Aggregator
DPC Investigates TikTok Over Transfer of EU User Data to China
The Data Protection Commission (DPC) has launched a formal inquiry into TikTok Technology Limited, scrutinizing the company’s practices regarding the transfer and storage of European Economic Area (EEA) users’ personal data to servers in China. This development stems from discrepancies uncovered in a prior investigation concluded on April 30, 2025, where TikTok asserted that EEA […]
The post DPC Investigates TikTok Over Transfer of EU User Data to China appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-7492 | PHPGurukul Vehicle Parking Management System 1.13 manage-incomingvehicle.php del sql injection (EUVD-2025-21236)
CVE-2002-2226 | TFTP32 up to 2.21 filename memory corruption (VU#632633 / EDB-22025)
COMmander: Network-Based Tool for COM and RPC Exploitation
The need for solutions that improve detection skills against sophisticated attacks is growing in the ever-changing cybersecurity world. COMmander emerges as a lightweight, C#-based utility designed to bolster defensive telemetry by monitoring Remote Procedure Call (RPC) and Component Object Model (COM) activities at a granular level. Developed to address gaps in identifying network-based exploitations involving […]
The post COMmander: Network-Based Tool for COM and RPC Exploitation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2017-16884 | MistServer 2.12 /admin/api cross site scripting (EDB-43205)
CVE-2025-7490 | PHPGurukul Vehicle Parking Management System 1.13 /admin/reg-users.php del sql injection (EUVD-2025-21235)
CVE-2025-7491 | PHPGurukul Vehicle Parking Management System 1.13 manage-outgoingvehicle.php del sql injection (EUVD-2025-21234)
Researchers Bypass Meta’s Llama Firewall Using Prompt Injection Vulnerabilities
Researchers at Trendyol, a leading e-commerce platform, have uncovered multiple vulnerabilities in Meta’s Llama Firewall, a suite of tools designed to safeguard large language models (LLMs) against malicious inputs. Llama Firewall incorporates components like PROMPT_GUARD for mitigating prompt injection attacks and CODE_SHIELD for detecting insecure code generation. However, Trendyol’s Application Security team, motivated by internal […]
The post Researchers Bypass Meta’s Llama Firewall Using Prompt Injection Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2008-0281 | ID-Commerce 2.0 liste.php idFamille sql injection (EDB-31009 / XFDB-39594)
CVE-2013-0663 | Schneider Electric Modicon Quantum Plc 140noe77111 cross-site request forgery (EDB-44678)
CVE-2007-2718 | Stalker CommuniGate Pro up to 5.1.8 cross site scripting (EDB-30027 / Nessus ID 25215)
Fake Gaming and AI Companies Target Windows and macOS Users with Drainer Malware Attacks
The cybersecurity company Darktrace has uncovered a persistent, intricate social engineering campaign that targets bitcoin users, building on earlier findings by Cado Security Labs in December 2024. Threat actors are fabricating elaborate startup companies themed around AI, gaming, video conferencing, Web3, and social media to lure victims into downloading malware disguised as legitimate software. These […]
The post Fake Gaming and AI Companies Target Windows and macOS Users with Drainer Malware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-7488 | JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 /file/download Name path traversal (Issue 18 / EUVD-2025-21233)
CVE-2025-7489 | PHPGurukul Vehicle Parking Management System 1.13 search-vehicle.php searchdata sql injection (EUVD-2025-21232)
CVE-2008-0218 | Merak IceWarp Mail Server Message cross site scripting (EDB-31001 / Nessus ID 29895)
CVE-2025-7567 | ShopXO up to 6.5.0 header.html lang/system_type cross site scripting (Issue 89 / EUVD-2025-21298)
Bitcoin Depot Breach Exposes Data of 27,000 Crypto Users
Bitcoin Depot, Inc., a prominent cryptocurrency ATM operator, has disclosed a data breach that compromised the personal information of approximately 27,000 users. The breach, which involved unauthorized access to sensitive customer records, underscores the persistent vulnerabilities in the fintech sector, particularly for platforms handling digital asset transactions. Detected on June 23, 2024, the incident prompted […]
The post Bitcoin Depot Breach Exposes Data of 27,000 Crypto Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.