Aggregator
CVE-2025-52879 | JetBrains TeamCity up to 2025.03.2 NPM Registry Integration cross site scripting
CVE-2025-52877 | JetBrains TeamCity up to 2025.03.2 diskUsageBuildsStats Page cross site scripting
CVE-2025-52876 | JetBrains TeamCity up to 2025.03.2 favoriteIcon Page cross site scripting (EUVD-2025-18915)
CVE-2025-52875 | JetBrains TeamCity up to 2025.03.2 Performance Monitor Page cross site scripting (EUVD-2025-18914)
Microsoft will start removing legacy drivers from Windows Update
Microsoft will start removing legacy drivers from Windows Update to improve driver quality for Windows users but, most importantly, to increase security, the company has announced. This is intended to be an ongoing process and Microsoft is planning to introduce new publishing rules for driver updates. A step-by-step process Microsoft is, in effect, trimming its “driver garden” so that Windows will – ideally and in time – only deal with fresh, well-tested, secure and compatible … More →
The post Microsoft will start removing legacy drivers from Windows Update appeared first on Help Net Security.
CVE-2025-52878 | JetBrains TeamCity up to 2025.03.2 Username authorization
SparkKitty Targets iOS and Android Devices via App Store and Google Play Attacks
A sophisticated spyware campaign, dubbed SparkKitty, has emerged as a significant threat to both iOS and Android users, infiltrating even the official app stores like Google Play and the App Store. First detected in connection with the earlier SparkCat campaign from January 2025, which targeted crypto wallet seed phrases, SparkKitty has since evolved into a […]
The post SparkKitty Targets iOS and Android Devices via App Store and Google Play Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-6535 | xxyopen/201206030 novel-plus up to 5.1.3 User Management Module UserMapper.xml list sort/order sql injection (EUVD-2025-18967)
CVE-2025-6534 | xxyopen/201206030 novel-plus up to 5.1.3 File FileController.java remove resource injection (EUVD-2025-18972)
CVE-2025-6533 | xxyopen/201206030 novel-plus up to 5.1.3 CATCHA LoginController.java ajaxLogin authentication replay (EUVD-2025-18961)
CVE-2015-7602 | Bisonware BisonFTP 3.5 RETR Command path traversal (Exploit 133749 / EDB-38341)
Submit #596573: xxyopen novel-plus 5.1.3 SQL Injection [Accepted]
Submit #596505: xxyopen novel-plus v5.1.3 Improper Authorization [Accepted]
Submit #596481: xxyopen novel-plus 5.1.3 Improper Restriction of Excessive Authentication Attempts [Accepted]
McLaren Health Care says data breach impacts 743,000 patients
CVE-2025-6532 | NOYAFA/Xiami LF9 Pro up to 20250611 RTSP Live Video Stream Endpoint access control (EUVD-2025-18962)
APT36 Hackers Attacking Indian Defense Personnel in Sophisticated Phishing Attack
A Pakistan-based cyber espionage group known as APT36 or Transparent Tribe has launched a highly sophisticated phishing campaign targeting Indian defense personnel, utilizing credential-stealing malware designed to establish long-term infiltration within sensitive military networks. The campaign represents a significant escalation in nation-state cyber threats, employing advanced social engineering techniques that exploit the trust inherent in […]
The post APT36 Hackers Attacking Indian Defense Personnel in Sophisticated Phishing Attack appeared first on Cyber Security News.
Linux Firewall IPFire 2.29 Core Update 195 Released With VPN Protocol Support
IPFire has released Core Update 195 for version 2.29, marking a significant milestone with the introduction of native WireGuard VPN protocol support. This highly anticipated update transforms the open-source firewall distribution by integrating modern VPN capabilities alongside comprehensive security enhancements and system improvements. WireGuard VPN Integration The standout feature of IPFire 2.29 Core Update 195 […]
The post Linux Firewall IPFire 2.29 Core Update 195 Released With VPN Protocol Support appeared first on Cyber Security News.