Aggregator
CVE-2025-0150 | Zoom Workplace App/Meeting SDK up to 6.2.x on iOS denial of service
CVE-2025-43239 | Apple macOS up to 13.6/14.6/15.5 File out-of-bounds (Nessus ID 243030)
CVE-2025-43241 | Apple macOS up to 13.6/14.6/15.5 Restrictions sandbox (Nessus ID 243030)
CVE-2025-43235 | Apple macOS up to 15.5 App denial of service (EUVD-2025-23132 / Nessus ID 243030)
CVE-2025-43240 | Apple macOS up to 15.5 improper check or handling of exceptional conditions (Nessus ID 243030)
Flo settles class action lawsuit alleging improper data sharing
Ladon SharePoint CVE-2025-53770漏洞后门批量检测
CMS、WhatCMS、CmsInfo等,Cobalt Strike下用法一致,输入URL,仅识别URL对应指纹,输入非URL时,会探测常见cve-2025-53770网站、网络
$1 000 000 за взлом WhatsApp?! Охота на уязвимости началась
CVE-2005-1071 | JPortal Web Portal 2.3.1 banner.inc.php haslo sql injection (EDB-25382 / SA14919)
CVE-2005-1403 | Just William Amazon Webstore closeup.php currentNumber cross site scripting (EDB-25560 / BID-13427)
CVE-2005-3509 | JPortal Jportal Web Portal 2.2.1 banner.php ID sql injection (EDB-26469 / BID-15324)
CVE-2005-3052 | jportal 2.3.1 module/down.inc.php sql injection (EDB-26293)
Comp AI secures $2.6M pre-seed to disrupt SOC 2 market
Comp AI secures $2.6M pre-seed to disrupt SOC 2 market
San Francisco, California, 1st August 2025, CyberNewsWire
The post Comp AI secures $2.6M pre-seed to disrupt SOC 2 market appeared first on Security Boulevard.
CVE-2025-23289 | NVIDIA Omniverse Launcher on Windows/Linux log file (EUVD-2025-23314)
CVE-2023-32251 | Linux Kernel up to 6.3 ksmbd fs/ksmbd/smb2pdu.c smb2_sess_setup improper authentication (EUVD-2023-36508)
CVE-2025-7443 | BerqWP Plugin up to 2.2.42 on WordPress store_javascript_cache.php store_javascript_cache unrestricted upload (EUVD-2025-23334)
Why I joined Tonic.ai: A software engineer’s perspective
Staff Software Engineer Johnny Goodnow shares his thoughts on the problem Tonic is tackling, the engineering challenges it entails, and the team taking it on—and how these three key ingredients translate into energizing, impactful work.
The post Why I joined Tonic.ai: A software engineer’s perspective appeared first on Security Boulevard.
Hackers Exploit Microsoft 365’s Direct Send Feature for Internal Phishing Attacks
Threat actors are leveraging Microsoft 365’s Direct Send feature to launch sophisticated phishing campaigns that mimic internal organizational emails, eroding trust and heightening the success rate of social engineering exploits. This feature, designed for unauthenticated relaying of messages from devices like multifunction printers and legacy applications to internal recipients, allows external attackers to spoof sender […]
The post Hackers Exploit Microsoft 365’s Direct Send Feature for Internal Phishing Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.