Aggregator
Weekly Threat Landscape Digest – Week 24
Date: Jun 13, 2025 – Week 24 This week’s threat landscape highlights the evolving sophistication of threat actors, who are […]
The post Weekly Threat Landscape Digest – Week 24 appeared first on HawkEye.
CVE-2000-0925 | Smartwin Technology Cyberoffice Shopping Cart 2.0 the _private privileges management (EDB-20248 / XFDB-5318)
Tenable Agent for Windows Vulnerability Let Attackers Login as Admin to Delete The System Files
Tenable, a prominent cybersecurity provider, has released version 10.8.5 of its Agent software to address three critical security vulnerabilities affecting Windows hosts running versions prior to 10.8.5. These flaws, identified as CVE-2025-36631, CVE-2025-36632, and CVE-2025-36633, could allow non-administrative users to exploit SYSTEM-level privileges, potentially leading to severe system compromise or local privilege escalation. Vulnerability Details […]
The post Tenable Agent for Windows Vulnerability Let Attackers Login as Admin to Delete The System Files appeared first on Cyber Security News.
Блокчейн + квантовая физика + паранойя = идеальный способ подкинуть монетку
CVE-2004-1925 | Tiki Tikiwiki 1.6.1/1.8.1 sql injection (EDB-43809 / Nessus ID 14364)
CVE-2007-3590 | b1g b1gBB 2.24 visitenkarte.php User cross site scripting (EDB-4122 / XFDB-35131)
NIST Released 19 Zero Trust Architecture Implementations Guide – What’s New
The National Institute of Standards and Technology (NIST) has published a new resource to aid organizations in implementing zero trust architectures (ZTAs), a cybersecurity approach that assumes no user or device is inherently trustworthy. The guidance, titled Implementing a Zero Trust Architecture (NIST SP 1800-35), details 19 example ZTA implementations using commercially available technologies, offering […]
The post NIST Released 19 Zero Trust Architecture Implementations Guide – What’s New appeared first on Cyber Security News.
CVE-2025-4200 | Zagg Plugin up to 1.4.1 on WordPress load_view file inclusion
CVE-2025-4187 | UserPro Plugin up to 5.1.10 on WordPress userpro_fbconnect path traversal
CVE-2025-6040 | Easy Flashcards Plugin up to 0.1 on WordPress Setting ef_settings_submenu cross-site request forgery
CVE-2025-5589 | StreamWeasels Kick Integration Plugin up to 1.1.3 on WordPress status-classic-offline-text cross site scripting
CVE-2025-5336 | Click to Chat Plugin up to 4.22 on WordPress data-no_number cross site scripting
Kali Linux 2025.2 delivers Bloodhound CE, CARsenal, 13 new tools
OffSec has released Kali Linux 2025.2, the most up-to-date version of the widely used penetration testing and digital forensics platform. KDE Plasma 6.3 in Kali Linux 2025.2 (Source: OffSec) New in Kali Linux 2025.2 As per usual, the newest Kali version comes with new community wallpapers and new versions of the KDE Plasma and GNOME graphical desktop environments. This time around, the Kali Menu is new, as well: it has been reorganized to follow the … More →
The post Kali Linux 2025.2 delivers Bloodhound CE, CARsenal, 13 new tools appeared first on Help Net Security.
CVE-2004-1924 | Tiki TikiWiki 1.6.1/1.8.1 cross site scripting (EDB-43809 / Nessus ID 14364)
中科院信工所 | 福尔摩斯与华生:通过HTTP版本并行性实现鲁棒轻量级的HTTPS网站指纹识别
Iranian Hacktivist Group Handala Claims Responsibility for Major Cyberattacks on Israeli Targets
You must login to view this content
CVE-2006-2211 | 321soft PhP-Gallery 0.9 index.php path path traversal (EDB-27803 / XFDB-26231)
Handala
You must login to view this content
Medusa Blog
You must login to view this content