Aggregator
CVE-2025-4315 | CubeWP Plugin up to 1.1.23 on WordPress update_user_meta privileges management (EUVD-2025-18093)
CVE-2025-25478 | SysPass 3.2.x Filename unrestricted upload (EUVD-2025-5922)
CVE-2025-25476 | SysPass 3.2.x Notification cross site scripting (EUVD-2025-5921)
CVE-2025-25461 | SeedDMS 6.0.29 Category Name cross site scripting (EUVD-2025-5943)
CVE-2025-49465 | Zoom Workplace up to 6.3.x on Windows buffer overflow
McDonald’s AI Hiring Bot With Password ‘123456’ Leaks Millions of Job-Seekers Data
A severe security vulnerability in McDonald’s AI-powered hiring system has exposed the personal information of potentially 64 million job applicants to unauthorized access. Key Takeaways1. McDonald's AI hiring bot exposed 64 million job applicants' personal data through weak security using password "123456."2. Researchers accessed the entire system in 30 minutes using simple password guessing and […]
The post McDonald’s AI Hiring Bot With Password ‘123456’ Leaks Millions of Job-Seekers Data appeared first on Cyber Security News.
Fake online stores look real, rank high, and trap unsuspecting buyers
Shopping on a fake online store can lead to more than a bad purchase. It could mean losing money, having your identity stolen, or even getting malware on your device. E-shop scams rose by 790% in the first quarter of 2025 compared to the same period in 2024, according to Avast. Cybercriminals might be exploiting economic uncertainty as rising tariffs push consumers to seek cheaper deals online. This makes it easier to trick people with … More →
The post Fake online stores look real, rank high, and trap unsuspecting buyers appeared first on Help Net Security.
CVE-2025-32023
CVE-2025-6491
十年博弈 - ViewState RCE的前世今生
十年博弈 - ViewState RCE的前世今生
Open source has a malware problem, and it’s getting worse
Sonatype has published its Q2 2025 Open Source Malware Index, identifying 16,279 malicious open source packages across major ecosystems such as npm and PyPI. This brings the total number of malware packages discovered by the company to 845,204. Compared to the same quarter last year, the volume of detected malware has jumped by 188%, highlighting the escalating scale and sophistication of attacks targeting developers, software teams, and CI/CD pipelines. “Attackers are no longer simply experimenting … More →
The post Open source has a malware problem, and it’s getting worse appeared first on Help Net Security.