Aggregator
CVE-2025-24013 | CodeIgniter up to 4.5.7 Header Validation interpretation conflict (GHSA-x5mq-jjr3-vmx6)
CVE-2025-25291 | SAML-Toolkits ruby-saml up to 1.12.3/1.17.x ReXML/Nokogiri signature verification (GHSA-4vc4-m8qh-g8jm / Nessus ID 232721)
CVE-2024-9216 | gaizhenbiao ChuanhuChatGPT get_model missing critical step in authentication
CVE-2025-0187 | gradio-app gradio up to 0.39.1 File Upload resource consumption
CVE-2024-9159 | gaizhenbiao ChuanhuChatGPT authorization
CVE-2024-9107 | gaizhenbiao chuanhuchatgpt cross site scripting
CVE-2025-30217 | Frappe up to 14.93.1/15.54.x sql injection
CVE-2025-1781 | W3C CSS Validator prior 20250226 XML xml external entity reference (GHSA-745m-xmq6-g6x7)
CVE-2025-20233 | Splunk App for Lookup File Editing up to 4.0.4 chmod permission assignment (SVD-2025-0310)
CVE-2025-20230 | Splunk Enterprise/Secure Gateway App Key Value Store access control (SVD-2025-0307 / Nessus ID 233365)
ASNmap: Go CLI and Library for quickly mapping organization network ranges using ASN information
Tonic.ai product updates: May 2024
Textual is the first secure data lakehouse for LLMs, subsetting has arrived for Db2 LUW, Ephemeral now supports Oracle, + Avro is on Structural! Learn more about all the latest releases from Tonic.ai.
The post Tonic.ai product updates: May 2024 appeared first on Security Boulevard.
CVE-2025-20146 | Cisco IOS XR up to 24.3.2 Layer 3 Multicast denial of service (cisco-sa-multicast-ERMrSvq7)
CVE-2025-20142 | Cisco IOS XR up to 7.10.1 IPv4 Access Control List denial of service (cisco-sa-ipv4uni-LfM3cfBu)
BSidesSF 2025: GenAI Application Security: Not Just Prompt Injection
Creator/Author/Presenter: Ahmed Abugharbia
Our deep appreciation to Security BSides - San Francisco and the Creators/Authors/Presenters for publishing their BSidesSF 2025 video content on YouTube. Originating from the conference’s events held at the lauded CityView / AMC Metreon - certainly a venue like no other; and via the organization's YouTube channel.
Additionally, the organization is welcoming volunteers for the BSidesSF Volunteer Force, as well as their Program Team & Operations roles. See their succinct BSidesSF 'Work With Us' page, in which, the appropriate information is to be had!
The post BSidesSF 2025: GenAI Application Security: Not Just Prompt Injection appeared first on Security Boulevard.
Что, если время — это просто перевёрнутое пространство? Физик пошел от противного — и открыл то, чего не видел никто
CVE-2025-2824 | IBM Operational Decision Manager 8.11.0.1/8.11.1.0/8.12.0.1/9.0.0.1/9.5.0 redirect (WID-SEC-2025-1698)
Linux 6.17 прокачал EXT4: файловая система готова к атакам многопоточных контейнеров
Social engineering attacks surged this past year, Palo Alto Networks report finds
Unit 42 said social engineering — the method of choice for groups as diverse as Scattered Spider and North Korean tech workers — was the top initial attack vector over the past year.
The post Social engineering attacks surged this past year, Palo Alto Networks report finds appeared first on CyberScoop.