Aggregator
CVE-2026-4272 | Honeywell Barcode Scanner missing authentication
CVE-2019-25682 | VictorAlagwu CMSsite 1.0 users.php add_user/edit_user cross-site request forgery (Exploit 46480 / EDB-46480)
36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware
A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi plugins were published to the npm registry, carrying payloads designed to exploit Redis for remote code execution, steal credentials, and establish persistent command-and-control access on […]
The post 36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware appeared first on Cyber Security News.
CVE-2019-25664 | SuiteCRM 7.10.7 Users index.php DetailView record sql injection (Exploit 46311)
CVE-2019-25685 | phpBB 3.2.3 plupload imagick path traversal (Exploit 46512 / EDB-46512)
CVE-2019-25673 | UniSharp Laravel File Manager 2.0.0 Upload Endpoint Type unrestricted upload (Exploit 356 / EDB-46389)
CVE-2019-25668 | Phpscriptsmall News Website Script 2.0.5 index.php/show/news/ news ID sql injection (Exploit 46456 / EDB-46456)
CVE-2019-25678 | C4G Basic Laboratory Information System 3.4 users_select.php site missing authentication (Exploit 46438 / EDB-46438)
CVE-2019-25684 | OpenDocMan 1.3.4 Parameter search.php where sql injection (Exploit 46500 / EDB-46500)
CVE-2019-25662 | Montala ResourceSpace 8.6 watched_searches.php ref sql injection (Exploit 46308 / EDB-46308)
CVE-2019-25675 | eDirectory 1.0 Login Endpoint language_file.php key sql injection (Exploit 46423)
CVE-2019-25671 | VA MAX 8.3.4 Parameter changeip.php mtu_eth0 path traversal (Exploit 46348 / EDB-46348)
CVE-2026-5614 | Belkin F9K1015 1.00.10 /goform/formSetPassword webpage stack-based overflow (EUVD-2026-19158)
CVE-2026-5615 | givanz Vvvebjs up to 2.0.5 File Upload Endpoint upload.php uploadAllowExtensions cross site scripting (EUVD-2026-19160)
CVE-2026-5616 | JeecgBoot 3.9.0/3.9.1 AI Chat JeecgBizToolsProvider.java missing authentication (Issue 9464 / EUVD-2026-19162)
CVE-2026-5609 | Tenda i12 1.0.0.11(3862) Parameter /goform/wifiSSIDset formwrlSSIDset index/wl_radio stack-based overflow (EUVD-2026-19148)
CVE-2026-5610 | Belkin F9K1015 1.00.10 /goform/formWISP5G webpage stack-based overflow (EUVD-2026-19150)
CVE-2026-5608 | Belkin F9K1122 1.00.33 /goform/formWlanSetup webpage stack-based overflow (EUVD-2026-19146)
Residential proxies make a mockery of IP-based defenses
Attack traffic moved through ordinary home and mobile connections in ways that limited the usefulness of IP reputation on its own. GreyNoise observed 4 billion malicious sessions during a 90-day period and described activity that appeared indistinguishable from normal user traffic at the network level. Residential proxies routed traffic through consumer broadband, mobile data, and small-business connections. These same IP ranges were used by employees, customers, and partners, which made it difficult to separate malicious … More →
The post Residential proxies make a mockery of IP-based defenses appeared first on Help Net Security.