Aggregator
CVE-2019-25735 | AllPlayer 7.4 URL buffer overflow (Exploit 46668)
CVE-2019-25733 | nsauditor NetShareWatcher 1.5.8.0 Find buffer overflow (Exploit 46578)
CVE-2019-25731 | Zuz Music 2.1 Inbox Interface ___contact name/subject/message cross site scripting (Exploit 46420)
CVE-2019-25734 | Web-Dorado Contact Form Maker 1.13.1 admin-ajax.php path traversal (Exploit 46661)
CVE-2019-25726 | Nicheoffice All in One Video Downloader 1.2 Admin Interface ID sql injection (Exploit 46077)
CVE-2019-25730 | Themerig Listing Hub CMS 1.0 pages.php ID sql injection (Exploit 46419)
CVE-2019-25729 | simcy_creative PDF Signer 3.0 shell_exec cross-site request forgery (Exploit 46276)
CVE-2019-25728 | Care2x 2.7 login.php ck_config sql injection (Exploit 46268)
CVE-2019-25732 | eitube EI-Tube 3.0 Search Endpoint sql injection (Exploit 46440)
CVE-2019-25727 | ad-manager-wd Ad Manager WD 1.0.11 on WordPress edit.php path path traversal (Exploit 46252)
Weaponized ChatGPT Download Site Delivers Malware Via Sponsored Search Results
A new malvertising campaign is exploiting ChatGPT’s popularity by promoting a weaponized fake download site via sponsored search results, delivering malware to both Windows and macOS users. Security researchers from Evalian’s SOC team identified the operation, which leverages convincing OpenAI branding and search engine ads to lure users actively seeking legitimate AI tools. The campaign […]
The post Weaponized ChatGPT Download Site Delivers Malware Via Sponsored Search Results appeared first on Cyber Security News.
UN food agency investigates breach exposing data of Gaza aid recipients
快速打造可手机控制的私有 C***X 助手
Microsoft blames unexpected Windows driver updates on caching issue
Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process
Большой брат следит в формате сторис. Google запустит сервис, который читает письма ради ежедневных советов
Critical Cisco Unified CM Bug Patched as Public Exploit Code Emerges
Нейросети требуют слишком много энергии. Но Сбер, кажется, придумал решение
Kali365 PhaaS Operation Expands Beyond Microsoft 365 to Target Okta and MAX Messenger
A new and fast-growing phishing operation is making waves in the cybersecurity world, and it is moving far beyond its original targets. Kali365, a phishing-as-a-service (PhaaS) platform first spotted in April 2026, was initially built to steal Microsoft 365 login tokens by tricking users into authorizing fake device login requests. Now it has grown into […]
The post Kali365 PhaaS Operation Expands Beyond Microsoft 365 to Target Okta and MAX Messenger appeared first on Cyber Security News.