Aggregator
Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution
A newly disclosed path traversal vulnerability (CVE-2024-4885) in Progress Software’s WhatsUp Gold network monitoring solution has raised alarms across the cybersecurity community. Rated as critical, this flaw enables unauthenticated attackers to execute arbitrary code on affected systems by exploiting improper input validation in file path handling mechanisms. The vulnerability, classified under CWE-22 (Improper Limitation of […]
The post Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Why a push for encryption backdoors is a global security risk
Governments in the UK, US, and Europe are pressuring tech companies to weaken encryption in the name of security. The latest push from the UK government demanding Apple create a backdoor to encrypted iCloud data is just one example, one that should alarm privacy advocates, businesses, and governments. In this Help Net Security video, professor Nigel Smart, Chief Academic Officer at Zama and a leading expert in cryptography, warns that these measures don’t just threaten … More →
The post Why a push for encryption backdoors is a global security risk appeared first on Help Net Security.
ASP.NET下Webshell编译产物免杀
CVE-2025-26378 | Nozomi Q-Free MaxTime up to 2.11.0 HTTP routes.lua authorization
CVE-2025-26376 | Nozomi Q-Free MaxTime up to 2.11.0 HTTP routes.lua authorization
CVE-2025-25766 | MRCMS 3.1.2 /file/savefile.do unrestricted upload
CVE-2025-25765 | MRCMS 3.1.2 /file/save.do
CVE-2025-1786 | rizinorg rizin up to 0.7.4 /librz/bin/pdb/pdb.c msf_stream_directory_free -P buffer overflow (Issue 4893)
CVE-2025-1788 | rizinorg rizin up to 0.8.0 /librz/util/utf8.c rz_utf8_encode heap-based overflow (Issue 4910)
CVE-2017-2469 | Apple iOS up to 10.2 WebKit memory corruption (HT207617 / EDB-41869)
Cybersecurity jobs available right now: March 4, 2025
Application Security Engineer Via | Israel | Hybrid – View job details As a Application Security Engineer, you will perform security assessments, including penetration testing, vulnerability scanning, and code reviews, to identify security weaknesses in applications. Define and implement application security testing strategies, including static analysis, dynamic analysis, and software composition analysis. Cloud Security Architect Kinaxis | Canada | Hybrid – View job details As a Cloud Security Architect, you will lead and participate in … More →
The post Cybersecurity jobs available right now: March 4, 2025 appeared first on Help Net Security.
The Hidden Trap in the PCI DSS SAQ A Changes
CISA Alerts on Active Exploitation of Cisco Small Business Router Flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March 3, 2025, about actively exploiting a critical command injection vulnerability (CVE-2023-20118) affecting end-of-life Cisco Small Business RV Series Routers. The flaw, which carries a CVSSv3.1 score of 6.5, enables authenticated attackers to execute arbitrary commands with root privileges, potentially compromising entire […]
The post CISA Alerts on Active Exploitation of Cisco Small Business Router Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
We're Backfilling and Cleaning Stealer Logs in Have I Been Pwned
I think I've finally caught my breath after dealing with those 23 billion rows of stealer logs last week. That was a bit intense, as is usually the way after any large incident goes into HIBP. But the confusing nature of stealer logs coupled with an overtly long