Aggregator
CVE-2025-0645 | Narkom Pyxis Signage up to 31012025 unrestricted upload
CVE-2025-60798 | phpPgAdmin up to 7.13.0 display.php browseQuery sql injection
CVE-2025-60797 | phpPgAdmin up to 7.13.0 dataexport.php Query sql injection
黑客团伙如何用树莓派入侵银行ATM系统并取款数年
CVE-2025-60738 | Ilevia EVE X1 Server up to 6.00 2025_07_21 ping.php privilege escalation
Security gap in Perplexity’s Comet browser exposed users to system-level attacks
There is a serious security problem inside Comet, the AI-powered agentic browser made by Perplexity, SquareX researchers say: Comet’s MCP API allows the browser’s built-in (but hidden from the user) extensions to issue commands directly to a user’s device, and the capability can be leveraged by attackers. Comet can run applications, read files and modify data on the local system. “Old-school” browsers normally block this level of access, but (some) AI-powered browsers are effectively braking … More →
The post Security gap in Perplexity’s Comet browser exposed users to system-level attacks appeared first on Help Net Security.
D-Link warns of new RCE flaws in end-of-life DIR-878 routers
大脑处理不同语言的基本语音的方式相同
Конец проводов в мозгу навсегда. Нейрочип MOTE питается светом, читает ваши мысли год подряд и передаёт их… световыми вспышками
Работа над ошибками. Xubuntu опубликовала анатомию взлома своего сайта
Turn your Windows 11 migration into a security opportunity
Trust Beyond Containers: Identity and Agent Security Lessons from KubeCon 2025
From secure service mesh rollouts to AI cluster hardening, see how KubeCon + CloudNativeCon NA 2025 redefined identity, trust, and governance in Kubernetes environments.
The post Trust Beyond Containers: Identity and Agent Security Lessons from KubeCon 2025 appeared first on Security Boulevard.
CISA Issues New Guidance on Bulletproof Hosting Threat
Oligo delivers runtime-native security for models and agents
Oligo Security announced new capabilities to protect the broadest spectrum of AI deployments, including AI applications, LLMs, and agentic AI. The new platform modules address the largest blind spot in AI security by securing production AI technologies that remain largely ungoverned, unmonitored, and operating in real time. “AI is moving into production faster than it can be secured, forcing businesses to take greater risks in the name of speedy innovation,” said Nadav Czerninski, CEO, Oligo … More →
The post Oligo delivers runtime-native security for models and agents appeared first on Help Net Security.
Одна буква в ДНК убивала младенца — врачи переписали геном за 6 месяцев и создали лекарство только для него
Intelligence Insights: November 2025
Tsundere Botnet Abusing Popular Node.js and Cryptocurrency Packages to Attack Windows, Linux, and macOS Users
Tsundere represents a significant shift in botnet tactics, leveraging the power of legitimate Node.js packages and blockchain technology to distribute malware across multiple operating systems. First identified around mid-2025 by Kaspersky GReAT researchers, this botnet demonstrates the evolving sophistication of supply chain attacks. The threat originates from activity first observed in October 2024, where attackers […]
The post Tsundere Botnet Abusing Popular Node.js and Cryptocurrency Packages to Attack Windows, Linux, and macOS Users appeared first on Cyber Security News.
Sturnus Banking Malware Steals Communications from Signal and WhatsApp, Gaining Full Control of The Device
A new banking malware called Sturnus has emerged as a significant threat to mobile users across Europe. Security researchers have discovered that this sophisticated Android trojan can capture encrypted messages from popular messaging apps like WhatsApp, Telegram, and Signal by accessing content directly from the device screen after decryption. The malware’s ability to monitor these […]
The post Sturnus Banking Malware Steals Communications from Signal and WhatsApp, Gaining Full Control of The Device appeared first on Cyber Security News.