Aggregator
安全运营 | “纵深防护·极智运营”北京站·第十期「度安讲」 技术沙龙开放报名
8 months 3 weeks ago
How we train AI to uncover malicious JavaScript intent and make web surfing safer
8 months 3 weeks ago
Learn more about how Cloudflare developed an AI model to uncover malicious JavaScript intent using a Graph Neural Network, from pre-processing data to inferencing at scale.
Juan Miguel Cejuela
An early look at cryptographic watermarks for AI-generated content
8 months 3 weeks ago
It's hard to tell the difference between web content produced by humans and web content produced by AI. We're taking new approach to making AI content distinguishable without impacting performance.
Teresa Brooks-Mejia
Trapping misbehaving bots in an AI Labyrinth
8 months 3 weeks ago
How Cloudflare uses generative AI to slow down, confuse, and waste the resources of AI Crawlers and other bots that don’t respect “no crawl” directives.
Reid Tatoris
Take control of public AI application security with Cloudflare's Firewall for AI
8 months 3 weeks ago
Firewall for AI discovers and protects your public LLM-powered applications, and is seamlessly integrated with Cloudflare WAF. Join the beta now and take control of your generative AI security.
Radwa Radwan
Improved Bot Management flexibility and visibility with new high-precision heuristics
8 months 3 weeks ago
By building and integrating a new heuristics framework into the Cloudflare Ruleset Engine, we now have a more flexible system to write rules and deploy new releases rapidly.
Curtis Lowder
安全运营 | “纵深防护·极智运营”北京站·第十期「度安讲」 技术沙龙开放报名
8 months 3 weeks ago
CVE-2025-2511 | mitchelllevy AHAthat Plugin up to 1.6 on WordPress ID sql injection
8 months 3 weeks ago
A vulnerability was found in mitchelllevy AHAthat Plugin up to 1.6 on WordPress. It has been classified as critical. Affected is an unknown function. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2025-2511. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-13933 | Chimpstudio FoodBakery Plugin up to 4.7 on WordPress cross-site request forgery
8 months 3 weeks ago
A vulnerability was found in Chimpstudio FoodBakery Plugin up to 4.7 on WordPress and classified as problematic. This issue affects the function foodbakery_var_backup_file_delete/foodbakery_widget_file_delete/theme_option_save/export_widget_settings/ajax_import_widget_data/foodbakery_var_settings_backup_generate/foodbakery_var_backup_file_restore/theme_option_rest_all. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-13933. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-13442 | aonetheme Service Finder Bookings Plugin up to 5.0 on WordPress authentication bypass
8 months 3 weeks ago
A vulnerability has been found in aonetheme Service Finder Bookings Plugin up to 5.0 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass using alternate channel.
This vulnerability was named CVE-2024-13442. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-2512 | thomstark File Away Plugin up to 3.9.9.0.1 on WordPress upload unrestricted upload
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in thomstark File Away Plugin up to 3.9.9.0.1 on WordPress. This affects the function Upload. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-2512. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Капча просит клик – кошелек опустошен: ClearFake прячет вредоносные скрипты в смарт-контрактах Binance
8 months 3 weeks ago
За фальшивыми проверками безопасности скрывается изощрённая стелс-атака.
国际业务 GTV 突破 900 亿,2024 年滴滴出海扛起增长「大旗」
8 months 3 weeks ago
滴滴已经变了,需要重新认识。
[Meachines] [Medium] Sneaky snmp+SSH-IPV6+BOF-NOP-Sled权限提升
8 months 3 weeks ago
#snmp #SQLI #SSH #IPV6 #BOF #NOP-Sled权限提升
Хакеры получают полный контроль над промышленными системами через mySCADA myPRO
8 months 3 weeks ago
Как всего один POST-запрос может остановить работу целого предприятия.
CVE-2024-50631 | Synology Drive Server sql injection (SA_24_21)
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Synology Drive Server. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-50631. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30235 | Shearwater SecurEnvoy SecurAccess Enrol up to 9.4.514 race condition
8 months 3 weeks ago
A vulnerability was found in Shearwater SecurEnvoy SecurAccess Enrol up to 9.4.514. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to race condition.
This vulnerability is known as CVE-2025-30235. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30236 | Shearwater SecurEnvoy SecurAccess Enrol up to 9.4.514 HTTP POST Request external control of assumed-immutable web parameter
8 months 3 weeks ago
A vulnerability was found in Shearwater SecurEnvoy SecurAccess Enrol up to 9.4.514. It has been rated as critical. Affected by this issue is some unknown functionality of the component HTTP POST Request Handler. The manipulation leads to external control of assumed-immutable web parameter.
This vulnerability is handled as CVE-2025-30236. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1232 | Paul Ryley Site Reviews Plugin up to 7.2.4 on WordPress Review cross site scripting
8 months 3 weeks ago
A vulnerability classified as problematic has been found in Paul Ryley Site Reviews Plugin up to 7.2.4 on WordPress. This affects an unknown part of the component Review Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-1232. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com