Aggregator
Europol Denies $50K Reward for Qilin Ransomware, Calls It a Scam
CVE-2025-55297 | Espressif ESP-IDF up to 5.0.8/5.1.5/5.3.2/5.4.0 buffer overflow (GHSA-9w88-r2vm-qfc4)
How a volunteer-run wildfire site in Portugal stayed online during DDoS attacks
CVE-2025-55420 | FoxCMS 1.2.6 /index.php cross site scripting (EUVD-2025-25450)
CVE-2025-55743 | UnoPim up to 0.2.0 unrestricted upload (GHSA-v22v-xwh7-2vrm / EUVD-2025-25455)
CVE-2025-52395 | Roadcute API 1.0 password recovery (EUVD-2025-25451)
CVE-2025-48956 | vLLM up to 0.0.x HTTP Endpoint resource consumption (GHSA-rxc4-3w6r-4v47)
CVE-2025-57763 | LabRedesCefetRJ WeGIA up to 3.4.6 insere_despacho.php cross site scripting (GHSA-67w3-jf96-f754 / EUVD-2025-25461)
CVE-2025-57765 | LabRedesCefetRJ WeGIA up to 3.4.6 pre_cadastro_adotante.php msg_e cross site scripting (GHSA-39r5-c63f-99mx)
CVE-2025-57764 | LabRedesCefetRJ WeGIA up to 3.4.6 cargos.php msg_e cross site scripting (GHSA-qx7f-q867-cgx2)
CVE-2025-57762 | LabRedesCefetRJ WeGIA up to 3.4.6 dependente_docdependente.php nome cross site scripting (GHSA-494r-43f3-p828 / EUVD-2025-25462)
CVE-2025-57755 | musistudio claude-code-router up to 1.0.33 cross-domain policy (GHSA-8hmm-4crw-vm2c)
Meta 和 OpenAI 的 AI 爬虫对网站造成最严重的负担
CVE-2025-57761 | LabRedesCefetRJ WeGIA up to 3.4.9 dependente_remover.php id_funcionario sql injection (GHSA-fxwc-r5m4-hj62 / EUVD-2025-25464)
CVE-2024-45438 | TitanHQ SpamTitan up to 8.00.100/8.01.13 quarantine.php email improper authorization
NOT-So-Great Firewall: China Blocks the Web for 74 Min.
Xi Whiz: HTTPS connections on port 443 received forged replies.
The post NOT-So-Great Firewall: China Blocks the Web for 74 Min. appeared first on Security Boulevard.
K-12 School Incident Response Plans Fall Short
Warlock Ransomware Exploits SharePoint Flaws for Initial Access and Credential Theft
The Warlock ransomware group has intensified its operations by targeting unpatched on-premises Microsoft SharePoint servers, leveraging critical vulnerabilities to achieve remote code execution and initial network access. This campaign, observed in mid-2025, involves sending crafted HTTP POST requests to upload web shells, facilitating reconnaissance, privilege escalation, and credential theft. Initial Exploitation Attackers exploit flaws like […]
The post Warlock Ransomware Exploits SharePoint Flaws for Initial Access and Credential Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.