Aggregator
CVE-2024-58114 | Huawei HarmonyOS 5.0.0 ArkUI Framework allocation of resources
Когда фишинг пахнет спецслужбой — Bitter снова в игре, и запах явно индийский
CVE-2025-5780 | code-projects Patient Record Management System 1.0 /view_dental.php itr_no sql injection
CVE-2025-5779 | code-projects Patient Record Management System 1.0 /birthing.php itr_no/comp_id sql injection
Submit #591128: code-projects Patient Record Management System 1.0 SQL Injection [Accepted]
Iranian APT ‘BladedFeline’ Stays Silent in Organizations Network for 8 Years
A sophisticated Iranian cyberespionage group has maintained undetected access to government networks across Iraq and the Kurdistan Regional Government for nearly eight years, representing one of the longest-running advanced persistent threat campaigns in the Middle East. The group, designated as BladedFeline by security researchers, has been operating since at least 2017, systematically targeting Kurdish diplomatic […]
The post Iranian APT ‘BladedFeline’ Stays Silent in Organizations Network for 8 Years appeared first on Cyber Security News.
CVE-2025-5778 | 1000 Projects ABC Courier Management System 1.0 /adminSQL Username sql injection
Submit #591127: code-projects Patient Record Management System 1.0 SQL Injection [Accepted]
在传出 OpenAI 准备收购 Windsurf 后 Anthropic 切断了该公司对其大模型的访问
Submit #591110: 1000 Projects ABC Courier Management System V1.0 SQL Injection [Accepted]
June 2025 Patch Tuesday forecast: Second time is the charm?
Microsoft has been busy releasing more out-of-band (OOB) patches than usual throughout May. The May Patch Tuesday release of updates was typical in number of vulnerabilities addressed with 41 in both Windows 10 and 11, and their associated servers. They also did a great job finally fixing most of the reported issues that have been carried out for a while. But it appears something was not quite right, because there were some issues reported from … More →
The post June 2025 Patch Tuesday forecast: Second time is the charm? appeared first on Help Net Security.
CVE-2024-46941 | Vivo SystemUI Component Protection Setting permissions (EUVD-2024-54649)
CVE-2024-56342 | IBM Verify Identity Access Digital Credentials 24.06 information exposure (EUVD-2024-54648)
CVE-2025-36513 | i-PRO Surveillance Camera cross-site request forgery (EUVD-2025-17048)
CVE-2025-5719 | Vivo Wallet missing authentication (EUVD-2025-17051)
PrimeCache: бэкдор, который живёт по принципу "не трогай — не заметят"
Hackers Exploit Roundcube Vulnerability to Steal User Credentials via XSS Attack
A recent spearphishing campaign targeting Polish entities has been attributed with high confidence to the UNC1151 threat actor, a group linked to Belarusian state interests and, according to some sources, Russian intelligence services. CERT Polska reports that the attackers leveraged a critical vulnerability in the Roundcube webmail platform—CVE-2024-42009—to steal user credentials with minimal user interaction. […]
The post Hackers Exploit Roundcube Vulnerability to Steal User Credentials via XSS Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.