Aggregator
CVE-2025-12888 | wolfSSL 5.8.2 X25519 information exposure (Nessus ID 276566)
CVE-2025-12889 | wolfSSL 5.8.4 TLS 1.2 certificate validation (Nessus ID 276559)
CVE-2025-13544 | ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3 /customer_register.php unrestricted upload (EUVD-2025-198562 / CNNVD-202511-2585)
CVE-2025-13545 | ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3 /admin_area/index.php edit_pack sql injection (EUVD-2025-198563 / CNNVD-202511-2586)
CVE-2025-13546 | ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3 Search /results.php user_query sql injection (EUVD-2025-198566 / CNNVD-202511-2584)
On cyber, Trump’s national security strategy emphasizes industry and regional partners
Submit #697380: xerrors Yuxi-Know Yuxi-Know ≤ 0.4.0 Server-Side Request Forgery [Accepted]
«MAX» — наш рулевой. Минцифры решило, что мессенджер защитит нас лучше, чем старые добрые СМС
AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2
A persistent privilege escalation technique in AWS that allows attackers with limited permissions to execute code under higher-privileged execution roles on EC2 instances and SageMaker notebook instances. First documented by Grzelak in 2016 for EC2, the method exploits modifiable boot-time configurations to inject malicious payloads, bypassing standard IAM controls like PassRole. Recent analysis from Security […]
The post AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2 appeared first on Cyber Security News.
React2Shell Vulnerability Under Attack From China-Nexus Groups
Hackers Using CastleRAT Malware to Attack Windows Systems and Gain Remote Access
A new Remote Access Trojan known as CastleRAT has emerged as a growing threat to Windows systems worldwide. First observed around March 2025, this malware enables attackers to gain complete remote control over compromised machines. The threat comes in two main builds: a lightweight Python version and a more powerful compiled C version, with the […]
The post Hackers Using CastleRAT Malware to Attack Windows Systems and Gain Remote Access appeared first on Cyber Security News.