Aggregator
CVE-2025-48477 | freescout up to 1.8.179 fill behavioral workflow (GHSA-2c82-qx7x-35h8)
CVE-2025-48490 | Lomkit laravel-rest-api up to 2.12.x improper authorization (GHSA-69rh-hccr-cxrj)
CVE-2025-48476 | freescout up to 1.8.179 Password Field fill behavioral workflow (GHSA-7h5m-q39p-h849)
CVE-2025-48889 | gradio-app gradio up to 5.30.x Flagging denial of service (GHSA-8jw3-6x8j-v96g)
京麒CTF初赛圆满结束,决赛战火即将点燃!
ConnectWise Hacked – Nation State Actors Compromised the Systems to Access Customer Data
ConnectWise, a leading provider of software solutions for managed service providers, disclosed today that it detected suspicious activity within its environment, believed to be orchestrated by a sophisticated nation-state actor. The breach, which impacted a small number of ScreenConnect customers, has prompted an immediate response from the company, including an investigation led by top cybersecurity […]
The post ConnectWise Hacked – Nation State Actors Compromised the Systems to Access Customer Data appeared first on Cyber Security News.
Симка превращается в маяк: как оператор связи сдал всех своих абонентов с потрохами
CVE-2014-10078 | Vembu StoreGrid 4.4.x onlineregsuccess.php cross site scripting (EDB-46549 / OSVDB-109818)
全球气温到 2029 年可能首次升温超 2℃
Securing Multi-Cloud Infrastructures in 2025 Enterprise Deployments
As enterprises increasingly adopt multi-cloud architectures to optimize flexibility and avoid vendor lock-in, securing these distributed environments has become a critical priority. According to industry forecasts, over 70% of organizations will rely on multi-cloud or hybrid models by 2025. However, this shift has expanded attack surfaces, with misconfigurations, supply chain vulnerabilities, and identity management gaps posing […]
The post Securing Multi-Cloud Infrastructures in 2025 Enterprise Deployments appeared first on Cyber Security News.
Apache Tomcat CGI Servlet Flaw Enables Security Constraint Bypass
A newly disclosed vulnerability, CVE-2025-46701, has been identified in Apache Tomcat’s CGI servlet, allowing attackers to bypass security constraints under specific conditions. The flaw, announced on May 29, 2025, is rooted in the improper handling of case sensitivity within the pathInfo component of URLs mapped to the CGI servlet. When Tomcat is deployed on a […]
The post Apache Tomcat CGI Servlet Flaw Enables Security Constraint Bypass appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.