Aggregator
CVE-2025-13239 | Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution /submit_checkout behavioral workflow (EUVD-2025-197719 / CNNVD-202511-1829)
CVE-2025-6171 | GitLab Community Edition/Enterprise Edition up to 18.3.5/18.4.3/18.5.1 Packages API Endpoint authorization (Patch 549730 / EUVD-2025-197692)
CVE-2025-13250 | WeiYe-Jing datax-web up to 2.1.2 Job remove/update/pause/start/triggerJob access control (EUVD-2025-197730)
CVE-2025-13251 | WeiYe-Jing datax-web up to 2.1.2 sql injection (EUVD-2025-197731)
CVE-2025-12859 | DedeBIZ up to 6.3.2 templets_one_edit.php ids sql injection
CVE-2025-12860 | DedeBIZ up to 6.3.2 /admin/freelist_main.php orderby sql injection
CVE-2025-59288 | Microsoft Playwright signature verification (EUVD-2025-34363 / Nessus ID 270369)
SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely
SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service attacks. The vulnerability was internally discovered and reported by SonicWall’s security team. The flaw, tracked as CVE-2025-40601, carries a CVSS score of 7.5 and affects multiple generations of SonicWall firewall products. Field […]
The post SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely appeared first on Cyber Security News.
OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently
OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The new system represents a significant leap in agentic AI capabilities, enabling machines to work on coding projects with minimal human intervention. GPT-5.1-Codex-Max operates differently from general-purpose AI models. Built specifically for software engineering, the model features compaction technology that enables it to […]
The post OpenAI Releases GPT-5.1-Codex-Max that Performs Coding Tasks Independently appeared first on Cyber Security News.
YAML 语法详解
用友 U8 Cloud NCCloudGatewayServlet 命令执行漏洞
Hacker claims to steal 2.3TB data from Italian rail group, Almaviva
What insurers really look at in your identity controls
Insurers judge organizations by the strength of their identity controls and by how consistently those controls are applied, according to a new Delinea report. CISOs are entering a market that rewards maturity and penalizes gaps that once passed without scrutiny. Control maturity is the baseline for insurability Nearly all security leaders said they were required to have at least some security controls in place before coverage was approved. Insurers expect organizations to show progress in … More →
The post What insurers really look at in your identity controls appeared first on Help Net Security.
Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations
The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions against Media Land. This Russia-based bulletproof hosting company provides infrastructure to ransomware and other cybercriminals. The U.S. Federal Bureau of Investigation also coordinated the action targeting the company’s leadership team and related entities. Bulletproof hosting providers offer specialized servers designed […]
The post Authorities Sanctioned Russia-based Bulletproof Hosting Provider for Supporting Ransomware Operations appeared first on Cyber Security News.