Aggregator
CVE-2025-55623 | Reolink App 4.54.0.4.20250526 on Android ADB improper authentication
CVE-2025-55620 | Reolink App 4.54.0.4.20250526 on Android valuateJavascript cross site scripting
CVE-2025-55624 | Reolink App 4.54.0.4.20250526 on Android intent by broadcast receiver (EUVD-2025-25606)
CVE-2025-9140 | Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7 tabdetail_moduleSave.php getvaluestring sql injection (EDB-52420)
CVE-2025-8908 | Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4 event.php openid sql injection
CVE-2025-8528 | Exrick xboot up to 3.3.4 getMenuList sensitive information in a cookie (Issue 69)
CVE-2024-13273 | Drupal Open Social up to 12.3.7/12.4.4 cross site scripting
XCon x HG 国际黑马会议圆满成功 | 安全锚定 智守未来
Farmers Insurance Breach Exposes Data of 1.1 Million Customers via Salesforce Compromise
Farmers Insurance has disclosed a data breach stemming from unauthorized access to a third-party vendor’s database, potentially compromising the personal information of approximately 1.1 million customers. The breach, detected on May 30, 2025, involved an unauthorized actor infiltrating a system managed by the vendor, which housed sensitive customer data. Farmers, encompassing Farmers Insurance Exchange, Farmers […]
The post Farmers Insurance Breach Exposes Data of 1.1 Million Customers via Salesforce Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-9578 | Acronis Cyber Protect Cloud Agent up to 40733 on Windows permission assignment
What Are the Latest Trends in Cloud Traffic Observability?
Shadow IT Is Expanding Your Attack Surface. Here’s Proof
CVE-2025-3601 | GitLab Community Edition/Enterprise Edition up to 18.1.4/18.2.4/18.3.0 allocation of resources (Issue 536034 / Nessus ID 258045)
CVE-2025-2246 | GitLab Community Edition/Enterprise Edition up to 18.1.4/18.2.4/18.3.0 GraphQL API authorization (Issue 524592 / Nessus ID 258046)
CVE-2025-38475 | Linux Kernel up to 6.12.39/6.15.7 smc cipso_v4_sock_setattr null pointer dereference (Nessus ID 258053 / WID-SEC-2025-1665)
CVE-2025-38453 | Linux Kernel up to 6.15.6/6.16-rc5 msg_ring kfree_rcu allocation of resources (Nessus ID 258053 / WID-SEC-2025-1653)
CVE-2025-38256 | Linux Kernel up to 6.12.35/6.15.4/6.16-rc3 io_uring unpin_user_folio buffer overflow (EUVD-2025-20805 / Nessus ID 258053)
Cisco IMC Virtual Keyboard Video Monitor Let Attacker Direct User to Malicious Website
Cisco disclosed a high-severity open redirect vulnerability in the Virtual Keyboard Video Monitor (vKVM) component of its Integrated Management Controller (IMC). Tracked as CVE-2025-20317 with a CVSS 3.1 base score of 7.1, the vulnerability could enable an unauthenticated remote attacker to redirect administrators or users of affected devices to malicious websites, potentially capturing credentials through […]
The post Cisco IMC Virtual Keyboard Video Monitor Let Attacker Direct User to Malicious Website appeared first on Cyber Security News.
Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33
It is no secret that passwords are highly susceptible to phishing and brute force attacks. This led to the mass adoption of passkeys, a passwordless authentication method leveraging cryptographic key pairs that allows users to log in with biometrics or a hardware key. According to FIDO, over 15 billion accounts have been passkey-enabled, with 69% […]
The post Breaking the Passkey Promise: SquareX Discloses Major Passkey Vulnerability at DEF CON 33 appeared first on Cyber Security News.