Aggregator
CVE-2025-20649 | MediaTek MT7961 Bluetooth Stack SW insufficient permissions or privileges (MSV-2184)
CVE-2025-20646 | MediaTek MT6890/MT7915/MT7916/MT7981/MT7986 WLAN AP FW out-of-bounds write (MSV-1803)
CVE-2025-20648 | MediaTek MT8678 Apu out-of-bounds (MSV-2584 / ALPS09456673)
CVE-2025-20645 | MediaTek MT8796 KeyInstall out-of-bounds write (MSV-2599 / ALPS09475476)
CVE-2025-20651 | MediaTek MT8678 Da out-of-bounds (MSV-2062 / ALPS09291294)
CVE-2025-20650 | MediaTek MT8678 Da out-of-bounds write (MSV-2061 / ALPS09291294)
CVE-2025-1844 | ESAFENET CDG 5.6.3.154.205_20250114 backupLogDetail.jsp logTaskId sql injection
CVE-2025-1845 | ESAFENET DSM 3.1.2 examExportPDF s command injection
Fog
Fog
Abyss
Apache Derby Vulnerability Let Attackers Bypass Authentication with LDAP Injection
A critical security vulnerability (CVE-2022-46337) in Apache Derby, an open-source relational database implemented entirely in Java, has exposed systems to authentication bypass attacks via LDAP injection. The flaw, rated with a CVSS score of 9.1, enables attackers to craft malicious usernames that circumvent LDAP authentication checks, potentially granting unauthorized access to sensitive data and database […]
The post Apache Derby Vulnerability Let Attackers Bypass Authentication with LDAP Injection appeared first on Cyber Security News.
近1.2万API密钥通过AI训练数据集被泄露;Vo1d僵尸网络蔓延,160万安卓电视设备沦为肉鸡 | 牛览
Hackers Using PowerShell and Microsoft Legitimate Apps to Deploy Malware
Cybersecurity experts are warning of an increasing trend in fileless attacks, where hackers leverage PowerShell and legitimate Microsoft applications to deploy malware without leaving significant traces on compromised systems. These sophisticated attacks, which have been around for over two decades, are proving particularly effective in bypassing traditional antivirus solutions and complicating incident response efforts. PowerShell […]
The post Hackers Using PowerShell and Microsoft Legitimate Apps to Deploy Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.