Aggregator
Submit #628437: Scada-LTS 2.7.8.1 Cross Site Scripting [Accepted]
Malicious npm Packages Target Crypto Developers to Steal Login Credentials
A sophisticated threat campaign dubbed “Solana-Scan” has emerged, deploying malicious npm packages aimed at infiltrating the Solana cryptocurrency ecosystem. Identified by the Safety research team through advanced malicious package detection technology, this operation involves a threat actor operating under the handle “cryptohan” and associated with the email [email protected]. The actor has published packages masquerading as […]
The post Malicious npm Packages Target Crypto Developers to Steal Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Massive Allianz Life data breach impacts 1.1 million people
选择性漏洞:主动学习中的清洁标签后门攻击
U.S. CISA adds Trend Micro Apex One flaw to its Known Exploited Vulnerabilities catalog
Grok сорвал контракт с правительством США — и всё из-за промптов о Гитлере
150 инструментов и 12 ИИ-агентов HexStrike AI выпустил новую платформу для автоматизации пентестов
CVE-2025-8898 | Taxi Booking Manager for Woocommerce Plugin up to 1.3.0 on WordPress authorization (EUVD-2025-25073)
CVE-2025-8896 | User Profile Builder Plugin up to 3.14.3 on WordPress GDPR Communication Preferences gdpr_communication_preferences cross site scripting (EUVD-2025-25075)
CVE-2025-8089 | Advanced iFrame Plugin up to 2025.6 on WordPress additional cross site scripting (EUVD-2025-25074)
CVE-2025-8464 | Drag and Drop Multiple File Upload for Contact Form 7 Plugin Cookie path traversal
CVE-2025-7499 | BetterDocs Plugin up to 4.1.1 on WordPress get_response authorization
CVE-2025-8719 | Translate This gTranslate Shortcode Plugin up to 1.0 on WordPress base_lang cross site scripting
CVE-2025-7867 | Portabilis i-Educar 2.9.0/2.10.0 Agenda /intranet/agenda.php novo_titulo/novo_descricao cross site scripting
CVE-2025-32463漏洞复现与分析
83% 的 Python 开发者仍然使用旧版本
上线通知|每月上线的京东卡来啦~
Kubernetes 集群环境的 20 多个威胁场景
CISA Warns of Trend Micro Apex One OS Command Injection Vulnerability Exploited in Attacks
CISA has issued a critical warning regarding a high-severity OS command injection vulnerability in Trend Micro Apex One Management Console that threat actors are actively exploiting in the wild. The vulnerability, tracked as CVE-2025-54948 and classified under CWE-78, poses significant risks to organizations running on-premise installations of the enterprise security platform. Key Takeaways1. CISA confirms […]
The post CISA Warns of Trend Micro Apex One OS Command Injection Vulnerability Exploited in Attacks appeared first on Cyber Security News.