Aggregator
CVE-2025-46573 | auth0 passport-wsfed-saml2 up to 4.6.3 SAML2 Authentication improper authentication (GHSA-8gqj-226h-gm8r)
CVE-2025-44073 | SeaCMS 13.3 admin_comment_news.php sql injection
CVE-2025-47418 | Crestron Automate VX up to 6.4.0.49 Network API information disclosure
Autorize: Burp Suite extension for automatic authorization enforcement detection
Autorize is an open-source Burp Suite extension that checks if users can access things they shouldn’t. It runs automatic tests to help security testers find authorization problems. Autorize installation To use Autorize, you’ll need Burp Suite and Jython. Here’s how to set it up: Download Burp Suite Download Jython Open burp > Extender > Options > Python Environment > Select File > Choose the Jython standalone JAR Install Autorize from the BApp Store or download … More →
The post Autorize: Burp Suite extension for automatic authorization enforcement detection appeared first on Help Net Security.
CVE-2025-3218 | IBM i 7.2/7.3/7.4/7.5/7.6 Netserver certificate validation
JVN: Milesight製UG65-868M-EAにおけるブートコードがコピーされる揮発性メモリに対するアクセス制御が不適切な脆弱性
JVN: BrightSign製Brightsignプレーヤーにおける不要な権限での実行の脆弱性
SQCTF2025-Crypto-WP
中国 AI 投资人:练习时长两年半
1 in 3 workers keep AI use a secret
Employees are feeling heightened concerns around the use of technology to enhance productivity, as well as job dissatisfaction and a lack of motivation at work. In fact, 30% of employees who use GenAI tools at work worry their job may be cut and 27% experience AI-fueled imposter syndrome, saying they don’t want people to question their ability, according to Ivanti. “Ivanti’s research shows that employees continue to want greater autonomy over their work lives and … More →
The post 1 in 3 workers keep AI use a secret appeared first on Help Net Security.