Aggregator
CVE-2024-36453 | Webmin/Usermin session_login.cgi cross site scripting
CVE-2024-36450 | Webmin up to 1.900 sysinfo.cgi cross site scripting
CVE-2024-6447 | FULL Plugin up to 3.1.12 on WordPress Parameter License Plan cross site scripting
CVE-2024-6649 | SourceCodester Employee and Visitor Gate Pass Logging System 1.0 Users.php save_users cross-site request forgery
Report: The State of Secrets Sprawl 2025
GitGuardian’s State of Secrets Sprawl 2025 report shows no progress in combating secrets sprawl, with 23.8 million secrets leaked on public GitHub repositories in 2024—a 25% year-over-year increase. Despite GitHub Push Protection’s efforts, secrets sprawl is accelerating, especially with generic secrets, which made up 58% of all leaked credentials. More troubling, 70% of secrets leaked in 2022 remain active, significantly expanding the attack surface for threat actors. The report makes one thing clear: secrets management … More →
The post Report: The State of Secrets Sprawl 2025 appeared first on Help Net Security.
Vanta strengthens collaboration between security and GRC teams
Vanta announced a series of new features and capabilities to help security and GRC teams seamlessly collaborate across their organization and extended network. These releases—including team-based collaboration and granular user access, an integrated Vanta Exchange for vendor security reviews, enhanced audit capabilities and expanded security questionnaire automation—reduce manual processes and enable companies to manage trust as a team. With 65% of businesses reporting that customers, investors and suppliers increasingly require proof of compliance, maintaining a … More →
The post Vanta strengthens collaboration between security and GRC teams appeared first on Help Net Security.
Why Cybersecurity Needs More Business-Minded Leaders
752,000 Browser Phishing Attacks Mark 140% Increase YoY
Обновитесь или платите: Microsoft раскрывает будущее Windows 10 после 2025 года
CVE-2023-32110 | JupiterX Theme Plugin up to 3.0.0 on WordPress print_pane file inclusion
CVE-2023-38388 | JupiterX Core Premium Plugin up to 3.3.5 on WordPress unrestricted upload
CVE-2025-28857 | rankchecker Rankchecker.io Integration Plugin up to 1.0.9 on WordPress cross-site request forgery
Decoding a Malware Analyst: Essential Skills and Expertise
Malware analysis is a promising yet competitive career path, where education must be taken seriously to stand up against ever-evolving threats. The demand for such professionals has never been higher, but the requirements and expectations are not low either. A specific mindset and a number of well-developed soft skills are no less vital than a […]
The post Decoding a Malware Analyst: Essential Skills and Expertise appeared first on ANY.RUN's Cybersecurity Blog.
Leaked Black Basta Chats Suggest Russian Officials Aided Leader's Escape from Armenia
CVE-2017-2454 | Apple tvOS up to 10.1 WebKit memory corruption (HT207601 / EDB-41807)
APTs have been using zero-day Windows shortcut exploit for eight years (ZDI-CAN-25373)
State-sponsored threat actors and cybercrime groups from North Korea, Iran, Russia, and China have been exploiting a zero-day Windows vulnerability with no fix in sight for the last eight years, researchers with Trend Micro’s Zero Day Initiative have warned on Tuesday. The vulnerability, which doesn’t have a CVE number but is being tracked as ZDI-CAN-25373 by ZDI researchers, allowed attackers to surreptitiously execute malicious commands on a victim’s machine and deliver a variety of malware … More →
The post APTs have been using zero-day Windows shortcut exploit for eight years (ZDI-CAN-25373) appeared first on Help Net Security.
1Kosmos 1Key secures shared login environments and OT systems
1Kosmos announced 1Kosmos 1Key for shared account login environments. With FIDO-compliant biometric authentication, 1Kosmos 1Key addresses the pressing need for security, accountability, and auditability in settings where multiple users access shared accounts, such as operational technology (OT) systems, hospitality services, and other collaborative workspaces. Shared accounts are commonly used in both IT and OT environments where many users interact with a single workstation or application. However, shared access can also lead to security vulnerabilities, accountability … More →
The post 1Kosmos 1Key secures shared login environments and OT systems appeared first on Help Net Security.