Aggregator
CVE-2009-1938 | Joomla CMS up to 1.5.10 cross site scripting (EDB-33022 / Nessus ID 39427)
【安全圈】T-Mobile否认6400万用户数据遭黑客窃取事件
【安全圈】微软修复9.3分高危漏洞
【安全圈】网信办加强数据安全执法,两家违法企业被罚
CVE-2019-7442 | CyberArk Password Vault Web Access up to 10.7 SAML Authentication xml external entity reference (ID 152801 / EDB-46828)
CVE-2004-1927 | Tiki TikiWiki 1.6.1/1.8.1 path traversal (EDB-43809 / Nessus ID 14364)
CVE-2019-7652 | TheHive Project UnshortenLink Analyzer up to 1.0 Data server-side request forgery (ID 152804 / EDB-46820)
CVE-2025-5238 | YITH WooCommerce Wishlist Plugin up to 4.5.0 on WordPress ID cross site scripting
CVE-2025-4667 | Appointment Booking Calendar Plugin up to 1.6.8.30 on WordPress Shortcode cross site scripting
CVE-2006-2210 | 321soft PhP-Gallery 0.9 index.php path cross site scripting (EDB-27804 / XFDB-26230)
CVE-2012-5913 | WordPress Integrator 1.32 wp-integrator.php redirect_to cross site scripting (EDB-37016 / XFDB-74475)
CVE-2004-1926 | Tiki TikiWiki 1.6.1/1.8.1 code injection (EDB-43809 / Nessus ID 14364)
AMOS macOS Stealer Hides in GitHub With Advanced Sophistication Methods
A sophisticated new variant of the AMOS macOS stealer has emerged, demonstrating unprecedented levels of technical sophistication in its distribution and obfuscation methods. The malware leverages GitHub repositories as distribution platforms, exploiting the platform’s legitimacy to bypass security measures and target unsuspecting macOS users with cryptocurrency theft capabilities. The latest campaign involves a multi-layered attack […]
The post AMOS macOS Stealer Hides in GitHub With Advanced Sophistication Methods appeared first on Cyber Security News.
Frida编译调试与Hook技术实战:赠 android rat源码供学习
驱动挂钩所有内核导出函数来进行驱动逻辑分析
CVE-2018-6396 | Google Map Landkarten up to 4.2.3 on Joomla cid/id sql injection (EDB-44113 / BID-103094)
Palo Alto Networks fixed multiple privilege escalation flaws
Weekly Threat Landscape Digest – Week 24
Date: Jun 13, 2025 – Week 24 This week’s threat landscape highlights the evolving sophistication of threat actors, who are […]
The post Weekly Threat Landscape Digest – Week 24 appeared first on HawkEye.
Tenable Agent for Windows Vulnerability Let Attackers Login as Admin to Delete The System Files
Tenable, a prominent cybersecurity provider, has released version 10.8.5 of its Agent software to address three critical security vulnerabilities affecting Windows hosts running versions prior to 10.8.5. These flaws, identified as CVE-2025-36631, CVE-2025-36632, and CVE-2025-36633, could allow non-administrative users to exploit SYSTEM-level privileges, potentially leading to severe system compromise or local privilege escalation. Vulnerability Details […]
The post Tenable Agent for Windows Vulnerability Let Attackers Login as Admin to Delete The System Files appeared first on Cyber Security News.