Aggregator
CVE-2025-58714 | Microsoft Windows up to Server 2025 Ancillary Function Driver for WinSock access control (EUVD-2025-34321)
CVE-2025-55699 | Microsoft Windows up to Server 2025 Kernel information disclosure (EUVD-2025-34322)
CVE-2025-13051 | ASUSTOR ABP/AES uncontrolled search path (EUVD-2025-198124 / CNNVD-202511-2269)
CVE-2025-12777 | YITH WooCommerce Wishlist Plugin up to 4.10.0 on WordPress AJAX lists authorization (EUVD-2025-198126 / CNNVD-202511-2270)
CVE-2025-6251 | Royal Elementor Addons and Templates Plugin up to 1.7.1036 on WordPress item['field_id'] cross site scripting (EUVD-2025-198115 / CNNVD-202511-2259)
Inside Iran's Cyber Objectives: What Do They Want?
JVN: 複数のAutomated Logic製品における複数の脆弱性
New infosec products of the week: November 21, 2025
Here’s a look at the most interesting products from the past week, featuring releases from Bedrock Data, Immersive, Kentik, Minimus, and Synack. Kentik AI Advisor brings intelligence and automation to network design and operations Kentik has launched the Kentik AI Advisor, an agentic AI solution that understands enterprise and service provider networks, thinks critically, and offers guidance for designing, operating, and protecting infrastructure at scale. Bedrock Data expands platform with AI governance and natural-language policy … More →
The post New infosec products of the week: November 21, 2025 appeared first on Help Net Security.
JVN: iCam365製CCTVカメラにおける複数の脆弱性
JVN: 複数のOpto 22製品における複数の脆弱性
JVN: 複数のFesto製品における複数の脆弱性
JVN: Emerson製Appleton UPSMON-PROにおけるスタックベースのバッファオーバーフローの脆弱性
CVE-2025-7895 | harry0703 MoneyPrinterTurbo up to 1.2.6 File Extension video.py upload_bgm_file unrestricted upload (EUVD-2025-22024)
CVE-2025-7896 | harry0703 MoneyPrinterTurbo up to 1.2.6 video.py download_video/delete_video path traversal (EUVD-2025-22020)
CVE-2025-7897 | harry0703 MoneyPrinterTurbo up to 1.2.6 API Endpoint app/controllers/base.py verify_token missing authentication (EUVD-2025-22019)
CVE-2025-38261 | Linux Kernel up to 6.15.4 riscv put_user buffer overflow (EUVD-2025-20800 / Nessus ID 271193)
AI"投毒"已成产业:从特斯拉到华尔街,揭秘入侵物理世界的AI攻击真相
Gartner预测:2030年超四成企业将因"影子AI"遭遇安全事件;公考季诈骗套路升级:网警揭露六大常见陷阱 | 牛览
Salesforce Confirms that Customers’ Data Was Accessed Following the Gainsight Breach
Salesforce has issued a critical security alert identifying “unusual activity” involving Gainsight-published applications connected to customer environments. The CRM giant’s investigation indicates that this activity may have enabled unauthorized access to Salesforce data through the applications’ external connections. In an immediate response to contain the threat, Salesforce has revoked all active access and refresh tokens […]
The post Salesforce Confirms that Customers’ Data Was Accessed Following the Gainsight Breach appeared first on Cyber Security News.