Aggregator
Google fined $314M for misusing idle Android users’ data
Apache APISIX Vulnerability Enables Cross-Issuer Access Under Misconfigurations
A newly disclosed vulnerability, CVE-2025-46647, has been identified in the openid-connect plugin of Apache APISIX, a widely used open-source API gateway. This flaw, rated as important, could allow attackers to gain unauthorized access across different identity issuers under specific misconfigurations. The vulnerability was reported by JunXu Chen to the Apache APISIX development mailing list on July 2, […]
The post Apache APISIX Vulnerability Enables Cross-Issuer Access Under Misconfigurations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-48231 | codepeople Booking Calendar Contact Form Plugin up to 1.2.58 on WordPress cross site scripting (EUVD-2025-19983)
CVE-2025-47565 | ashanjay EventON Plugin up to 4.9.9 on WordPress authorization (EUVD-2025-19980)
CVE-2025-47479 | AresIT WP Compress Plugin up to 6.30.30 on WordPress weak authentication (EUVD-2025-19979)
CVE-2025-28976 | dsrodzin Email Address Security by WebEmailProtector Plugin cross site scripting (EUVD-2025-19970)
CVE-2025-23970 | aonetheme Service Finder Booking Plugin up to 6.0 on WordPress privileges assignment (EUVD-2025-19966)
CVE-2025-7066 | Jirafeau up to 4.6.2 cross site scripting (EUVD-2025-20016)
CVE-2025-47634 | Keylor Mendoza WC Pickup Store Plugin up to 1.8.9 on WordPress authorization (EUVD-2025-19982)
CVE-2025-28980 | machouinard Aviation Weather from NOAA Plugin up to 0.7.2 on WordPress path traversal (EUVD-2025-19972)
CVE-2025-28983 | ClickandPledge Click & Pledge Connect Plugin up to WP6.8 on WordPress sql injection (EUVD-2025-19973)
CVE-2002-1075 | David Harris Pegasus Mail up to 4.01 Header To/From memory corruption (EDB-21648 / XFDB-9673)
Offensive System Prompt Pentest Playbook
Instagram Now Rotating TLS Certificates Daily with 1-Week Validity
Instagram has begun rotating its TLS certificates on a daily basis, with each certificate valid for just over a week. This approach, which goes far beyond current industry standards, was discovered during routine network debugging and has since been confirmed through systematic monitoring and analysis. Setup and Discovery The anomaly was first noticed when a […]
The post Instagram Now Rotating TLS Certificates Daily with 1-Week Validity appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.