Aggregator
CVE-2019-25499 | niteosoft Simple Job Script 1.66 get_job_applications_ajax.php job_id sql injection (Exploit 46612)
CVE-2019-25503 | Blondish PHPads 2.0 click.php3 bannerID sql injection (Exploit 46798)
CVE-2026-20131 | Cisco Secure Firewall Management Center up to 10.0.0 Web-based Management Interface deserialization (cisco-sa-fmc-rce-NKhnULJh / EUVD-2026-9444)
CVE-2026-20003 | Cisco Secure Firewall Management Center up to 7.7.10.1 REST API sql injection (cisco-sa-fmc-sql-injection-2qH6CcJd)
CVE-2026-20001 | Cisco Secure Firewall Management Center up to 7.7.0 REST API sql injection (cisco-sa-fmc-sql-injection-2qH6CcJd)
CVE-2026-20062 | Cisco Secure Firewall Adaptive Security Appliance Software CLI incorrect execution-assigned permissions (cisco-sa-asa-scpcxt-filecpy-rgeP73nE)
CVE-2026-20106 | Cisco Secure Firewall Adaptive Security Appliance Software Access SSL VPN/HTTP Management/MUS memory leak (cisco-sa-asaftd-vpn-m9sx6MbC)
CVE-2026-20105 | Cisco Secure Firewall Adaptive Security Appliance Software Remote Access SSL VPN memory leak (cisco-sa-asaftd-vpn-m9sx6MbC)
FBI seizes LeakBase cybercrime forum, data of 142,000 members
Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners
Microsoft, Europol, and partners have dismantled the Tycoon 2FA phishing-as-a-service (PhaaS) platform, seizing 330 domains used for credential theft and MFA bypass. This coordinated action disrupts a service active since 2023 that powered tens of millions of phishing emails monthly. Tycoon 2FA enabled cybercriminals to bypass multifactor authentication (MFA) via adversary-in-the-middle (AiTM) techniques, capturing credentials, […]
The post Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners appeared first on Cyber Security News.
Нейросети теперь сами сносят файрволы: скрипт CyberStrikeAI в одиночку делает работу сотни живых взломщиков
149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
Windows 10 Update KB5068164 Breaks Windows Recovery Environment
Microsoft’s October 2025 Windows Recovery Environment update for Windows 10 introduced a critical boot failure issue, rendering WinRE inaccessible on affected systems, with a fix confirmed only in March 2026. Released on October 14, 2025, KB5068164 was designed to automatically apply Safe OS Dynamic Update KB5067017 to the Windows Recovery Environment (WinRE) on Windows 10 […]
The post Windows 10 Update KB5068164 Breaks Windows Recovery Environment appeared first on Cyber Security News.