Aggregator
React security advisory (AV25-834)
1 week 1 day ago
Canadian Centre for Cyber Security
Дорого, мощно, глупо. Хакеры продали «элитный» софт на тысячи долларов, но забыли зашифровать C2-трафик
1 week 1 day ago
Платформа Weyhro C2 внедряет код в легитимные процессы системы для развёртывания невидимой рабочей среды.
Submit #707107: ctcms 2.1.2 Command Injection [Duplicate]
1 week 1 day ago
Submit #707107 / VDB-336488
airrudder
Submit #707106: ctcms 2.1.2 Command Injection [Accepted]
1 week 1 day ago
Submit #707106 / VDB-336488
airrudder
Submit #707105: ctcms 2.1.2 Command Injection [Accepted]
1 week 1 day ago
Submit #707105 / VDB-336487
airrudder
Submit #707104: ctcms 2.1.2 Command Injection [Accepted]
1 week 1 day ago
Submit #707104 / VDB-336486
airrudder
HPE security advisory (AV25-833)
1 week 1 day ago
Canadian Centre for Cyber Security
RALord
1 week 1 day ago
You must login to view this content
cohenido
700Credit data breach impacts 5.8 million vehicle dealership customers
1 week 1 day ago
700Credit, a U.S.-based financial services and fintech company, will start notifying more than 5.8 million people that their personal information has been exposed in a data breach incident. [...]
Bill Toulas
Dark Net Drug Operation “SocialPharma” Dismantled as Four Men Jailed
1 week 1 day ago
Dark Net Drug Operation “SocialPharma” Dismantled as Four Men Jailed
Dark Web Informer
Third Defendant Pleads Guilty in Fantasy Sports Betting Hack Case
1 week 1 day ago
A Minnesota man has pleaded guilty to a credential stuffing scheme that compromised over 60,000 accounts
Microsoft Edge security advisory (AV25-832)
1 week 1 day ago
Canadian Centre for Cyber Security
Топ-3 в России, на очереди — СНГ. Российский PT NGFW выходит на рынок Беларуси
1 week 1 day ago
Лаборатория BI.ZONE подтвердила скорость PT NGFW.
GitHub Scanner for React2Shell (CVE-2025-55182) Turns Out to Be Malware
1 week 1 day ago
A GitHub repository posing as a vulnerability scanner for CVE-2025-55182, also referred to as “React2Shell,” was exposed as…
Waqas
美国 Z 世代再次青睐实体媒介
1 week 1 day ago
2010 年代以来流媒体支配了媒体消费,实体媒介如 DVD 和 CD 的销量随之下滑。但实体媒介仍然在流通,最近几年部分类型的实体媒介的销量还出现了反弹。推动这一趋势的驱动力量之一是 Z 世代,流媒体服务日益昂贵,而 3-5 美元的实体 DVD 可能比购买数字版更便宜,而且能真正拥有所有权。实体 CD 交易平台 Discogs 今年的销量比去年同期增长 8%。行业组织 Digital Entertainment Group 的数据显示,DVD、蓝光和 4K 超高清蓝光光盘的销量在第三季度比去年同期下降 3%,而去年同期则下降了近 26%。美国唱片行业协会 RIAA 预测,2024 年 CD 销量将同比增长 1.5%。黑胶唱片的销量则在 2023 年就超过了 CD。
ServiceNow in Advanced Talks to Acquire Armis for $7 Billion: Reports
1 week 1 day ago
ServiceNow Inc. is in advanced talks to acquire cybersecurity startup Armis in a deal that could reach $7 billion, its largest ever, according to reports. Bloomberg News first reported the discussions over the weekend, noting that an announcement could come within days. However, sources cautioned that the deal could still collapse or attract competing bidders...
The post ServiceNow in Advanced Talks to Acquire Armis for $7 Billion: Reports appeared first on Security Boulevard.
Jon Swartz
Alleged Data Breach of Australian Real Estate Sector includes 1.2M Records
1 week 1 day ago
Alleged Data Breach of Australian Real Estate Sector includes 1.2M Records
Dark Web Informer
CVE-2025-4576 | Liferay Portal/DXP entry_cover_image_caption.jsp cross site scripting
1 week 1 day ago
A vulnerability has been found in Liferay Portal and DXP and classified as problematic. This impacts an unknown function of the file modules/apps/blogs/blogs-web/src/main/resources/META-INF/resources/blogs/entry_cover_image_caption.jsp. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-4576. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-14003 | Image Gallery Plugin up to 2.13.3 on WordPress add_images_to_gallery_callback authorization (EUVD-2025-203368)
1 week 1 day ago
A vulnerability marked as problematic has been reported in Image Gallery Plugin up to 2.13.3 on WordPress. Affected is the function add_images_to_gallery_callback. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2025-14003. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com