Aggregator
CVE-2022-49694 | Linux Kernel up to 5.18.7 del_gendisk use after free
CVE-2025-27500 | openziti ziti-console up to 3.7.0 /api/upload cross site scripting (GHSA-frxm-vm48-5qf2)
CVE-2025-27501 | openziti ziti-console up to 3.7.0 server-side request forgery (GHSA-fqxh-vfv5-8qjp)
CVE-2025-27643 | Vasion Print Virtual Appliance Host AWS API Key hard-coded key
CVE-2025-1891 | shishuocms 1.1 cross-site request forgery
CVE-2025-1892 | shishuocms 1.1 Directory Deletion Page /manage/folder/add.json folderName cross site scripting
Elastic Kibana 原型污染致任意代码执行漏洞(CVE-2025-25012)安全风险通告
Elastic Kibana 原型污染致任意代码执行漏洞(CVE-2025-25012)安全风险通告
Critical IDOR Vulnerabilities in ZITADEL Let Hackers Modify Key Settings
Security researchers have disclosed critical Insecure Direct Object Reference (IDOR) vulnerabilities in ZITADEL’s administration interface that expose organizations to account takeover risks and unauthorized configuration changes. Tracked as CVE-2025-27507 with a CVSS v3.1 score of 9.1/10, these flaws allow authenticated users without proper permissions to manipulate sensitive LDAP configurations and other critical instance settings. Vulnerability Overview The vulnerabilities reside […]
The post Critical IDOR Vulnerabilities in ZITADEL Let Hackers Modify Key Settings appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
【新品发布】赛宁网安大模型四件套重磅发布!
报告解读:ICS/OT 安全预算不断增加,但关键领域资金不足
BreachRx Brings Generative AI to Security Incident Management
BreachRx this week added generative artificial intelligence (GenAI) capabilities to a security incident platform that promises to streamline workflows across all the stakeholders that need to collaborate.
The post BreachRx Brings Generative AI to Security Incident Management appeared first on Security Boulevard.
Android App With 220,000+ Downloads From Google Play Installs Banking Trojan
A sophisticated Android banking trojan campaign leveraging a malicious file manager application accumulated over 220,000 downloads on the Google Play Store before its removal. Dubbed Anatsa (also known as TeaBot), the malware targets global financial institutions through a multi-stage infection process. It deploys fake login overlays and abuses accessibility services to steal credentials and execute […]
The post Android App With 220,000+ Downloads From Google Play Installs Banking Trojan appeared first on Cyber Security News.
LibreOffice Flaw Allows Attackers to Run Arbitrary Scripts via Macro URL
A significant security vulnerability in LibreOffice, designated as CVE-2025-1080, has been patched in versions 24.8.5 and 25.2.1, released on March 4, 2025. The flaw, which allowed attackers to execute arbitrary scripts through manipulated macro URLs, posed a severe risk to users of the open-source office suite. This vulnerability underscores the importance of prompt software updates […]
The post LibreOffice Flaw Allows Attackers to Run Arbitrary Scripts via Macro URL appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.