Aggregator
Securing Tomorrow: How AI is Reshaping the Cybersecurity Landscape
9 months ago
'There Will Be Pain': CISA Cuts Spark Bipartisan Concerns
9 months ago
Analysis of Proposed Budget, Workforce Cuts Reveal Risks to Cyber Readiness
The Trump administration’s 2026 budget proposal would eliminate over 1,000 positions and nearly $425 million from CISA, gutting cyber ops, risk modeling and election security - prompting warnings that the U.S. is weakening its national cyber defense amid rising global threats.
The Trump administration’s 2026 budget proposal would eliminate over 1,000 positions and nearly $425 million from CISA, gutting cyber ops, risk modeling and election security - prompting warnings that the U.S. is weakening its national cyber defense amid rising global threats.
DA: Sleep Center Worker Installed Secret Camera in Bathrooms
9 months ago
Ex-Employee Faces Criminal Charges; Hospital Reports Incident as Big HIPAA Breach
A former worker of a New York hospital's sleep disorders center has been indicted on criminal charges alleging he hid cameras in the facility's bathrooms to record videos of staff and patients. The hospital reported the incident to federal regulators as a HIPAA breach affecting thousands.
A former worker of a New York hospital's sleep disorders center has been indicted on criminal charges alleging he hid cameras in the facility's bathrooms to record videos of staff and patients. The hospital reported the incident to federal regulators as a HIPAA breach affecting thousands.
EU Prepares for Transnational Cyberattacks
9 months ago
Cyber Blueprint Spells Out Measures to Coordinate Against Disruptive Hacks
Europe is girding for a possibility of a transnational cybersecurity incident through recommendations outlining a continental response for transnational cybersecurity threats. The Council of the European Union on Friday a "EU Cyber Blueprint."
Europe is girding for a possibility of a transnational cybersecurity incident through recommendations outlining a continental response for transnational cybersecurity threats. The Council of the European Union on Friday a "EU Cyber Blueprint."
US Supreme Court Grants DOGE Unfettered Access to SSA Systems
9 months ago
Unsigned Order Overturns District Court Injunction
The U.S. Supreme Court granted Friday a Trump administration cost-cutting effort known as the "Department of Government Efficiency" access to data on Americans held at the Social Security Administration. Two liberal justices accused their conservative colleagues of a double standard.
The U.S. Supreme Court granted Friday a Trump administration cost-cutting effort known as the "Department of Government Efficiency" access to data on Americans held at the Social Security Administration. Two liberal justices accused their conservative colleagues of a double standard.
Hackers Using New ClickFix Technique To Exploits Human Error Via Fake Prompts
9 months ago
Cybersecurity researchers have identified a sophisticated new social engineering campaign that exploits fundamental human trust in everyday computer interactions. The ClickFix technique, which has been actively deployed since March 2024, represents a dangerous evolution in cybercriminal tactics that bypasses traditional security measures by targeting the most vulnerable component of any network: the end user. This […]
The post Hackers Using New ClickFix Technique To Exploits Human Error Via Fake Prompts appeared first on Cyber Security News.
Tushar Subhra Dutta
CVE-2025-49127 | kafbat kafka-ui 1.0.0 deserialization (EUVD-2025-17363)
9 months ago
A vulnerability has been found in kafbat kafka-ui 1.0.0 and classified as very critical. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-49127. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-2674 | Ajax Pagination Plugin 1.1 on WordPress wp-admin/admin-ajax.php ajax_navigation loop path traversal (EDB-32622)
9 months ago
A vulnerability has been found in Ajax Pagination Plugin 1.1 on WordPress and classified as critical. This vulnerability affects the function ajax_navigation of the file wp-admin/admin-ajax.php. The manipulation of the argument loop leads to path traversal.
This vulnerability was named CVE-2014-2674. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5784 | PHPGurukul Employee Record Management System 1.3 /myexp.php emp3ctc sql injection (EUVD-2025-17324)
9 months ago
A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vulnerability affects unknown code of the file /myexp.php. The manipulation of the argument emp3ctc leads to sql injection.
This vulnerability was named CVE-2025-5784. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5748 | WOLFBOX Level 2 EV Charger Tuya Communications Module routine (ZDI-25-327 / EUVD-2025-17312)
9 months ago
A vulnerability classified as critical was found in WOLFBOX Level 2 EV Charger. This vulnerability affects unknown code of the component Tuya Communications Module. The manipulation leads to exposed dangerous routine.
This vulnerability was named CVE-2025-5748. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2025-5749 | WOLFBOX Level 2 EV Charger BLE Encryption uninitialized variable (ZDI-25-328 / EUVD-2025-17313)
9 months ago
A vulnerability was found in WOLFBOX Level 2 EV Charger. It has been rated as critical. Affected by this issue is some unknown functionality of the component BLE Encryption. The manipulation leads to use of uninitialized variable.
This vulnerability is handled as CVE-2025-5749. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2025-5750 | WOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse secKey/localKey/stdTimeZone/devId heap-based overflow (ZDI-25-329 / EUVD-2025-17314)
9 months ago
A vulnerability classified as critical was found in WOLFBOX Level 2 EV Charger. This vulnerability affects the function tuya_svc_devos_activate_result_parse. The manipulation of the argument secKey/localKey/stdTimeZone/devId leads to heap-based buffer overflow.
This vulnerability was named CVE-2025-5750. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5785 | TOTOLINK X15 1.0.0-B20230714.1105 HTTP POST Request /boafrm/formWirelessTbl submit-url buffer overflow (EUVD-2025-17325)
9 months ago
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
The identification of this vulnerability is CVE-2025-5785. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5747 | WOLFBOX Level 2 EV Charger MCU Command Parser interpretation input (ZDI-25-326 / EUVD-2025-17326)
9 months ago
A vulnerability classified as critical has been found in WOLFBOX Level 2 EV Charger. This affects an unknown part of the component MCU Command Parser. The manipulation leads to misinterpretation of input.
This vulnerability is uniquely identified as CVE-2025-5747. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-5783 | PHPGurukul Employee Record Management System 1.3 /editmyexp.php emp3workduration sql injection (EUVD-2025-17327)
9 months ago
A vulnerability, which was classified as critical, was found in PHPGurukul Employee Record Management System 1.3. This affects an unknown part of the file /editmyexp.php. The manipulation of the argument emp3workduration leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-5783. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-22482 | QNAP Qsync Central 4.3.0.11/4.4.0.15/4.4.0.16_20240819 format string (qsa-25-10 / EUVD-2025-17341)
9 months ago
A vulnerability, which was classified as critical, has been found in QNAP Qsync Central 4.3.0.11/4.4.0.15/4.4.0.16_20240819. This issue affects some unknown processing. The manipulation leads to format string.
The identification of this vulnerability is CVE-2025-22482. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-33035 | QNAP File Station 5.5.6.4847 path traversal (qsa-25-16 / EUVD-2025-17330)
9 months ago
A vulnerability was found in QNAP File Station 5.5.6.4847 and classified as critical. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2025-33035. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5751 | WOLFBOX Level 2 EV Charger hard-coded credentials (ZDI-25-330 / EUVD-2025-17315)
9 months ago
A vulnerability, which was classified as critical, has been found in WOLFBOX Level 2 EV Charger. This issue affects some unknown processing. The manipulation leads to hard-coded credentials.
The identification of this vulnerability is CVE-2025-5751. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2025-29884 | QNAP File Station 5.5.6.4741 certificate validation (qsa-25-09 / EUVD-2025-17345)
9 months ago
A vulnerability was found in QNAP File Station 5.5.6.4741 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper certificate validation.
This vulnerability is handled as CVE-2025-29884. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com