Aggregator
Google Chrome Vulnerability Let Attackers Escape Payload from Sandbox – Technical Details Disclosed
A critical vulnerability in Google Chrome has recently been discovered that allows malicious actors to break out of the browser’s protective sandbox environment, potentially giving attackers access to the underlying operating system. The flaw, identified as CVE-2025-2783, affects Chrome versions prior to 134.0.6998.142 across Windows, macOS, and Linux platforms. This vulnerability represents a significant security […]
The post Google Chrome Vulnerability Let Attackers Escape Payload from Sandbox – Technical Details Disclosed appeared first on Cyber Security News.
Europol Creates Operational Taskforce to Tackle Violence-as-a-Service
In response to the concerning rise of “violence-as-a-service” (VaaS) and the exploitation of youth by organized crime, Europol has announced the formation of a new Operational Task Force (OTF), codenamed GRIMM. This multinational initiative, led by Sweden, brings together law enforcement agencies from Belgium, Denmark, Finland, France, Germany, the Netherlands, and Norway. Europol provides operational […]
The post Europol Creates Operational Taskforce to Tackle Violence-as-a-Service appeared first on Cyber Security News.
Bitwarden Access Intelligence defends against credential risks and phishing
Bitwarden launched Access Intelligence, a set of new capabilities that enables enterprises to proactively defend against internal credential risks and external phishing threats. Access Intelligence introduces two core functionalities: Risk Insights, which allows IT teams to identify, prioritize, and remediate at-risk credentials; and Advanced Phishing Blocker, which alerts and redirects users away from known phishing sites in real-time, using a continuously updated open source blocklist of malicious domains. This approach enables better protection for users … More →
The post Bitwarden Access Intelligence defends against credential risks and phishing appeared first on Help Net Security.
CVE-2000-0665 | GAMSoft Telsrv 1.4/1.5 Username denial of service (EDB-16816 / Nessus ID 10474)
Google Warns of 75 Zero-Day Vulnerabilities Exploited in the Wild
Google’s Threat Intelligence Group (GTIG) has revealed that 75 zero-day vulnerabilities were exploited in the wild during 2024, highlighting both evolving attacker tactics and shifting targets in the global cybersecurity landscape. While this figure decreases from the 98 zero-days observed in 2023, it still represents a significant increase from the 63 tracked in 2022, underscoring […]
The post Google Warns of 75 Zero-Day Vulnerabilities Exploited in the Wild appeared first on Cyber Security News.
ExtraHop strenghtens network detection and response
ExtraHop launched all-in-one sensor designed to unify network traffic collection that scales across a number of security use cases. This further advances ExtraHop’s vision to consolidate NDR, network performance monitoring (NPM), intrusion detection (IDS), and full packet forensics into an integrated, powerful, and adaptable security solution for the modern hybrid enterprise. According to IDC, tool consolidation can save 16% of total tool costs and nearly 20% of analyst time on average. With the ExtraHop all-in-one … More →
The post ExtraHop strenghtens network detection and response appeared first on Help Net Security.
CVE-2012-4237 | Tecnick TCExam up to 11.2.21 tce_edit_answer.php subject_module_id sql injection (EDB-37584 / BID-54861)
CVE-2025-32432
CVE-2014-8676 | Soplanning up to 1.32 file_get_contents path path traversal (EDB-37604 / BID-75726)
OpenBSD 7.7 Released with Significant Performance & Security Enhancements
OpenBSD 7.7, the 58th release of the security-focused operating system, was officially launched on April 28, 2025. This release substantially improves multiple areas, including performance optimization, hardware support, and security enhancements. The new version features notable performance improvements, particularly on ARM64 architecture, where the PMAP teardown has been optimized by skipping TLB flushes, resulting in […]
The post OpenBSD 7.7 Released with Significant Performance & Security Enhancements appeared first on Cyber Security News.
SentinelOne Uncovers Chinese Espionage Campaign Targeting Its Infrastructure and Clients
Akamai Firewall for AI: Get Powerful Protection for New LLM App Threats
G.O.S.S.I.P 阅读推荐 2025-04-29 安全研究的历史局限性
G.O.S.S.I.P 阅读推荐 2025-04-29 安全研究的历史局限性
Windows Server 2025 Hotpatching Service to be Rolled Out From July 1st, 2025
Microsoft has confirmed that its hotpatching feature for Windows Server 2025, which has been in preview since 2024, will transition to a paid subscription model starting July 1st, 2025. The announcement, made by Janine Patrick, Windows Server Product Marketing Manager, and Artem Pronichkin, Senior Program Manager, marks a significant shift in how organizations can manage […]
The post Windows Server 2025 Hotpatching Service to be Rolled Out From July 1st, 2025 appeared first on Cyber Security News.
CISA warns about actively exploited Broadcom, Commvault vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new flaws to its Known Exploited Vulnerabilities catalog on Monday, affecting Commvault (CVE-2025-3928), Active! Mail (CVE-2025-42599), and Broadcom Brocade (CVE-2025-1976) solutions. CISA’s KEV catalog is constantly updated and provides IT admins in US federal civilian agencies with instructions on how to remediate these threats and by which date (as mandated by the Binding Operational Directive 22-01), but this living document can also come in handy … More →
The post CISA warns about actively exploited Broadcom, Commvault vulnerabilities appeared first on Help Net Security.