Aggregator
Debug 不如打球!secsys2025春季运动会回顾
11 months 1 week ago
系统软件与安全实验室2025年春季运动会回顾
Debug 不如打球!secsys2025春季运动会回顾
11 months 1 week ago
系统软件与安全实验室2025年春季运动会回顾
Intergenerational Mentoring: Key to Cybersecurity's AI Future
11 months 1 week ago
As threats evolve and technology changes, our ability to work together across generations will determine our success.
Han Cho
Introducing AutoRAG: fully managed Retrieval-Augmented Generation on Cloudflare
11 months 1 week ago
AutoRAG is here: fully managed Retrieval-Augmented Generation (RAG) pipelines powered by Cloudflare's global network and powerful developer ecosystem.
Anni Wang
Cloudflare Workflows is now GA: production-ready durable execution
11 months 1 week ago
Workflows — a durable execution engine built directly on top of Workers — is now Generally Available. We’ve landed new human-in-the-loop capabilities, more scale, and more metrics.
Sid Chatterjee
Cloudflare acquires Outerbase to expand database and agent developer experience capabilities
11 months 1 week ago
Cloudflare has acquired Outerbase, expanding our database and agent developer experience capabilities.
Brandon Strittmatter
CVE-2025-2526 | Streamit Theme up to 4.0.2 on WordPress Email Address edit_profile authorization
11 months 1 week ago
A vulnerability classified as critical was found in Streamit Theme up to 4.0.2 on WordPress. Affected by this vulnerability is the function st_Authentication_Controller::edit_profile of the component Email Address Handler. The manipulation leads to authorization bypass.
This vulnerability is known as CVE-2025-2526. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-2519 | Sreamit Theme up to 4.0.1 on WordPress st_send_download_file information disclosure
11 months 1 week ago
A vulnerability classified as problematic has been found in Sreamit Theme up to 4.0.1 on WordPress. Affected is the function st_send_download_file. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-2519. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2525 | Streamit Theme up to 4.0.1 on WordPress edit_profile unrestricted upload
11 months 1 week ago
A vulnerability was found in Streamit Theme up to 4.0.1 on WordPress. It has been rated as critical. This issue affects the function st_Authentication_Controller::edit_profile. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-2525. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-30195 | PowerDNS Recursor 5.2.0 Resource Record Set null pointer dereference
11 months 1 week ago
A vulnerability was found in PowerDNS Recursor 5.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component Resource Record Set Handler. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2025-30195. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27686 | Dell Unisphere for PowerMax prior 9.2.4.15/10.2.0.9 ldap injection
11 months 1 week ago
A vulnerability was found in Dell Unisphere for PowerMax. It has been classified as problematic. This affects an unknown part. The manipulation leads to ldap injection.
This vulnerability is uniquely identified as CVE-2025-27686. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-0050 | ARM Valhall GPU Userspace Driver up to r49p2/r53p0 memory corruption
11 months 1 week ago
A vulnerability was found in ARM Valhall GPU Userspace Driver and 5th Gen GPU Architecture Userspace Driver up to r49p2/r53p0 and classified as critical. Affected by this issue is some unknown functionality of the component GPU Handler. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2025-0050. Local access is required to approach this attack. There is no exploit available.
vuldb.com
A member of the Scattered Spider cybercrime group pleads guilty
11 months 1 week ago
A 20-year-old man linked to the Scattered Spider cybercrime group has pleaded guilty to charges filed in Florida and California. Noah Urban, a 20-year-old from Palm Coast, pleaded guilty to conspiracy, wire fraud, and identity theft in two federal cases, one in Florida and another in California. “In the California case, he pleaded guilty to […]
Pierluigi Paganini
赏金$10000的漏洞
11 months 1 week ago
Immuta Data Marketplace enhancements accelerate data provisioning
11 months 1 week ago
Immuta announced enhancements to its Data Marketplace solution to help organizations that are increasingly focusing on data-driven decision making and artificial intelligence address the increase in volume of data access requests while minimizing data risk. Upcoming new features such as timebound approvals, dynamic domain assignments, and prevention policies modernize data access workflows – accelerating provisioning and helping data teams keep up with rising request volumes. As data access governance evolves in the agentic AI era, … More →
The post Immuta Data Marketplace enhancements accelerate data provisioning appeared first on Help Net Security.
Industry News
CVE-2025-24244 | Apple macOS Font memory corruption (Nessus ID 233570)
11 months 1 week ago
A vulnerability was found in Apple macOS. It has been declared as critical. This vulnerability affects unknown code of the component Font Handler. The manipulation leads to memory corruption.
This vulnerability was named CVE-2025-24244. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24254 | Apple macOS up to 13.6/14.6/15.3 symlink
11 months 1 week ago
A vulnerability was found in Apple macOS up to 13.6/14.6/15.3. It has been classified as critical. This affects an unknown part. The manipulation leads to symlink following.
This vulnerability is uniquely identified as CVE-2025-24254. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24260 | Apple macOS up to 13.6/14.6/15.3 denial of service
11 months 1 week ago
A vulnerability was found in Apple macOS up to 13.6/14.6/15.3. It has been classified as critical. Affected is an unknown function. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2025-24260. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24257 | Apple macOS App out-of-bounds write
11 months 1 week ago
A vulnerability was found in Apple macOS. It has been classified as critical. Affected is an unknown function of the component App. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2025-24257. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com