Aggregator
CVE-2025-30523 | Marcel-NL Super Simple Subscriptions Plugin up to 1.1.0 on WordPress sql injection
We raised a $35M Series B. Here’s what’s next for fake data.
Today, we're excited to announce that Tonic.ai has raised $35 million in Series B funding led by global venture capital and private equity firm Insight Partners. A milestone that serves as further proof of the value of mimicking production data for development—the value of fake data.
The post We raised a $35M Series B. Here’s what’s next for fake data. appeared first on Security Boulevard.
Dell security advisory (AV25-155)
Clio – Real-Time Logging Tool With Locking, User Authentication, and Audit Trails
Clio has emerged as a revolutionary real-time logging solution developed by cybersecurity engineers at CyberLock Technologies in the evolving landscape of cybersecurity tools. Launched in January 2025, this sophisticated tool addresses critical gaps in traditional logging frameworks by providing comprehensive visibility into system events while maintaining strong security protocols. Clio’s architecture is specifically designed to […]
The post Clio – Real-Time Logging Tool With Locking, User Authentication, and Audit Trails appeared first on Cyber Security News.
VanHelsing RaaS Launch: 3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion Tactics
Microsoft Edge security advisory (AV25-154)
Hidden Threats: How Microsoft 365 Backups Store Risks for Future Attacks
FCC Conducting Investigation into Chinese Entities Placed on the Government’s Prohibited List
The Federal Communications Commission (FCC) has launched a sweeping investigation into nine Chinese technology and telecommunications companies that were previously placed on its Covered List, aiming to determine if these firms are evading U.S. restrictions. FCC Chairman Brendan Carr announced on March 21, 2025, that the agency has sent Letters of Inquiry and at least […]
The post FCC Conducting Investigation into Chinese Entities Placed on the Government’s Prohibited List appeared first on Cyber Security News.
Report: Fortune 500 employee-linked account exposure
A backbone of our economy, Fortune 500 companies employ more than 31 million people worldwide. According to data analyzed by the Enzoic research team, over the past three years of 2022, 2023, and 2024, more than three million employee-linked accounts became newly compromised by cybercriminals. 1 in 10 Fortune 500 employees had their credentials exposed in recent years 5.7 exposure average per compromised account These leaked credentials pose significant risks, enabling account takeover (ATO), spear … More →
The post Report: Fortune 500 employee-linked account exposure appeared first on Help Net Security.
Next.js 中间件权限绕过漏洞(CVE-2025-29927)
Код 0x222400: как ABYSSWORKER стирает защитные функции корпоративных систем
Eclypsium Earns Spot on Coveted 2025 CRN Partner Program Guide
Global Partner Program empowers partners to deliver top-tier supply chain security solutions to enterprise customers Portland, OR – March 24, 2025 – Eclypsium, a leader in infrastructure supply chain security, is proud to announce that it has been included in the prestigious 2025 CRN® Partner Program Guide. The guide is issued annually by CRN®, a […]
The post Eclypsium Earns Spot on Coveted 2025 CRN Partner Program Guide appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise.
The post Eclypsium Earns Spot on Coveted 2025 CRN Partner Program Guide appeared first on Security Boulevard.
WordPress Plug-in Vulnerability Let Hackers Inject Malicious SQL Queries
A critical vulnerability in GamiPress, a popular WordPress plugin used for gamification and rewards systems on websites. The high-impact flaw, categorized as CVE-2024-13496 with a CVSS 3.1 score of 7.5, allowed unauthenticated attackers to inject malicious SQL queries that could potentially compromise entire WordPress installations. The vulnerability, which affected all GamiPress versions up to 7.3.1, […]
The post WordPress Plug-in Vulnerability Let Hackers Inject Malicious SQL Queries appeared first on Cyber Security News.
WordPress Plugin Vulnerability Exposes 200k+ Sites to Code Execution Attacks
A critical vulnerability in WP Ghost, a popular WordPress security plugin with over 200,000 active installations. The high-severity flaw, tracked as CVE-2025-26909 with a CVSS score of 9.6, allows unauthenticated attackers to exploit a Local File Inclusion (LFI) vulnerability that can lead to Remote Code Execution (RCE). Website administrators are strongly advised to update immediately […]
The post WordPress Plugin Vulnerability Exposes 200k+ Sites to Code Execution Attacks appeared first on Cyber Security News.