Aggregator
SecWiki News 2025-06-10 Review
1 month 3 weeks ago
FIN6 hackers pose as job seekers to backdoor recruiters’ devices
1 month 3 weeks ago
In a twist on typical hiring-related social engineering attacks, the FIN6 hacking group impersonates job seekers to target recruiters, using convincing resumes and phishing sites to deliver malware. [...]
Bill Toulas
UK cyber agency pushes for 'strategic policy agenda' as government efforts stall
1 month 3 weeks ago
Leaders at the U.K.'s National Cyber Security Centre are calling for more political attention on cybersecurity, arguing that regulation and legislation aren't keeping up with technology.
CVE-2025-47709 | Enterprise MFA up to 4.6.x/5.1.x on Drupal authorization (sa-contrib-2025-055)
1 month 3 weeks ago
A vulnerability was found in Enterprise MFA up to 4.6.x/5.1.x on Drupal. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2025-47709. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47707 | Enterprise MFA up to 4.6.x/5.1.x on Drupal authentication bypass (sa-contrib-2025-053)
1 month 3 weeks ago
A vulnerability classified as critical has been found in Enterprise MFA up to 4.6.x/5.1.x on Drupal. Affected is an unknown function. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is traded as CVE-2025-47707. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47702 | oEmbed Providers up to 2.2.1 on Drupal cross site scripting (sa-contrib-2025-048)
1 month 3 weeks ago
A vulnerability was found in oEmbed Providers up to 2.2.1 on Drupal. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-47702. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47703 | COOKiES Consent Management up to 1.2.13 on Drupal cross site scripting (sa-contrib-2025-049)
1 month 3 weeks ago
A vulnerability was found in COOKiES Consent Management up to 1.2.13 on Drupal. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2025-47703. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47704 | Klaro Cookie & Consent Management up to 3.0.4 on Drupal cross site scripting (sa-contrib-2025-050)
1 month 3 weeks ago
A vulnerability classified as problematic has been found in Klaro Cookie & Consent Management up to 3.0.4 on Drupal. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-47704. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47705 | IFrame Remove Filter up to 2.0.4 on Drupal cross site scripting (sa-contrib-2025-051)
1 month 3 weeks ago
A vulnerability classified as problematic was found in IFrame Remove Filter up to 2.0.4 on Drupal. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-47705. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47708 | Enterprise MFA up to 4.6.x/5.1.x on Drupal cross-site request forgery (sa-contrib-2025-054)
1 month 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Enterprise MFA up to 4.6.x/5.1.x on Drupal. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2025-47708. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-48012 | One Time Password up to 1.2.x on Drupal authentication replay (sa-contrib-2025-063 / EUVD-2025-16011)
1 month 3 weeks ago
A vulnerability, which was classified as critical, has been found in One Time Password up to 1.2.x on Drupal. Affected by this issue is some unknown functionality. The manipulation leads to authentication bypass by capture-replay.
This vulnerability is handled as CVE-2025-48012. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-48009 | Single Content Sync up to 1.4.11 on Drupal authorization (sa-contrib-2025-060 / EUVD-2025-16014)
1 month 3 weeks ago
A vulnerability has been found in Single Content Sync up to 1.4.11 on Drupal and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2025-48009. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47710 | Enterprise MFA up to 4.6.x/5.1.x on Drupal authentication bypass (sa-contrib-2025-056 / EUVD-2025-14928)
1 month 3 weeks ago
A vulnerability classified as critical was found in Enterprise MFA up to 4.6.x/5.1.x on Drupal. Affected by this vulnerability is an unknown functionality. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is known as CVE-2025-47710. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47706 | Enterprise MFA up to 4.6.x/5.1.x on Drupal authentication replay (sa-contrib-2025-052 / EUVD-2025-14924)
1 month 3 weeks ago
A vulnerability was found in Enterprise MFA up to 4.6.x/5.1.x on Drupal. It has been classified as critical. This affects an unknown part. The manipulation leads to authentication bypass by capture-replay.
This vulnerability is uniquely identified as CVE-2025-47706. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-30951 | FUDforum 3.1.3 /adm/admsmiley.php chpos cross site scripting
1 month 3 weeks ago
A vulnerability classified as problematic was found in FUDforum 3.1.3. Affected by this vulnerability is an unknown functionality of the file /adm/admsmiley.php. The manipulation of the argument chpos leads to cross site scripting.
This vulnerability is known as CVE-2024-30951. The attack can be launched remotely. There is no exploit available.
vuldb.com
S5 Agency World Ltd falls victim to BERT Ransomware
1 month 3 weeks ago
S5 Agency World Ltd falls victim to BERT Ransomware
Dark Web Informer - Cyber Threat Intelligence
5 plead guilty to laundering nearly $37 million stolen through Cambodian cyber scam centers
1 month 3 weeks ago
The scheme is based in Cambodia, where people residing in scam centers contact U.S. victims through phone calls, texts, dating apps and other avenues to promote fake cryptocurrency investments.
用.NET上传打穿PHP站点
1 month 3 weeks ago
通过上传ASPX可执行文件绕过PHP站点黑名单
Alleged Sale of Chrome Alert Bypass and WD Exclusion
1 month 3 weeks ago
Alleged Sale of Chrome Alert Bypass and WD Exclusion
Dark Web Informer - Cyber Threat Intelligence