Aggregator
CVE-2025-54422 | sandboxie-plus Sandboxie up to 1.16.1 cleartext storage (GHSA-jp7r-vgv9-43p7)
CVE-2025-40686 | Human Resource Management System 1.0 /detailview.php employeeid cross site scripting
CVE-2025-40685 | Human Resource Management System 1.0 /state.php searcstate cross site scripting
CVE-2025-40684 | Human Resource Management System 1.0 /country.php searccountry cross site scripting
CVE-2025-51970 | PuneethReddyHC Online Shopping System Advanced 1.0 POST Parameter action.php keyword sql injection
CVE-2025-40682 | Human Resource Management System 1.0 /controller/ccity.php city/state sql injection
CVE-2025-40683 | Human Resource Management System 1.0 /city.php searccity cross site scripting
Цензура по кредитке: пользователи обрушили поддержку Visa и Mastercard после блокировки adult-игр
CVE-2025-4496 | TOTOLINK T10/A3100R/A950RG/A800R/N600R/A3000RU/A810R 4.1.8cu.5241_B20210927 /cgi-bin/cstecgi.cgi CloudACMunualUpdate FileName buffer overflow
CVE-2025-49812 | Apache HTTP Server up to 2.4.63 mod_ssl improper authentication (EUVD-2025-21016 / Nessus ID 242028)
CVE-2025-53020 | Apache HTTP Server up to 2.4.63 memory leak (EUVD-2025-21015 / Nessus ID 242028)
CVE-2025-50151 | Apache Jena up to 5.4.0 Configuration File unrestricted upload (EUVD-2025-22072)
CVE-2025-49656 | Apache Jena up to 5.4.0 Admin UI access control (EUVD-2025-22076)
Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44
New XWorm V6 Variant with Anti-Analysis Features Targeting Windows Users in Active Attacks
Netskope Threat Labs has uncovered a new iteration of the XWorm malware, version 6.0, which demonstrates ongoing development by threat actors and introduces sophisticated enhancements aimed at evading detection and maintaining persistence on Windows systems. This variant builds upon previously documented infection chains, incorporating advanced anti-analysis techniques and process protection mechanisms that make it particularly […]
The post New XWorm V6 Variant with Anti-Analysis Features Targeting Windows Users in Active Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Incidents impacting retailers – recommendations from the NCSC
Alleged Sale of Admin Access to Frank & Co. Jewellery
1000 км разлуки больше не приговор: объятия через интернет становятся реальностью
Lazarus Subgroup ‘TraderTraitor’ Targets Cloud Platforms and Contaminates Supply Chains
The North Korean state-sponsored advanced persistent threat (APT) known as TraderTraitor, a subgroup of the notorious Lazarus Group, has emerged as a formidable actor specializing in digital asset heists. Tracked under aliases such as UNC4899, Jade Sleet, TA444, and Slow Pisces by various cybersecurity firms including Mandiant, Microsoft, Proofpoint, and Unit42, TraderTraitor operates under the […]
The post Lazarus Subgroup ‘TraderTraitor’ Targets Cloud Platforms and Contaminates Supply Chains appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.