Aggregator
CVE-2025-25950 | Serosoft Academia Student Information System EagleR 1.0.118 update access control
CVE-2025-25952 | Serosoft Academia Student Information System EagleR 1.0.118 API Request getStudemtAllDetailsById?studentId=XX resource injection
CVE-2025-25949 | Serosoft Academia Student Information System EagleR 1.0.118 update User ID cross site scripting
CVE-2025-1835 | osuuu LightPicture 1.2.2 /app/controller/Api.php upload file unrestricted upload
CVE-2025-1836 | Incorta 2023.4.3 Edit Insight Service Name csv injection
CVE-2025-1841 | ESAFENET CDG 5.6.3.154.205 ClientSortLog.jsp startDate/endDate sql injection
CVE-2025-1842 | FITSTATS Technologies AthleteMonitoring up to 20250302 /login.php username cross site scripting
CVE-2025-1843 | Mini-Tmall up to 20250211 ProductMapper.java select orderBy sql injection
CVE-2007-1008 | Apple iTunes 7.0.2 memory corruption (EDB-29616 / BID-22615)
JavaGhost: Exploiting Amazon IAM Permissions for Phishing Attacks
Unit 42 researchers have observed a threat actor group known as JavaGhost exploiting misconfigurations in Amazon Web Services (AWS) environments to conduct sophisticated phishing campaigns. Active for over five years, JavaGhost has pivoted from website defacement to leveraging compromised cloud infrastructure for financial gain. The group’s attacks stem from exposed long-term AWS access keys, which […]
The post JavaGhost: Exploiting Amazon IAM Permissions for Phishing Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Симфония страха: хакеры Qilin стали дирижерами Хьюстонского оркестра
MediaTek Warns of Multiple Vulnerabilities that let Attackers Escalate Privileges
MediaTek has issued urgent security advisories warning of multiple high-severity vulnerabilities in its system-on-chip (SoC) architectures, including flaws that enable local privilege escalation (LPE) and remote code execution (RCE). The March 2025 Product Security Bulletin highlights three high severity vulnerabilities CVE-2025-20644, CVE-2025-20645, and CVE-2025-20646—affecting modem firmware, cryptographic key management, and Wi-Fi subsystems. These vulnerabilities impact […]
The post MediaTek Warns of Multiple Vulnerabilities that let Attackers Escalate Privileges appeared first on Cyber Security News.