Aggregator
CVE-2025-4759 | lockfile-lint-api up to 5.9.1 URL Validation incorrect behavior order: early validation (SNYK-JS-LOCKFILELINTAPI-10169587 / EUVD-2025-15407)
CVE-2025-4751 | D-Link DI-7003GV2 24.04.18D1 R(68125) /index.data information disclosure (EUVD-2025-15411)
CVE-2025-4752 | D-Link DI-7003GV2 24.04.18D1 R(68125) /install_base.data information disclosure (EUVD-2025-15410)
CVE-2025-4747 | Bohua NetDragon Firewall 1.0 ip_status.php subnet command injection (EUVD-2025-15406)
APT Group 123 Targets Windows Systems in Ongoing Malicious Payload Campaign
Group123, a North Korean state-sponsored Advanced Persistent Threat (APT) group also known by aliases such as APT37, Reaper, and ScarCruft, continues to target Windows-based systems across multiple regions. Active since at least 2012, the group has historically focused on South Korea but has broadened its operations since 2017 to include Japan, Vietnam, the Middle East, […]
The post APT Group 123 Targets Windows Systems in Ongoing Malicious Payload Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-4746 | Campcodes Sales and Inventory System 1.0 purchase_delete.php pr_id sql injection (EUVD-2025-15408)
CVE-2025-1531 | Hitachi Ops Center Analyzer Viewpoint default credentials (sec-2025-116 / EUVD-2025-15425)
【安全圈】玛莎百货网络攻击引发客户数据安全担忧
【安全圈】网络安全事件周报:勒索组织与国家级黑客同时盯上SAP漏洞
【安全圈】新Spectre变种攻击曝光:英特尔CPU存在特权分支注入漏洞,内存数据或遭窃取
【安全圈】Meta强推AI数据训练遭欧盟维权组织狙击:用户隐私权与商业利益的再度博弈
Modern Threats, Missed Phish: How Exposed Are You? (Part 2)
Alright, you’ve come this far. You’ve admitted that your SEG isn’t exactly the security soulmate you thought it was. Maybe you’ve even started to notice the red flags – missed phishes, frustrated clients, constant rule tuning. But breaking up is a process, and before you can move on to something better, it’s important to assess the current state of the relationship.
The post Modern Threats, Missed Phish: How Exposed Are You? (Part 2) appeared first on Security Boulevard.
UK Cyber Vacancies Growing 12% Per Year
CISA: Recently fixed Chrome vulnerability exploited in the wild (CVE-2025-4664)
A high-severity Chrome vulnerability (CVE-2025-4664) that Google has fixed on Wednesday is being leveraged by attackers, CISA has confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog. About CVE-2025-4664 CVE-2025-4664 stems from insufficient policy enforcement in Google Chrome’s Loader, which attackers can use to make the browser leak cross-origin data that can be used to take over accounts. The vulnerability can be triggered with a maliciously crafted HTML page, on Chrome versions prior … More →
The post CISA: Recently fixed Chrome vulnerability exploited in the wild (CVE-2025-4664) appeared first on Help Net Security.