Aggregator
CVE-2024-56524 | Radware Cloud Web Application Firewall Special Character access control (VU#722229 / EUVD-2025-14309)
CVE-2024-56523 | Radware Cloud Web Application Firewall HTTP GET Request access control (VU#722229 / EUVD-2025-14310)
CVE-2025-26841 | WPEVEREST Everest Forms up to 3.0.8 File Upload cross site scripting (EUVD-2025-14307)
CVE-2025-2141 | IBM System Storage Virtualization Engine TS7700 8.54.2.17/8.60.0.115/8.60.0.115 cross site scripting (EUVD-2025-19624)
CVE-2025-36056 | IBM System Storage Virtualization Engine TS7700 8.54.2.17/8.60.0.115/8.60.0.115 Web UI cross site scripting (EUVD-2025-19623)
CVE-2025-53003 | JanssenProject jans up to 1.7.x Config API information disclosure (ID 11575 / EUVD-2025-19625)
CVE-2024-23928 | Pioneer DMH-WT7600NEX Telematics certificate validation (ZDI-24-1045 / EUVD-2024-21358)
CVE-2024-23929 | Pioneer DMH-WT7600NEX Telematics path traversal (ZDI-24-1044 / EUVD-2024-21359)
CVE-2024-23937 | Silicon Labs Gecko OS Debug Interface format string (EUVD-2024-21367)
谷歌推出Chrome紧急更新v138.0.7204.97修复已经被黑客利用的高危漏洞
12306 余票监控工具:支持 飞书、企业微信、Bark推送、Telegram、Email 通知[Windows]
Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines
The notorious North Korean threat group Kimsuky has adopted a sophisticated social engineering tactic known as “ClickFix” to deceive users into executing malicious scripts on their own systems. Originally introduced by Proofpoint researchers in April 2024, this deceptive technique tricks victims into believing they need to troubleshoot browser errors or verify security documents, ultimately leading […]
The post Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines appeared first on Cyber Security News.
AI 上新|这个应用,让苏格拉底和尼采手把手教我「哲学」
AI 上新|这个应用,让苏格拉底和尼采手把手教我「哲学」
Stealthy WordPress Malware Uncovered: Multi-Stage RAT Injects via Header.php, Hides Traces
Cybercriminals have launched a new wave of attacks targeting WordPress websites—so meticulously concealed that the campaign was only recently uncovered. Security experts at Sucuri have discovered that compromised websites are being used as silent...
The post Stealthy WordPress Malware Uncovered: Multi-Stage RAT Injects via Header.php, Hides Traces appeared first on Penetration Testing Tools.
Scammers are tricking travelers into booking trips that don’t exist
Not long ago, travelers worried about bad weather. Now, they’re worried the rental they booked doesn’t even exist. With AI-generated photos and fake reviews, scammers are creating fake listings so convincing, people are losing money before they even pack a bag. The FTC reported that Americans lost $274 million to vacation and travel fraud in 2024. Why travelers fall for it Travel is expensive and people are doing everything they can to find cheaper deals. … More →
The post Scammers are tricking travelers into booking trips that don’t exist appeared first on Help Net Security.
Feds: $14.6 Billion in Healthcare Fraud Busted in Takedown
The Department of Justice in collaboration with the Department of Health and Human Services and other agencies said it has busted $14.6 billion in a wide range of healthcare fraud in 2025. The feds say a new "fusion center" using AI and other technologies will improve investigations moving forward.
'Skynet' Tries to Outwit AI Malware Analysis
If you can't outsmart the antivirus, maybe you can sweet-talk the algorithm into looking the other way. Security researchers discovered what appears to be the first known attempt to deploy prompt injection against artificial intelligence-powered malware analysis.
Senate Strips AI Moratorium Amid Sharp Bipartisan Opposition
Senate Republicans removed a state moratorium on artificial intelligence regulations from its version of President Donald Trump's "big, beautiful bill" following bipartisan warnings the component could risk data privacy and civil rights - particularly without a strong federal regulatory framework.