Aggregator
GitLab High-Severity Vulnerabilities Let Attackers Crash Instances
GitLab has disclosed multiple high-severity Denial-of-Service (DoS) vulnerabilities that could allow unauthenticated attackers to crash self-managed GitLab instances. These flaws impact Community Edition (CE) and Enterprise Edition (EE) versions prior to 18.4.1, 18.3.3, and 18.2.7, and exploit both HTTP endpoints and GraphQL APIs. Administrators must upgrade immediately to prevent service interruptions and potential data loss. […]
The post GitLab High-Severity Vulnerabilities Let Attackers Crash Instances appeared first on Cyber Security News.
加拿大新不伦瑞克大学 | IoT-PRIDS:利用数据包表示进行物联网入侵检测
CVE-2025-11080 | zhuimengshaonian wisdom-education up to 1.0.4 ExamInfoController.java selectStudentExamInfoList subjectId improper authorization (EUVD-2025-31441)
Singapore Threatens Meta With Fines Over Facebook Impersonation Scams
Fortra GoAnywhere Vulnerability Exploited as 0-Day Before Patch
A critical, perfect 10.0 CVSS score vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) solution was actively exploited as a zero-day at least a week before the company released a patch. The vulnerability, tracked as CVE-2025-10035, is a command injection flaw that allows for unauthenticated remote code execution. Security firm watchTowr reported credible evidence of […]
The post Fortra GoAnywhere Vulnerability Exploited as 0-Day Before Patch appeared first on Cyber Security News.
New Variant of The XCSSET Malware Attacking macOS App Developers
The macOS threat landscape has witnessed a significant escalation with the discovery of a new variant of the XCSSET malware targeting app developers. First observed in late September 2025, this variant builds upon earlier versions by introducing enhanced stealth techniques, expanded exfiltration capabilities, and robust persistence mechanisms. Attackers continue to leverage infected Xcode projects—the cornerstone […]
The post New Variant of The XCSSET Malware Attacking macOS App Developers appeared first on Cyber Security News.
CVE-2025-11025 | Vimesoft Corporate Messaging Platform prior 2.0.0 insertion of sensitive information into sent data
Submit #661308: https://gitee.com/zhuimengshaonian/wisdom-education wisdom-education 1.0.4 Horizontal overstepping authority [Accepted]
Malicious MCP Server Discovered Stealing Sensitive Emails Using AI Agents
Enterprises everywhere are embracing MCP servers—tools that grant AI assistants “god-mode” permissions to send emails, run database queries, and automate tedious tasks. But no one ever stopped to ask: Who built these tools? Today, the first real-world malicious MCP server—postmark-mcp—has emerged, quietly exfiltrating every email it processes. Since its initial release, postmark-mcp has been downloaded […]
The post Malicious MCP Server Discovered Stealing Sensitive Emails Using AI Agents appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-11079 | Campcodes Farm Management System 1.0 file information disclosure (EUVD-2025-31439)
Submit #661199: Campcodes Farm Management System v1.0 Directory traversal [Accepted]
Redefining incident response in the age of AI
150,000 Records of Home Health Care Firm Exposed on Web
An unencrypted database containing nearly 150,000 patient records of a California provider of home health and palliative care services was left exposed on the internet, said a cybersecurity researcher who discovered the unsecured data cache. Why does this keep happening in the healthcare sector?
How the EU Data Act Shifts Control Back to Users
The EU Data Act is now in its second phase of implementation, shifting the balance of power by granting users rights over the data generated by their connected devices and services. Beyond banning unfair contract terms and eliminating vendor lock-in, the act mandates data portability and access.
Feds Isolate Cisco Firewalls to Defend Against 'Arcane Door'
CISA issued an emergency directive Thursday after discovering an advanced hacking campaign exploiting two persistent zero-days in Cisco firewall gear - malware that survives system reboots and upgrades - forcing agencies to disconnect vulnerable devices by Friday.
New Chinese Espionage Hacking Group Uncovered
A hacking group associated with widespread compromise of edge devices is a Chinese-state-aligned group, says cybersecurity firm Recorded Future. The firm says the threat actor, which it now tracks as RedNovember, is "highly likely a Chinese state-sponsored threat activity group."