Aggregator
Weekly Threat Landscape Digest – Week 32
This week’s cybersecurity overview reflects an evolving threat environment marked by new vulnerability disclosures, exploitation of existing weaknesses, and persistent […]
The post Weekly Threat Landscape Digest – Week 32 appeared first on HawkEye.
CVE-2025-8755 | macrozheng mall up to 1.0.3 com.macro.mall.portal.controller UmsMemberController.java detail orderId authorization (EUVD-2025-24050)
CVE-2020-9322 | Statamic Core up to 2.11.7 /users cross site scripting (EUVD-2020-30143)
CVE-2025-36119 | IBM i 7.3/7.4/7.5/7.6 Digital Certificate Manager for i authentication spoofing (EUVD-2025-23989)
Submit #624046: macrozheng mall 1.0.3 Missing Authorization [Accepted]
Submit #623902: A Java cms with SQL injection exists https://github.com/miansen/Roothub/tree/v2.5 2.5 SQL Injection [Duplicate]
CVE-2021-33096 | Intel 82599 Ethernet Controller denial of service (intel-sa-00571 / Nessus ID 245557)
CVE-2023-0136 | Google Chrome up to 108.0.5359.124 Fullscreen API Remote Code Execution (EUVD-2023-12226 / Nessus ID 245555)
CVE-2021-20292 | Linux Kernel up to 5.8 Nouveau DRM Subsystem nouveau_sgdma.c nouveau_sgdma_create_ttm use after free (Nessus ID 245558)
CVE-2021-46958 | Linux Kernel up to 5.10.35/5.11.19/5.12/5.12.2 btrfs /dev/mapper/error-test btrfs_sync_log use after free (Nessus ID 245559)
CVE-2023-2006 | Linux Kernel RxRPC race condition (Nessus ID 245560)
«Вымогатели неуязвимы?» Операция Checkmate разобрала BlackSuit по винтикам.
CVE-2023-41525 | Hospital Management System 4 patientsearch.php patient_contact sql injection
CVE-2023-41526 | Hospital Management System 4 func1.php password3 sql injection
BSidesSF 2025: Using AI To Discover Silently Patched Vulnerabilities In Open Source
Creator/Author/Presenter: Mackenzie Jackson
Our deep appreciation to Security BSides - San Francisco and the Creators/Authors/Presenters for publishing their BSidesSF 2025 video content on YouTube. Originating from the conference’s events held at the lauded CityView / AMC Metreon - certainly a venue like no other; and via the organization's YouTube channel.
Additionally, the organization is welcoming volunteers for the BSidesSF Volunteer Force, as well as their Program Team & Operations roles. See their succinct BSidesSF 'Work With Us' page, in which, the appropriate information is to be had!
The post BSidesSF 2025: Using AI To Discover Silently Patched Vulnerabilities In Open Source appeared first on Security Boulevard.
Research reveals possible privacy gaps in Apple Intelligence’s data handling
LAS VEGAS — One of the big worries during the generative AI boom is where exactly data is traveling when users enter queries or commands into the system. According to new research, those worries may also extend to one of the world’s most popular consumer technology companies. Apple’s artificial intelligence ecosystem, known as Apple Intelligence, […]
The post Research reveals possible privacy gaps in Apple Intelligence’s data handling appeared first on CyberScoop.