Aggregator
IT巨头英迈因SafePay勒索软件攻击导致服务中断
1 month 2 weeks ago
这起事件与SafePay勒索软件行动有关,该行动已成为2025年较为活跃的行动之一。目前尚不清楚设备是否在攻击中被加密。
XCon2025官宣定档!无界场议题征集,热力启动!!
1 month 2 weeks ago
8月22日,邀你共赴这场纯享型技术盛宴~
腾讯云Web应用防火墙|秒级拦截千万级DDoS攻击,实现业务0中断
1 month 2 weeks ago
7月15日19:00,点击预约,锁定安全席位!
XCon2025官宣定档!无界场议题征集,热力启动!!
1 month 2 weeks ago
当前环境异常,需完成验证后方可继续访问。
IT巨头英迈因SafePay勒索软件攻击导致服务中断
1 month 2 weeks ago
当前环境出现异常,请完成验证后继续访问。
腾讯云Web应用防火墙|秒级拦截千万级DDoS攻击,实现业务0中断
1 month 2 weeks ago
当前环境出现异常状态,需完成验证后方可继续访问相关内容或功能。
How Gas Network's "Capture the Gap" Game Is Tackling The $1 Billion On-Chain Efficiency Problem
1 month 2 weeks ago
Gas Network推出"Capture the Gap"游戏,通过让用户捕捉区块链中gas价格差异来奖励参与者。该机制激励用户频繁更新gas oracle,改善网络效率和透明度。项目旨在通过 gamification 提升用户体验并促进去中心化生态发展。
Им нет и двадцати, а ущерб — под полмиллиарда. Новое лицо киберпреступности
1 month 2 weeks ago
История четырёх обыкновенных подростков, построивших цифровую империю зла.
Where policy meets profit: Navigating the new frontier of defense tech startups
1 month 2 weeks ago
In this Help Net Security interview, Thijs Povel, Managing Partner at Ventures.eu, discusses how the firm evaluates emerging technologies through the lens of defense and resilience. He explains how founders from both defense and adjacent sectors are addressing policy shifts, procurement cycles, and dual-use innovation. Povel also offers guidance for founders on handling slow-moving procurement cycles and proving the business case for resilience solutions. How do you differentiate between defense-adjacent and non-lethal tech when evaluating … More →
The post Where policy meets profit: Navigating the new frontier of defense tech startups appeared first on Help Net Security.
Mirko Zorz
Хотели безопасный SSH — получили бэкдор. Проверьте Termius: китайцы подменили оригинал на macOS
1 month 2 weeks ago
Думали, что цифровые подписи защищают от всего? Как бы не так.
CVE-2025-53862 | Red Hat Ansible Automation Platform aap-gateway information disclosure
1 month 2 weeks ago
A vulnerability was found in Red Hat Ansible Automation Platform. It has been classified as problematic. Affected is an unknown function of the component aap-gateway. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-53862. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-53861 | Red Hat Ansible Automation Platform missing secure attribute
1 month 2 weeks ago
A vulnerability was found in Red Hat Ansible Automation Platform and classified as problematic. This issue affects some unknown processing. The manipulation leads to sensitive cookie without secure attribute.
The identification of this vulnerability is CVE-2025-53861. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply the suggested workaround.
vuldb.com
CVE-2025-6851 | Broken Link Notifier Plugin up to 1.3.0 on WordPress ajax_blinks server-side request forgery (EUVD-2025-21125)
1 month 2 weeks ago
A vulnerability has been found in Broken Link Notifier Plugin up to 1.3.0 on WordPress and classified as critical. This vulnerability affects the function ajax_blinks. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2025-6851. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-6838 | Broken Link Notifier Plugin up to 1.3.0 on WordPress csv injection (EUVD-2025-21124)
1 month 2 weeks ago
A vulnerability, which was classified as critical, was found in Broken Link Notifier Plugin up to 1.3.0 on WordPress. This affects an unknown part. The manipulation leads to csv injection.
This vulnerability is uniquely identified as CVE-2025-6838. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-4593 | aviplugins WP Register Profile With Shortcode Plugin up to 3.6.2 on WordPress information disclosure
1 month 2 weeks ago
A vulnerability, which was classified as problematic, has been found in aviplugins WP Register Profile With Shortcode Plugin up to 3.6.2 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2025-4593. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-5530 | WPC Smart Compare for WooCommerce Plugin up to 6.4.6 on WordPress Shortcode shortcode_btn cross site scripting
1 month 2 weeks ago
A vulnerability classified as problematic was found in WPC Smart Compare for WooCommerce Plugin up to 6.4.6 on WordPress. Affected by this vulnerability is the function shortcode_btn of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-5530. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-6745 | WoodMart Plugin up to 8.2.5 on WordPress Password Protect woodmart_get_posts_by_query improper authentication
1 month 2 weeks ago
A vulnerability classified as critical has been found in WoodMart Plugin up to 8.2.5 on WordPress. Affected is the function woodmart_get_posts_by_query of the component Password Protect Handler. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-6745. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-7442 | WPGYM Plugin up to 67.7.x on WordPress sql injection
1 month 2 weeks ago
A vulnerability was found in WPGYM Plugin up to 67.7.x on WordPress. It has been rated as critical. This issue affects the function MJ_gmgt_delete_class_limit_for_member/MJ_gmgt_get_yearly_income_expense/MJ_gmgt_get_monthly_income_expense/MJ_gmgt_add_class_limit/MJ_gmgt_view_meeting_detail/MJ_gmgt_create_meeting. The manipulation leads to sql injection.
The identification of this vulnerability is CVE-2025-7442. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-31267 | Apple App Store Connect up to 2.x User Information improper authentication (EUVD-2025-21072)
1 month 2 weeks ago
A vulnerability was found in Apple App Store Connect up to 2.x. It has been declared as problematic. This vulnerability affects unknown code of the component User Information Handler. The manipulation leads to improper authentication.
This vulnerability was named CVE-2025-31267. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com