Aggregator
Grafana Flaws Allow User Redirection and Code Execution in Dashboards
Grafana Labs has released critical security patches addressing two significant vulnerabilities that could enable attackers to redirect users to malicious websites and execute arbitrary code within dashboard environments. The security update addresses CVE-2025-6023, a high-severity cross-site scripting (XSS) vulnerability, and CVE-2025-6197, a medium-severity open redirect flaw, both discovered through the company’s bug bounty program. Critical […]
The post Grafana Flaws Allow User Redirection and Code Execution in Dashboards appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Threat Actors Weaponizing GitHub Accounts To Host Payloads, Tools and Amadey Malware Plug-Ins
A sophisticated Malware-as-a-Service operation has emerged that exploits the trusted GitHub platform to distribute malicious payloads, representing a significant evolution in cybercriminal tactics. The operation leverages fake GitHub accounts to host an arsenal of malware tools, plugins, and payloads, capitalizing on GitHub’s widespread corporate acceptance to bypass traditional web filtering mechanisms. The malicious campaign targets […]
The post Threat Actors Weaponizing GitHub Accounts To Host Payloads, Tools and Amadey Malware Plug-Ins appeared first on Cyber Security News.
CVE-2025-7807 | Tenda FH451 1.0.0.9 /goform/SafeUrlFilter fromSafeUrlFilter Go/page stack-based overflow (EUVD-2025-21934)
CVE-2025-7806 | Tenda FH451 1.0.0.9 /goform/SafeClientFilter fromSafeClientFilter Go/page stack-based overflow (EUVD-2025-21935)
CVE-2025-7805 | Tenda FH451 1.0.0.9 /goform/PPTPUserSetting fromPptpUserSetting delno stack-based overflow (EUVD-2025-21933)
Борьба за звание Властелина космоса началась. Половина человечества — завидуй молча
CVE-2024-53054 | Linux Kernel up to 6.1.115/6.6.59/6.11.6 cgroup hung_task deadlock (Nessus ID 211777 / WID-SEC-2024-3509)
CVE-2024-53057 | Linux Kernel up to 6.11.6 qdisc_tree_reduce_backlog iteration (Nessus ID 211777 / WID-SEC-2024-3509)
Submit #616352: Tenda FH451 v1.0.0.9 Buffer Overflow [Duplicate]
Submit #616350: Tenda FH451 v1.0.0.9 Buffer Overflow [Accepted]
Submit #616349: Tenda FH451 v1.0.0.9 Buffer Overflow [Duplicate]
Microsoft Defender for Office 365 Launches New Dashboard for Enhanced Threat Vector Insights
Microsoft today announced the rollout of a revamped customer dashboard in Microsoft Defender for Office 365, designed to deliver unprecedented insights across a broad spectrum of attack vectors. The new interface gives security teams real-time visibility into threats blocked before delivery, malicious content remediated post-delivery, and even “missed” incidents, all without sacrificing privacy or performance. […]
The post Microsoft Defender for Office 365 Launches New Dashboard for Enhanced Threat Vector Insights appeared first on Cyber Security News.
Submit #616348: Tenda FH451 v1.0.0.9 Buffer Overflow [Accepted]
Submit #616347: Tenda FH451 v1.0.0.9 Buffer Overflow [Accepted]
诚邀渠道合作伙伴共启新征程
微信安全漏洞复现:无感执行远程代码
Ubiquiti UniFi Vulnerability Lets Hackers Inject Malicious Commands
A critical security vulnerability has been discovered in Ubiquiti’s UniFi Access devices that could allow malicious actors to inject and execute arbitrary commands on affected systems. The vulnerability, designated as CVE-2025-27212, affects multiple UniFi Access products and carries a maximum CVSS score of 9.8, indicating its severe nature and potential for widespread exploitation. Vulnerability Details […]
The post Ubiquiti UniFi Vulnerability Lets Hackers Inject Malicious Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Akira
You must login to view this content