A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. This vulnerability affects unknown code of the file /admin/editempeducation.php. The manipulation of the argument yopgra leads to sql injection.
This vulnerability was named CVE-2025-6300. The attack can be initiated remotely. Furthermore, there is an exploit available.
Global Tensions Are Driving Demand for Cybersecurity Jobs Cybersecurity professionals are finding themselves on the front lines of a different kind of battlefield - one that spans global networks, targets civilian infrastructure and operates continuously across borders. Follow these steps to prepare for a career in cyber defense.
Global Tensions Are Driving Demand for Cybersecurity Jobs Cybersecurity professionals are finding themselves on the front lines of a different kind of battlefield - one that spans global networks, targets civilian infrastructure and operates continuously across borders. Follow these steps to prepare for a career in cyber defense.
Shanghai Firm Bets on Open-Source Strategy, Efficiency Claims Shanghai artificial intelligence startup MiniMax released a new open-source large language model, positioning it as a direct competitor to American and other Chinese models. MiniMax says its model performs competitively on benchmark tests against leading proprietary and open models.
Crime Gang Begins Leaking Stolen Freedman HealthCare Data Cybercriminal gang World Leaks - formerly Hunters International - reportedly claims to have stolen 52.4 gigabytes of data containing 42,204 files from Massachusetts-based Freedman HealthCare, a contractor that provides data integration and analytics services to state health agencies.
Iranian Officials Call Internet Outages Intentional to Disrupt Israeli Operations Iranian officials said widespread internet outages were deliberate and meant to disrupt covert Israeli operations within the country following days of missile attacks from Israel and a rapidly escalating regional conflict that experts warn could trigger major cyberattacks on critical infrastructure.
Deal Expands Native Email Security and Response Workflows for MDR and MSP Clients Bitdefender’s acquisition of Irish startup Mesh adds native email protection to its XDR and MDR portfolios. Mesh’s dual-mode defense and MSP-friendly design provide deeper visibility, faster remediation and enhanced threat response across hybrid environments.
A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the argument targetAPSsid leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-6299. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.