Aggregator
Russia Uses ISPs to Spy on Diplomats, Warns Microsoft
2 weeks 3 days ago
Russian Intelligence Tied to SSL Stripping Attacks Designed for Eavesdropping
Russian intelligence since 2024 has been using their country's internet service providers to run adversary-in-the-middle attacks designed to infect diplomats inside the country's borders with intelligence-gathering malware, Microsoft warns.
Russian intelligence since 2024 has been using their country's internet service providers to run adversary-in-the-middle attacks designed to infect diplomats inside the country's borders with intelligence-gathering malware, Microsoft warns.
Milan Court Rejects Chinese Hacker's House Arrest Plea
2 weeks 3 days ago
Xu Zewei, Suspected Silk Typhoon Hacker, to Remain in Italian Prison
Prosecutors at a Milan court on Friday rejected a house arrest request by lawyers of a Chinese national awaiting possible extradition to the United States in Italy, citing flight risk. Italian authorities arrested Xu Zewei, 33, of Shanghai, in July after his arrival at Milan's Malpensa Airport.
Prosecutors at a Milan court on Friday rejected a house arrest request by lawyers of a Chinese national awaiting possible extradition to the United States in Italy, citing flight risk. Italian authorities arrested Xu Zewei, 33, of Shanghai, in July after his arrival at Milan's Malpensa Airport.
42% of Developers Using AI Say Their Codebase is Now Mostly AI-Generated
2 weeks 3 days ago
CVE-2023-38002 | IBM Storage Scale up to 5.1.9.2 session fixiation (XFDB-260208)
2 weeks 3 days ago
A vulnerability was found in IBM Storage Scale up to 5.1.9.2. It has been classified as critical. Affected is an unknown function. The manipulation leads to session fixiation.
This vulnerability is traded as CVE-2023-38002. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46716 | Sandboxie up to 1.15.11 Api_SetSecureParam out-of-bounds (GHSA-3984-r877-q7xp)
2 weeks 3 days ago
A vulnerability, which was classified as problematic, was found in Sandboxie up to 1.15.11. Affected is the function Api_SetSecureParam. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2025-46716. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46715 | Sandboxie up to 1.15.11 Registry Key Api_GetSecureParam out-of-bounds write (GHSA-67p9-6h73-ff7x)
2 weeks 3 days ago
A vulnerability was found in Sandboxie up to 1.15.11 and classified as critical. Affected by this issue is the function Api_GetSecureParam of the component Registry Key Handler. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2025-46715. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-54422 | sandboxie-plus Sandboxie up to 1.16.1 cleartext storage (GHSA-jp7r-vgv9-43p7)
2 weeks 3 days ago
A vulnerability, which was classified as problematic, was found in sandboxie-plus Sandboxie up to 1.16.1. This affects an unknown part. The manipulation leads to cleartext storage of sensitive information.
This vulnerability is uniquely identified as CVE-2025-54422. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46018 | CSC Pay Mobile App up to 2.19.3 Bluetooth improper authorization
2 weeks 3 days ago
A vulnerability, which was classified as critical, has been found in CSC Pay Mobile App up to 2.19.3. This issue affects some unknown processing of the component Bluetooth Handler. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2025-46018. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-50472 | modelscope ms-swift library up to 2.6.1 load_model_meta deserialization
2 weeks 3 days ago
A vulnerability was found in modelscope ms-swift library up to 2.6.1. It has been declared as critical. This vulnerability affects the function load_model_meta. The manipulation leads to deserialization.
This vulnerability was named CVE-2025-50472. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-44139 | Emlog Pro 2.5.7 plugin.php?action=upload_zip unrestricted upload
2 weeks 3 days ago
A vulnerability was found in Emlog Pro 2.5.7. It has been rated as critical. This issue affects some unknown processing of the file /emlog/admin/plugin.php?action=upload_zip. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2025-44139. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2019-19144 | Quantum DXi6702 2.3.0.3 Users?action=authenticate xml external entity reference
2 weeks 3 days ago
A vulnerability classified as problematic was found in Quantum DXi6702 2.3.0.3. Affected by this vulnerability is an unknown functionality of the file rest/Users?action=authenticate. The manipulation leads to xml external entity reference.
This vulnerability is known as CVE-2019-19144. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-45767 | jose 6.0.10 inadequate encryption (EUVD-2025-23364)
2 weeks 3 days ago
A vulnerability has been found in jose 6.0.10 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to inadequate encryption strength.
This vulnerability is known as CVE-2025-45767. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2025-50460 | ms-swift up to 3.6.3 PyYAML deserialization
2 weeks 3 days ago
A vulnerability classified as critical has been found in ms-swift up to 3.6.3. Affected is an unknown function of the component PyYAML Handler. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2025-50460. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-52901 | filebrowser up to 2.33.8 get request method with sensitive query strings (EUVD-2025-19581)
2 weeks 3 days ago
A vulnerability has been found in filebrowser up to 2.33.8 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to use of get request method with sensitive query strings.
This vulnerability was named CVE-2025-52901. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-52996 | filebrowser up to 2.32.0 Password Protected Link authentication bypass (EUVD-2025-19579)
2 weeks 3 days ago
A vulnerability, which was classified as problematic, was found in filebrowser up to 2.32.0. This affects an unknown part of the component Password Protected Link Handler. The manipulation leads to authentication bypass by primary weakness.
This vulnerability is uniquely identified as CVE-2025-52996. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2020-25412 | Gnuplot 5.4 command.c com_line code injection (Nessus ID 240563)
2 weeks 3 days ago
A vulnerability classified as critical has been found in Gnuplot 5.4. Affected is the function com_line of the file command.c. The manipulation leads to code injection.
This vulnerability is traded as CVE-2020-25412. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-20298 | Splunk Universal Forwarder up to 9.1.8/9.2.5/9.3.3/9.4.1 on Windows SplunkUniversalForwarder permission assignment (SVD-2025-0602 / EUVD-2025-16672)
2 weeks 3 days ago
A vulnerability was found in Splunk Universal Forwarder up to 9.1.8/9.2.5/9.3.3/9.4.1 on Windows. It has been rated as critical. This issue affects some unknown processing of the file C:\Program Files\SplunkUniversalForwarder. The manipulation leads to incorrect permission assignment.
The identification of this vulnerability is CVE-2025-20298. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52597 | Bubka 2FAuth up to 5.4.0 SVG File cross site scripting (GHSA-q5p4-6q4v-gqg3)
2 weeks 3 days ago
A vulnerability was found in Bubka 2FAuth up to 5.4.0. It has been rated as problematic. This issue affects some unknown processing of the component SVG File Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-52597. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
‘Highly evasive’ Vietnamese-speaking hackers stealing data from thousands of victims in 62+ nations
2 weeks 3 days ago
SentinelOne and Beazley Security say the group has been evolving its techniques of late, all with the goal of making money off stolen data.
The post ‘Highly evasive’ Vietnamese-speaking hackers stealing data from thousands of victims in 62+ nations appeared first on CyberScoop.
Tim Starks