Aggregator
Секретная программа SONGBOW: что известно о новой лазерной системе ВМС против гиперзвука
CVE-2025-1454 | Ninja Pages Plugin up to 1.4.2 on WordPress Admin Settings cross site scripting
CVE-2025-47785 | Emlog up to 2.5.9 admin/article_save.php origContent sql injection (GHSA-939m-47f7-m559)
CVE-2025-47786 | Emlog 2.5.13 /admin/comment.php perpage_num cross site scripting (GHSA-82qc-9vg7-2c6c)
CVE-2025-2203 | FunnelKit Plugin up to 3.10.1 on WordPress sql injection (EUVD-2025-15210)
CVE-2025-4871 | PCMan FTP Server 2.0.7 REST Command buffer overflow
CVE-2025-4872 | FreeFloat FTP Server 1.0 CCC Command buffer overflow
CVE-2025-32407 | Samsung Internet for Galaxy Watch 5.0.9 TLS Certificate channel accessible (EUVD-2025-15549)
CVE-2022-4363 | Wholesale Market Plugin prior 2.2.2 on WordPress Setting cross-site request forgery
CVE-2025-48187 | infiniflow ragflow up to 0.18.1 excessive authentication (EUVD-2025-15586)
CVE-2025-47945 | donetick up to 0.1.43 JSON Web Token variable initialization (GHSA-hjjg-vw4j-986x)
CVE-2025-47273 | pypa setuptools up to 78.1.0 PackageIndex path traversal (ID 4946 / EUVD-2025-15591)
CVE-2025-4863 | Advaya Softech GEMS ERP Portal 2.1 studentLogin.action userId sql injection
CVE-2025-4866 | weibocom rill-flow 0.1.18 Management Console code injection (Issue 102)
CVE-2025-4190 | CSV Mass Importer Plugin up to 1.2 on WordPress unrestricted upload (EUVD-2025-15569)
19 ways to build zero trust: NIST offers practical implementation guide
The National Institute of Standards and Technology (NIST) has released a new guide that offers practical help for building zero trust architectures (ZTA). The guidance, titled Implementing a Zero Trust Architecture (SP 1800‑35), includes 19 example setups using off‑the‑shelf commercial tools. The new guidance is the result of work by NIST’s National Cybersecurity Center of Excellence (NCCoE). Over four years, 24 industry partners including major tech companies helped build, install, test, and document 19 ZTA … More →
The post 19 ways to build zero trust: NIST offers practical implementation guide appeared first on Help Net Security.
特温特大学 | HoneyKube: 设计和部署一个基于微服务的 Web 蜜罐
New infosec products of the week: June 13, 2025
Here’s a look at the most interesting products from the past week, featuring releases from Contrast Security, Cymulate, Lemony, SpecterOps, Thales, and Vanta. Lemony mitigates privacy and compliance risks associated with cloud-based AI With Lemony, different teams can run their own nodes or clusters of nodes and securely connect them. This enables teams to share knowledge across the organization, but only at the depth permitted by defined AI access policies. In other words, teams can … More →
The post New infosec products of the week: June 13, 2025 appeared first on Help Net Security.