Aggregator
Submit #521037: Netis WF-2404 Router Firmware Version: APR-R4A4-V1.1.124EN-Netis(WF-2404),2010.12.14 16:18. Use of Weak Hash [Accepted]
Submit #521036: Netis WF-2404 Firmware Version: APR-R4A4-V1.1.124EN-Netis(WF-2404),2010.12.14 16:18. Hardware Allows Activation of Test or Debug Logic at Runtime [Accepted]
Red Team Tactics Grow More Sophisticated with Advancements in Artificial Intelligence
A recent scoping review has revealed that red team tactics are becoming increasingly sophisticated as artificial intelligence (AI) technologies advance. The study, which analyzed 11 articles published between 2015 and 2023, identified a wide array of AI methods being employed in cyberattacks, including classification, regression, and clustering techniques. Among the most prominent AI methods utilized […]
The post Red Team Tactics Grow More Sophisticated with Advancements in Artificial Intelligence appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-2869 | Clinic Queuing System 1.0 /manage_user.php ID cross site scripting
CVE-2025-2868 | Clinic Queuing System 1.0 /index.php page cross site scripting
Microsoft fixes Remote Desktop issues caused by Windows updates
CVE-2025-2870 | Clinic Queuing System 1.0 /patient_side.php page cross site scripting
CVE-2025-2917 | ChestnutCMS up to 1.5.3 /dev-api/cms/file/read readFile filePath path traversal
CVE-2025-2916 | Aishida Call Center System up to 20250314 amr2mp3 File command injection
CVE-2005-2782 | AutoLinks 2.1 al_initialize.php alpath file inclusion (EDB-26208 / Nessus ID 19522)
Submit #520933: https://github.com/liweiyi/ChestnutCMS ChestnutCMS ≤1.5.3 Arbitrary file read vulnerability [Accepted]
CVE-2024-4431 | LA-Studio Element Kit for Elementor Plugin up to 1.3.7.6 on WordPress ID cross site scripting
CVE-2024-4563 | Progress MOVEit Automation up to 2024.0.0 Configuration Export risky encryption
CVE-2024-29392 | Silverpeas Core 6.3 ClipboardSessionController cross site scripting
JFK and the Houthis: Haste Makes Waste of Security
Rather than simply exposing buried truths of the assassination, the final tranche of JFK files also exposed the personal information, including social security numbers, of a parade of people associated with the decades-long investigation, many of whom are still alive today.
The post JFK and the Houthis: Haste Makes Waste of Security appeared first on Security Boulevard.
CVE-2024-35627 | tileserver-gl up to 4.4.10 /data/v3/?key cross site scripting
英国托管服务供应商Advanced因客户数据泄露被罚307万英镑;美国电信巨头WOW!被曝遭入侵,40万客户数据被泄露 | 牛览
Submit #520604: Aishida Co., Ltd. Aishida Co., Ltd.'s call center system amr2mp3 Command Injection [Accepted]
Cloudflare open sources OPKSSH to bring Single Sign-On to SSH
OPKSSH (OpenPubkey SSH) makes it easy to authenticate to servers over SSH using OpenID Connect (OIDC), allowing developers to ditch manually configured SSH keys in favor of identity provider-based access. By tightly integrating with identity providers (IdPs) and avoiding any additional trusted third party, OPKSSH offers a streamlined and secure way to manage SSH authentication. This week, OPKSSH was officially open-sourced under the umbrella of the OpenPubkey project. While OpenPubkey itself became a Linux Foundation … More →
The post Cloudflare open sources OPKSSH to bring Single Sign-On to SSH appeared first on Help Net Security.