Aggregator
CVE-2025-9288 | browserify sha.js up to 2.4.11 input validation (GHSA-95m3-7q98-8xr5 / EUVD-2025-25403)
CVE-2025-32379 | koajs koa up to 2.16.0/3.0.0-alpha.4 ctx.redirect cross site scripting (GHSA-x2rg-q646-7m2v / WID-SEC-2025-2424)
CVE-2025-45768 | jpadilla pyjwt 2.10.1 inadequate encryption (WID-SEC-2025-2424)
CVE-2025-53547 | Helm up to 3.18.3 code injection (GHSA-557j-xg8c-q2mm / EUVD-2025-20751)
CVE-2024-33531 | cdbattags lua-resty-jwt 0.2.3 Enc Header improper authentication (WID-SEC-2025-2424)
Active Directory at Risk Due to Domain-Join Account Misconfigurations
Active Directory domain join accounts are systematically exposing enterprise environments to compromise, even when administrators follow Microsoft’s official guidance. A comprehensive security analysis reveals that these specialized accounts inherit excessive privileges by default, creating a direct pathway for attackers to escalate access from internal networks to full domain control. During security assessments, domain join accounts […]
The post Active Directory at Risk Due to Domain-Join Account Misconfigurations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
"Грибной мозг" объявил войну кремнию: ученые создали мыслящие микросхемы из обычных шампиньонов
CVE-2025-12295 | D-Link DAP-2695 2.00RC13 Firmware Update sub_40C6B8 signature verification (WID-SEC-2025-2422)
CVE-2025-12296 | D-Link DAP-2695 2.00RC13 Firmware Update sub_4174B0 os command injection (WID-SEC-2025-2422)
FileFix + Cache Smuggling: A New Evasion Combo
Cybersecurity researchers have uncovered a sophisticated evolution in phishing attacks that combines FileFix social engineering with cache smuggling techniques to bypass modern security defenses. This hybrid attack method eliminates the need for malicious code to make web requests, instead extracting payloads directly from the browser’s cache where they were planted through cache smuggling. The technique […]
The post FileFix + Cache Smuggling: A New Evasion Combo appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.