Aggregator
Submit #560786: Netgear EX6120 1.0.0.68 Buffer Overflow [Duplicate]
Submit #560785: Netgear EX6120 1.0.0.68 Buffer Overflow [Accepted]
CVE-2025-3341 | codeprojects Online Restaurant Management System 1.0 reservation_view.php ID sql injection
ResolverRAT 通过复杂的网络钓鱼攻击医疗保健和制药行业
Streamlining Global Automotive Cybersecurity Governance to Accelerate Innovation, Assurance, and Compliance
Bringing streamable HTTP transport and Python language support to MCP servers
Revived CryptoJS library is a crypto stealer in disguise
An illicit npm package called 'crypto-encrypt-ts' may appear to revive the unmaintained but vastly popular CryptoJS library, but what it actually does is peek into your crypto wallet and exfiltrate your secrets to threat actors.
The post Revived CryptoJS library is a crypto stealer in disguise appeared first on Security Boulevard.
VeriSource 数据泄露影响了 400 万个人
France links Russian APT28 to attacks on dozen French entities
Silent
DARPA Highlights Critical Infrastructure Security Challenges
CVE-2025-3342 | codeprojects Online Restaurant Management System 1.0 /admin/payment_save.php ID sql injection
CVE-2025-3345 | codeprojects Online Restaurant Management System 1.0 /admin/combo.php del sql injection
CVE-2025-29087 | SQLite up to 3.49.0 concat integer overflow (Nessus ID 234212)
CVE-2025-4115 | Netgear JWNR2000v2 1.0.0.11 default_version_is_new host buffer overflow
CVE-2025-4116 | Netgear JWNR2000v2 1.0.0.11 get_cur_lang_ver host buffer overflow
CVE-2025-4117 | Netgear JWNR2000v2 1.0.0.11 sub_41A914 host buffer overflow
Cato Networks macOS Client Vulnerability Enables Low-Privilege Code Execution
A critical vulnerability in Cato Networks’ widely used macOS VPN client has been disclosed, enabling attackers with limited access to gain full control over affected systems. Tracked as ZDI-25-252 (CVE pending), the flaw highlights mounting risks for enterprises relying on remote-access tools in hybrid work environments. Security firm Zero Day Initiative (ZDI) uncovered the bug, which carries […]
The post Cato Networks macOS Client Vulnerability Enables Low-Privilege Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
TheWizards Deploy ‘Spellbinder Hacking Tool’ for Global Adversary-in-the-Middle Attack
ESET researchers have uncovered sophisticated attack techniques employed by a China-aligned threat actor dubbed “TheWizards,” which has been actively targeting entities across Asia and the Middle East since 2022. The group employs a custom lateral movement tool called Spellbinder that performs adversary-in-the-middle (AitM) attacks using IPv6 SLAAC spoofing, allowing attackers to redirect legitimate software updates […]
The post TheWizards Deploy ‘Spellbinder Hacking Tool’ for Global Adversary-in-the-Middle Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.