Aggregator
CVE-2025-13776 | TIK-SOFT Finka-FK hard-coded credentials
CVE-2026-27589 | caddyserver caddy up to 2.11.0 Admin API /load cross-site request forgery
CVE-2024-48928 | Piwigo up to 14.x Configuration Parameter RAND random values
CVE-2026-27588 | caddyserver caddy up to 2.11.0 case sensitivity
US ‘committed’ to fighting transnational gangs behind Southeast Asian scam compounds: FBI
CVE-2026-27585 | caddyserver caddy up to 2.11.0 Configuration input validation
CVE-2026-27587 | caddyserver caddy up to 2.11.0 path case sensitivity
CVE-2026-27586 | caddyserver caddy up to 2.11.0 CA File ClientAuthentication.provision exceptional condition
Submit #758336: itsourcecode News Portal Project V1.0 SQL Injection [Accepted]
CVE-2026-27590 | caddyserver caddy up to 2.11.0 Request Path strings.ToLower SCRIPT_NAME/SCRIPT_FILENAME/PATH_INFO input validation
CVE-2026-27571 | nats-io nats-server up to 2.11.11/2.12.2 WebSockets data amplification
CVE-2026-3133 | itsourcecode Document Management System 1.0 Login /loging.php Username sql injection
Submit #758324: itsourcecode News Portal Project V1.0 SQL Injection [Accepted]
Submit #758323: itsourcecode Document Management System V1.0 SQL Injection [Accepted]
Одна бесконечность больше другой — целые числа можно пересчитать, дробные нельзя. Математика сошла с ума?
65% of Financial Organizations Targeted by Ransomware as Cybercriminals Escalate Attacks
The financial sector remains a prime target for cybercriminals, safeguarding not only vast sums of money but also sensitive personal data, payment systems, and economic trust. Recent reports highlight escalating threats, with 65% of financial organizations hit by ransomware in 2024, the highest rate across industries, while average recovery costs excluding ransoms reached $2.73 million. […]
The post 65% of Financial Organizations Targeted by Ransomware as Cybercriminals Escalate Attacks appeared first on Cyber Security News.
Anthropic Claims Chinese AI Firms ‘Distilled’ Claude to Train Their Models
Malicious NuGet Packages Attacking ASP.NET Developers to Steal Login Credentials
A supply chain attack targeting ASP.NET developers has surfaced, involving four malicious NuGet packages built to steal login credentials and plant persistent backdoors inside web applications. The packages — NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_ — were published between August 12 and 21, 2024, by a threat actor operating under the username “hamzazaheer,” and together they […]
The post Malicious NuGet Packages Attacking ASP.NET Developers to Steal Login Credentials appeared first on Cyber Security News.