Aggregator
CVE-2025-8324 | Zoho ManageEngine Analytics Plus 4.3.5/4350/5410/6100/6130 Filter Configuration sql injection
CVE-2025-11862 | Rockwell Automation Verve Asset Manager up to 1.41.3 API authorization
CVE-2025-11085 | Rockwell Automation FactoryTalk DataMosaix Private Cloud 7.11/8.00 cross site scripting
CVE-2025-9223 | Zoho ManageEngine Applications Manager up to 15200 Configuration command injection
CVE-2025-41106 | Fairsketch RISE CRM Framework up to 3.8 POST Request /clients/save_contact/ first_name cross site scripting
CVE-2025-11084 | Rockwell Automation FactoryTalk DataMosaix Private Cloud 7.11/8.00/8.01 MFA weak authentication
CVE-2025-41105 | Fairsketch RISE CRM Framework up to 3.8 POST Request /tickets/save Title cross site scripting
CVE-2025-41104 | Fairsketch RISE CRM Framework up to 3.8 POST Request save_estimate_request custom_field_1 cross site scripting
CVE-2025-41103 | Fairsketch RISE CRM Framework up to 3.8 POST Request /messages/reply reply_message cross site scripting
CVE-2025-10161 | Turkguven Perfektive prior 12574 Build 2701 excessive authentication
Weaponized NuGet Packages Inject Time-Delayed Destructive Payloads to Attack ICS Systems
A sophisticated supply chain attack has emerged, targeting industrial control systems through compromised .NET packages. The threat landscape shifted on November 5, 2025, when researchers identified nine malicious NuGet packages designed to inject destructive payloads into critical infrastructure environments. Published under the NuGet alias shanhai666 between 2023 and 2024, these packages accumulated nearly 9,500 downloads […]
The post Weaponized NuGet Packages Inject Time-Delayed Destructive Payloads to Attack ICS Systems appeared first on Cyber Security News.
Zoom Workplace for Windows Flaw Allows Local Privilege Escalation
A security vulnerability has been discovered in Zoom Workplace’s VDI Client for Windows that could allow attackers to escalate their privileges on affected systems. The flaw, tracked as CVE-2025-64740 and assigned bulletin ZSB-25042, has been rated as High severity with a CVSS score of 7.5. Attribute Details CVE ID CVE-2025-64740 Bulletin ID ZSB-25042 Product Zoom Workplace VDI […]
The post Zoom Workplace for Windows Flaw Allows Local Privilege Escalation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
К 2030 году ИТ-специалисты станут "когнитивным усилителем" для машины. Отныне наша главная роль — быть эмоциональным саппортом для алгоритма
Stop Open Source Malware at the Gate with Repository Firewall
Open source components form the backbone of innovation, but they also introduce significant security risks.
The post Stop Open Source Malware at the Gate with Repository Firewall appeared first on Security Boulevard.
WinRAR Vulnerability Exploited by APT-C-08 to Target Government Agencies
The notorious APT-C-08 hacking group, also known as BITTER, has been observed weaponizing a critical WinRAR directory traversal vulnerability (CVE-2025-6218) to launch sophisticated attacks against government organizations across South Asia. This development marks a concerning evolution in the threat actor’s capabilities, as the group leverages this easily exploitable flaw to infiltrate sensitive systems and steal classified […]
The post WinRAR Vulnerability Exploited by APT-C-08 to Target Government Agencies appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege
A security vulnerability has been discovered in Zoom Workplace VDI Client for Windows that could allow attackers to gain elevated privileges on affected systems. The flaw, tracked as CVE-2025-64740, has been assigned a high severity rating with a CVSS score of 7.5, according to Zoom’s security bulletin ZSB-25042. The vulnerability stems from improper verification of […]
The post Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege appeared first on Cyber Security News.
Devolutions Server Vulnerability Let Attackers Impersonate Users Using Pre-MFA Cookie
A critical vulnerability in Devolutions Server could allow attackers with low-level access to impersonate other user accounts by exploiting how the application handles authentication cookies before multi-factor authentication is completed. The security flaw, tracked as CVE-2025-12485, stems from improper privilege management during pre-MFA cookie handling. When users log in to Devolutions Server, the application generates temporary […]
The post Devolutions Server Vulnerability Let Attackers Impersonate Users Using Pre-MFA Cookie appeared first on Cyber Security News.
GNU Coreutils 9.9 brings fixes and updates across essential tools
GNU Coreutils is the backbone of many enterprise Linux environments. It provides the basic file, shell, and text utilities that every GNU-based system depends on. The latest release, version 9.9, refines these tools with fixes and performance improvements. Several long-standing issues have been resolved. The basenc --base58 command now works properly with large inputs, correcting a bug introduced in version 9.8. The cksum utility improves support for base64 encoded input and tagged formats used with … More →
The post GNU Coreutils 9.9 brings fixes and updates across essential tools appeared first on Help Net Security.