Aggregator
CVE-2025-7595 | code-projects Job Diary 1.0 /view-cad.php ID sql injection (EUVD-2025-21333)
CVE-2025-7596 | Tenda FH1205 2.0.0.7(775) /goform/WifiExtraSet formWifiExtraSet wpapsk_crypto stack-based overflow (EUVD-2025-21339)
CVE-2025-53689 | Apache Jackrabbit up to 2.20.16/2.22.0/2.23.1-beta xml external entity reference
CVE-2024-26293 | Avid NEXIS E-series prior 2025.5.1 gSOAP vulnerable third-party component (EUVD-2024-23564)
CVE-2025-27427 | Apache ActiveMQ Artemis up to 2.39.0 permission
CVE-2024-51768 | HPE AutoPass License Server hsqldb privilege escalation (ZDI-24-1632 / EUVD-2024-54781)
CVE-2024-51767 | HPE AutoPass License Server improper authentication (ZDI-24-1631 / EUVD-2024-54782)
CVE-2024-51769 | HPE AutoPass License Server sql injection (ZDI-24-1633 / EUVD-2024-54780)
CVE-2024-51770 | HPE AutoPass License Server xml external entity reference (ZDI-24-1634 / EUVD-2024-54783)
⚡ Weekly Recap: Scattered Spider Arrests, Car Exploits, macOS Malware, Fortinet RCE and More
Stellar Cyber 6.0.0 enhances automation, workflow intelligence, and user experience
Stellar Cyber released version 6.0.0 of its award-winning open and unified SecOps Platform, introducing new AI-driven capabilities and workflow enhancements designed to propel organizations further along their journey to a human-augmented autonomous SOC. The 6.0.0 release builds on Stellar Cyber’s vision of delivering intelligent, efficient, and decisive security operations through automation, AI, and seamless integration—all while remaining open, flexible, and accessible for security teams of any size or skill level. “With 6.0.0, we’re putting powerful … More →
The post Stellar Cyber 6.0.0 enhances automation, workflow intelligence, and user experience appeared first on Help Net Security.
CVE-2025-7597 | Tenda AX1803 1.0.0.1 /goform/setMacFilterCfg formSetMacFilterCfg deviceList stack-based overflow (EUVD-2025-21340)
CVE-2025-7598 | Tenda AX1803 1.0.0.1 /goform/setWifiFilterCfg formSetWifiMacFilterCfg deviceList stack-based overflow (EUVD-2025-21338)
CVE-2025-7599 | PHPGurukul Dairy Farm Shop Management System 1.3 /invoice.php del sql injection (EUVD-2025-21337)
Pune Auto Parts Firm Loses ₹2.35 Crore in Man-in-the-Middle Attack
A Pune-based automobile parts manufacturer fell victim to a sophisticated man-in-the-middle (MITM) cyber attack, resulting in a loss of ₹2.35 crore. The 52-year-old director of the company filed an FIR with the cybercrime police station after discovering that fraudsters impersonating executives from an Italian manufacturing firm had intercepted business communications and redirected payments to fraudulent […]
The post Pune Auto Parts Firm Loses ₹2.35 Crore in Man-in-the-Middle Attack appeared first on Cyber Security News.
14th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES McDonald’s has suffered a data breach that resulted in the exposure of chat transcripts, session tokens, and personal data from more than 64 million job applications submitted through its AI powered McHire […]
The post 14th July – Threat Intelligence Report appeared first on Check Point Research.