Aggregator
Submit #638609: donbermoy Advanced School Management System with Complete Features 1.0 SQL Injection [Accepted]
CVE-2025-9687 | Portabilis i-Educar up to 2.10 processamentoApi improper authorization
CVE-2025-9686 | Portabilis i-Educar up to 2.10 Listagem de áreas de conhecimento Page edit ID sql injection
【安全圈】2025年上半年全球数据泄露:美国超过200万账户遭曝光
【安全圈】TransUnion曝出第三方数据泄露事件:逾440万客户信息或遭泄露
【安全圈】腾讯云就此次安全事件做出回应
【安全圈】社交媒体位置追踪真相:谁在悄悄“盯着”你的行踪
Загрузил фото, ввёл данные — готово удостоверение. Власти закрыли маркетплейс, где подделки делались проще селфи
CVE-2025-9685 | Portabilis i-Educar up to 2.10 Listagem de áreas de conhecimento Page view ID sql injection
Submit #638592: mupen64plus.org mupen64plus <= 2.6.0 Integer Overflow to Buffer Overflow [Accepted]
CVE-2025-9684 | Portabilis i-Educar up to 2.10 Formula de Cálculo de Média Page edit ID sql injection
Safeguarding Healthcare With Secure and Smart Hospitals
Torkel Thune, head of the department for architecture, operational IT security and chief security officer at Oslo University Hospital, discusses how global shifts are affecting cybersecurity for the Nordic region, and how healthcare is especially vulnerable.
Bridging the IT-OT Security Divide in Manufacturing
Manufacturers face many challenges in securing OT and IT systems, from legacy technology to managing vulnerabilities. Tammy Klotz, CISO at Trinseo and last year's ManuSec Summit event chair, discusses the value of sharing firsthand insights with a cybersecurity community.
Submit #638582: Portabilis i-educar 2.10 Broken Object Level Authorization [Accepted]
Popular Nx Packages Compromised by Credential-Stealing Malware
A widespread supply chain attack on the popular Nx build system has compromised dozens of high-traffic packages, exposing sensitive credentials and demonstrating a frighteningly comprehensive approach to future threats. Security researchers have confirmed that malicious versions of Nx—numbered 20.9.0 through 21.8.0—systematically scanned infected machines for a broad range of secrets before exfiltrating them to public […]
The post Popular Nx Packages Compromised by Credential-Stealing Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #638577: Portabilis i-educar 2.10 SQL Injection [Accepted]
Submit #638576: Portabilis i-educar 2.10 SQL Injection [Accepted]
Submit #638574: Portabilis i-educar 2.10 SQL Injection [Accepted]
Attackers use “Contact Us” forms and fake NDAs to phish industrial manufacturing firms
A recently uncovered phishing campaign – carefully designed to bypass security defenses and avoid detection by its intended victims – is targeting firms in industrial manufacturing and other companies critical to various supply chains, Check Point researchers have warned. The phishing campaign(s) The researchers believe that the campaign has been mounted by financially motivated threat actors. Its goal is to deliver a malicious ZIP archive that contains a PowerShell script that will be executed in … More →
The post Attackers use “Contact Us” forms and fake NDAs to phish industrial manufacturing firms appeared first on Help Net Security.