Aggregator
CVE-2024-58250 | ppp up to 2.5.1 Passprompt Plugin untrusted search path
CVE-2025-1732 | Zyxel USG FLEX H uOS up to V1.31 Configuration File privileges management
CVE-2024-13569 | Rustaurius Front End Users Plugin up to 3.2.32 on WordPress cross site scripting
CVE-2025-2300 | Hitachi Ops Center Common Services 11.0.3 log file (sec-2025-112)
CVE-2024-46899 | Hitachi Ops Center Common Services up to 11.0.0-03 default credentials (sec-2025-111)
Microsoft Secures MSA Signing with Azure Confidential VMs Following Storm-0558 Breach
CVE-2025-3577 | Zyxel AMG1302-T10B 2.00(AAJC.16)C0 Web Management Interface path traversal
Fake Certificate Issued for Alibaba Cloud After SSL.com Validation Trick
A critical vulnerability in SSL.com’s domain validation process allowed unauthorized parties to fraudulently obtain TLS certificates for high-profile domains, including Alibaba Cloud’s aliyun.com, researchers revealed this week. The certificate authority (CA) has since revoked 11 improperly issued certificates, raising concerns about trust in automated validation systems. How Domain Validation Was Exploited According to Mozilla report, SSL.com’s Domain […]
The post Fake Certificate Issued for Alibaba Cloud After SSL.com Validation Trick appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-1731 | Zyxel USG FLEX H uOS up to 1.20/1.31 PostgreSQL Command permission assignment
CVE-2025-2987 | IBM Maximo Asset Management 7.6.1.3 server-side request forgery
StrikeReady Security Command Center v2 accelerates threat response
For years, security teams have operated in reactive mode, contending with siloed tools, fragmented intelligence, and a never-ending backlog of alerts. Traditional Security Operations platforms were supposed to unify data and streamline response—but they often introduced their own complexity, requiring heavy customization and manual oversight. ‘Hyper automation’ delivered much of the same empty promises, leaving most security teams firefighting today’s incidents with limited bandwidth to proactively manage tomorrow’s risks. StrikeReady is introducing its next-generation Security Command … More →
The post StrikeReady Security Command Center v2 accelerates threat response appeared first on Help Net Security.