Aggregator
CVE-2010-0185 | Adobe ColdFusion 9.0 Default Configuration access control (ID 116853 / XFDB-55997)
Released: MITRE ATT&CK v17.0, now with ESXi attack TTPs
MITRE has released the latest version of its ATT&CK framework, which now also includes a new section (“matrix”) to cover the tactics, techniques and procedures (TTPs) used to target VMware ESXi hypervisors. About MITRE ATT&CK MITRE ATT&CK is a regularly updated public knowledge base that charts how real-world threat actors behave. It also lists known/documented threat actor groups, malware, and (some) past high-profile campaigns. It’s used by cyber defenders and vendors for threat modeling and … More →
The post Released: MITRE ATT&CK v17.0, now with ESXi attack TTPs appeared first on Help Net Security.
NinjaOne unifies vulnerability and patch management
NinjaOne announced new capabilities that unify vulnerability management and patching workflows, ensuring a risk-based approach to patching and reducing time to remediate vulnerabilities. The new tools automate the import of vulnerability data, giving IT teams continuous visibility into vulnerabilities, so they can prioritize and verify the successful applicationof patches, reducing organizations’ risk. “The rapid growth in the number and diversity of endpoint devices, driven by hybrid work and digital transformation, has significantly expanded organizational attack … More →
The post NinjaOne unifies vulnerability and patch management appeared first on Help Net Security.
CVE-2025-2595 | CODESYS Visualization up to 4.7.x Template direct request (VDE-2025-027)
Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices
INC
CVE-2010-0248 | Microsoft Internet Explorer 6/7/8 code injection (MS10-002 / Nessus ID 44110)
CVE-2009-3861 | Safenet-inc SoftRemote up to 10.8.8 memory corruption (Nessus ID 70121 / XFDB-54083)
CVE-2009-4006 | Serv-U up to 9.1.0.0 memory corruption (Nessus ID 42934 / XFDB-54322)
Marine onderschept 3 drugstransporten in een week
CVE-2025-3454 | Grafana 10.4.0 Data Source Proxy API improper authorization
CVE-2025-2703 | Grafana/Grafana Enterprise XY Chart Plugin cross site scripting
CVE-2025-2595 | CODESYS Visualization up to 4.7.x Template direct request (VDE-2025-027)
CVE-2024-10306 | Red Hat Enterprise Linux/JBoss Core Services mod_proxy_cluster authorization
CVE-2025-42603 | Meon KYC Solutions 1.1 API Endpoint cleartext transmission (CIVN-2025-0082)
CVE-2025-42602 | Meon KYC Solutions 1.1 API Endpoint session expiration (CIVN-2025-0082)
CVE-2025-42605 | Meon Bidding Solutions 1.2 API Endpoint authorization (CIVN-2025-0082)
CVE-2025-42604 | Meon KYC Solutions 1.1 API Endpoint debug messages revealing unnecessary information (CIVN-2025-0082)
RBI Directs All Indian Banks to Transition to .bank.in Domains
The Reserve Bank of India (RBI) has issued a directive requiring all banking institutions in the country to migrate their web presence to the new .bank.in domain by October 31, 2025. This landmark cybersecurity initiative aims to create a more secure digital banking ecosystem and combat the rising threat of phishing attacks targeting Indian banking […]
The post RBI Directs All Indian Banks to Transition to .bank.in Domains appeared first on Cyber Security News.