Aggregator
CVE-2025-20156 | Cisco Meeting Management up to 3.9.0 REST API insufficient privileges (cisco-sa-cmm-privesc-uy2Vf8pc)
CVE-2025-30212 | Frappe up to 14.88.x/15.50.x sql injection
CVE-2025-30213 | Frappe up to 14.90.x/15.51.x stack-based overflow (GHSA-v342-4xr9-x3q3)
CVE-2025-30214 | Frappe up to 14.88.x/15.50.x Requests information disclosure (GHSA-qrv3-jc3h-f3m6)
CVE-2025-20297 | Splunk Enterprise/Cloud Platform REST Endpoint cross site scripting (SVD-2025-0601 / EUVD-2025-16671)
SecWiki News 2025-08-01 Review
面向LLM时代全尺寸现代知识图谱的精确检索基准CYPHERBENCH by ourren
筑牢Tor网络实验中统计推理的根基 by ourren
利用跨层RTT区分代理流量指纹 by ourren
传输层混淆:在TLS层规避SNI审查 by ourren
MirageFlow:一种针对 Tor 的新型带宽膨胀攻击 by ourren
更多最新文章,请访问SecWiki
CVE-2025-7845 | Stratum Plugin up to 1.6.0 on WordPress Google Maps Widget/Image Hotspot Widgets cross site scripting (EUVD-2025-23332)
男子的十字架纹身神秘消失然后皮肤开始坏死
Meta Offers $1M bounty at Pwn2Own Ireland 2025 for WhatsApp exploits
Lazarus Hackers Weaponize 234 npm and PyPI Packages to Infect Developers
Sonatype’s automated detection systems have uncovered an expansive and ongoing infiltration of the global open-source ecosystem by the notorious Lazarus Group, a threat actor believed to be backed by North Korea’s Reconnaissance General Bureau. Between January and July 2025, Sonatype identified and blocked 234 malicious software packages deployed through both the npm and PyPI open-source […]
The post Lazarus Hackers Weaponize 234 npm and PyPI Packages to Infect Developers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Koske Marks a Significant Step in AI-Created Malware: Aqua Security
Aqua Security detected "Koske," a cryptomining malware that brings malicious code closer to being as good or better than malware created by humans and includes indicators that it was developed with the use of a large language model.
The post Koske Marks a Significant Step in AI-Created Malware: Aqua Security appeared first on Security Boulevard.