Aggregator
CVE-2022-3046 | Google Chrome up to 104.0.5112.102 Browser Tag use after free (FEDORA-2022-3f28aa88cf / Nessus ID 211177)
HPE security advisory (AV25-289)
Ivanti EPMM flaw exploited by Chinese hackers to breach govt agencies
CVE-2005-4671 | CityPost Simple PHP Upload 5.3 simple-upload-53.php Message cross site scripting (EDB-25464 / XFDB-20164)
New Signal update stops Windows from capturing user chats
Multiple GitLab Vulnerabilities Let Attackers Trigger DoS Attacks
GitLab has released critical security patches addressing 11 vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE) platforms, with several high-risk flaws enabling denial-of-service (DoS) attacks. The coordinated release of versions 18.0.1, 17.11.3, and 17.10.7 comes as the DevOps platform confronts multiple attack vectors that could destabilize systems through resource exhaustion, authentication bypasses, and […]
The post Multiple GitLab Vulnerabilities Let Attackers Trigger DoS Attacks appeared first on Cyber Security News.
CVE-2006-0663 | IBM Lotus Domino iNotes Client 6.5.4 Domino Web Access cross site scripting (EDB-27181 / XFDB-24614)
Coinbase Breach Affected Almost 70,000 Customers
Versa Concerto 0-Day Authentication Bypass Vulnerability Allows Remote Code Execution
Significant vulnerabilities were uncovered in Versa Concerto, a widely deployed SD-WAN orchestration platform used by major enterprises and government entities. The flaws include authentication bypass vulnerabilities that can be chained to achieve remote code execution and complete system compromise. Despite responsible disclosure efforts beginning in February 2025, these critical issues remain unpatched, leaving organizations vulnerable […]
The post Versa Concerto 0-Day Authentication Bypass Vulnerability Allows Remote Code Execution appeared first on Cyber Security News.
Coaching Needed to Clear Network Operations Hurdles
Security Threats of Open Source AI Exposed by DeepSeek
Когда миллиардные штрафы — не удар, а просто пункт в бюджете: Big Tech учится жить под прицелом юристов
Chinese hackers breach US local governments using Cityworks zero-day
NIST Proposes Security Metric to Determine Likely Exploited Vulnerabilities
The U.S. National Institute of Standards and Technology (NIST) has unveiled a groundbreaking security metric designed to estimate which software vulnerabilities have likely been exploited, even if organizations don’t yet know it. Published on May 19, 2025, as NIST CSWP 41, the “Likely Exploited Vulnerabilities: A Proposed Metric for Vulnerability Exploitation Probability” paper by Peter […]
The post NIST Proposes Security Metric to Determine Likely Exploited Vulnerabilities appeared first on Cyber Security News.
StackHawk raises $12 million to help security teams tackle AI-powered dev cycles
StackHawk, the shift-left API security platform, announced it has taken on $12 million in additional funding from Sapphire and Costanoa Ventures to help security teams keep up with the pace of AI-driven development. With this funding, StackHawk will expedite shipping products and features that make it simple for modern teams embracing AI-driven development to scale safely, especially in data-sensitive industries such as healthcare and fintech. Sapphire and Costanoa Ventures also co-led StackHawk’s Series B funding … More →
The post StackHawk raises $12 million to help security teams tackle AI-powered dev cycles appeared first on Help Net Security.