Aggregator
CVE-2025-4497 | code-projects Simple Banking System up to 1.0 Sign In password2 buffer overflow
CVE-2025-4496 | TOTOLINK T10/A3100R/A950RG/A800R/N600R/A3000RU/A810R 4.1.8cu.5241_B20210927 /cgi-bin/cstecgi.cgi CloudACMunualUpdate FileName buffer overflow
Indirect Prompt Injection Exploits LLMs’ Lack of Informational Context
A new wave of cyber threats targeting large language models (LLMs) has emerged, exploiting their inherent inability to differentiate between informational content and actionable instructions. Termed “indirect prompt injection attacks,” these exploits embed malicious directives within external data sources-such as documents, websites, or emails-that LLMs process during operation. Unlike direct prompt injections, where attackers manipulate […]
The post Indirect Prompt Injection Exploits LLMs’ Lack of Informational Context appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #567082: Banking_System Buffer Overflow in Password Handling Function v1.0 Buffer Overflow [Accepted]
Submit #567081: TOTOLINK T10/A3100R/A950RG/A800R/N600R/A3000RU/A810R V4.1.8cu.5241_B20210927 Buffer Overflow [Accepted]
CVE-2025-3794 | WPForms Plugin up to 1.9.5 on WordPress start_timestamp cross site scripting
CVE-2025-4382 | Red Hat Enterprise Linux/OpenShift Container Platform TPM-based Auto-Decryption missing authentication
FreeDrain Phishing Attack Targets Users to Steal Financial Login Credentials
PIVOTcon, joint research by Validin and SentinelLABS has exposed FreeDrain, an industrial-scale cryptocurrency phishing operation that has been stealthily siphoning digital assets for years. This sophisticated campaign leverages search engine optimization (SEO) manipulation, free-tier web services, and intricate redirection techniques to target unsuspecting users of cryptocurrency wallets such as Trezor, MetaMask, and Ledger. Sophisticated Cryptocurrency […]
The post FreeDrain Phishing Attack Targets Users to Steal Financial Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-4495 | JAdmin-JAVA JAdmin 1.0 /memoAjax/save ID cross site scripting
CVE-2025-4494 | JAdmin-JAVA JAdmin 1.0 Admin Backend NoNeedLoginController.java toLogin improper authentication
Rhysida
You must login to view this content
Submit #566985: JAdmin-JAVA jadmin v1.0 Doubled Character XSS Manipulations [Accepted]
Submit #566984: JAdmin-JAVA jadmin 1.0 Incorrect Authorization [Accepted]
CVE-2025-4492 | Campcodes Online Food Ordering System 1.0 ticket-message.php ticket_id sql injection
CVE-2025-4491 | Campcodes Online Food Ordering System 1.0 ticket-status.php ticket_id sql injection
CVE-2025-4490 | Campcodes Online Food Ordering System 1.0 /view-ticket-admin.php ID sql injection
CVE-2025-4489 | Campcodes Online Food Ordering System 1.0 /routers/user-router.php t1_verified sql injection
Threat Actors Using Multimedia Systems Via Stealthy Vishing Attack
Cybercriminals have developed sophisticated vishing techniques that leverage multimedia file formats to bypass security systems and target unsuspecting victims. These new attack vectors, observed in early 2025, represent an evolution in social engineering tactics where threat actors exploit commonly trusted file formats to deliver fraudulent messages prompting victims to make phone calls to fake customer […]
The post Threat Actors Using Multimedia Systems Via Stealthy Vishing Attack appeared first on Cyber Security News.