Aggregator
Windows 11 24H2 KASLR Broken Using an HVCI-Compatible Driver with Physical Memory Access
A security researcher has published a detailed analysis demonstrating how Kernel Address Space Layout Randomization (KASLR) protections can be circumvented on Windows 11 24H2 systems through exploitation of an HVCI-compatible driver with physical memory access capabilities. The research, published by security researcher Yazid on June 9, 2025, presents a novel approach to obtaining the Windows […]
The post Windows 11 24H2 KASLR Broken Using an HVCI-Compatible Driver with Physical Memory Access appeared first on Cyber Security News.
CVE-2014-9094 | Digitalzoomstudio Video Gallery designrand cross site scripting (EDB-39250 / BID-68525)
CVE-2009-1938 | Joomla CMS up to 1.5.10 cross site scripting (EDB-33022 / Nessus ID 39427)
【安全圈】T-Mobile否认6400万用户数据遭黑客窃取事件
【安全圈】微软修复9.3分高危漏洞
【安全圈】网信办加强数据安全执法,两家违法企业被罚
CVE-2019-7442 | CyberArk Password Vault Web Access up to 10.7 SAML Authentication xml external entity reference (ID 152801 / EDB-46828)
CVE-2004-1927 | Tiki TikiWiki 1.6.1/1.8.1 path traversal (EDB-43809 / Nessus ID 14364)
CVE-2019-7652 | TheHive Project UnshortenLink Analyzer up to 1.0 Data server-side request forgery (ID 152804 / EDB-46820)
CVE-2025-5238 | YITH WooCommerce Wishlist Plugin up to 4.5.0 on WordPress ID cross site scripting
CVE-2025-4667 | Appointment Booking Calendar Plugin up to 1.6.8.30 on WordPress Shortcode cross site scripting
CVE-2006-2210 | 321soft PhP-Gallery 0.9 index.php path cross site scripting (EDB-27804 / XFDB-26230)
CVE-2012-5913 | WordPress Integrator 1.32 wp-integrator.php redirect_to cross site scripting (EDB-37016 / XFDB-74475)
CVE-2004-1926 | Tiki TikiWiki 1.6.1/1.8.1 code injection (EDB-43809 / Nessus ID 14364)
AMOS macOS Stealer Hides in GitHub With Advanced Sophistication Methods
A sophisticated new variant of the AMOS macOS stealer has emerged, demonstrating unprecedented levels of technical sophistication in its distribution and obfuscation methods. The malware leverages GitHub repositories as distribution platforms, exploiting the platform’s legitimacy to bypass security measures and target unsuspecting macOS users with cryptocurrency theft capabilities. The latest campaign involves a multi-layered attack […]
The post AMOS macOS Stealer Hides in GitHub With Advanced Sophistication Methods appeared first on Cyber Security News.