video, Kev Marriott, Senior Manager of Cyber at Immersive Labs, explores the challenges and opportunities of integrating AI into Security Operations Centers (SOCs). While AI can boost productivity by automating manual tasks and reducing alert fatigue, Kev emphasizes that human expertise remains critical for contextual analysis, incident response, and threat hunting. He cautions against over-reliance on AI, highlights potential risks, including standardization, misconfigurations, and evolving threat actor tactics, and urges … More →
The post AI in the SOC: Game-changer or more noise? appeared first on Help Net Security.
Help Net Security