Aggregator
微软9月补丁星期二值得关注的漏洞
Adobe 修复史上最严重的 Magento 漏洞之一
微软9月补丁星期二值得关注的漏洞
Lazarus Hackers Abuse Git Symlink Vulnerability in Stealthy Phishing Campaign
KuCoin’s security team has uncovered a new phishing campaign orchestrated by the Lazarus Group (APT38), the notorious state-sponsored collective renowned for financially motivated cyberespionage. Armed with government resources and a history of high-profile breaches, Lazarus continues to evolve its tactics to target cryptocurrency and financial institutions worldwide. Over the last decade, Lazarus has homed in […]
The post Lazarus Hackers Abuse Git Symlink Vulnerability in Stealthy Phishing Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
HackerOne Data Breach, Hackers Illegally Access Salesforce Environment
HackerOne, a leading vulnerability coordination platform, has confirmed that its Salesforce environment was compromised in a recent third-party data breach. The incident stemmed from an attack on the Drift application provided by Salesloft, which allowed unauthorized actors to gain entry to records stored in Salesforce. While no customer vulnerability data appears to have been exposed, […]
The post HackerOne Data Breach, Hackers Illegally Access Salesforce Environment appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-10211 | yanyutao0402 ChanCMS 3.3.0 /cms/collect/getArticle CollectController taskUrl server-side request forgery
CVE-2025-10210 | yanyutao0402 ChanCMS up to 3.3.0 Api.js search key sql injection
Submit #639779: yanyutao0402 ChanCMS V3.3.0 Unauthorized SSRF [Accepted]
Submit #639777: yanyutao0402 ChanCMS V3.3.0 Unauthorized SQL injection [Accepted]
Submit #639778: yanyutao0402 ChanCMS V3.3.0 Unauthorized RCE [Duplicate]
Critical Flaws in Microsoft Office Enable Remote Code Execution by Attackers
Microsoft has disclosed two serious security vulnerabilities in its Office suite that allow attackers to execute arbitrary code on affected systems. Both flaws were publicly released on September 9, 2025, and have been assigned CVE identifiers CVE-2025-54910 and CVE-2025-54906. These critical issues affect Microsoft Office on Windows and can be exploited by attackers to gain […]
The post Critical Flaws in Microsoft Office Enable Remote Code Execution by Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Apple iPhone Air and iPhone 17 Feature A19 Chips With Spyware-Resistant Memory Safety
Apple iPhone Air and iPhone 17 Feature A19 Chips With Spyware-Resistant Memory Safety
What is CRLF Injection? Exploitations and Security Tips
Интернет по талонам: власти выбрали 57 «правильных» сайтов на случай отключения мобильной связи
CVE-2025-10209 | Papermerge DMS up to 3.5.3 Authorization Token improper authorization
Microsoft Warns of Active Directory Domain Services Vulnerability, Let Attackers Escalate Privileges
Microsoft has issued an updated warning for a critical security vulnerability in Active Directory Domain Services, tracked as CVE-2025-21293. This flaw could permit an attacker who has already gained initial access to a system to escalate their privileges, potentially gaining complete control over the affected domain controller and undermining the security of the network infrastructure. […]
The post Microsoft Warns of Active Directory Domain Services Vulnerability, Let Attackers Escalate Privileges appeared first on Cyber Security News.