Aggregator
由敏感参数到反序列化命令执行的src挖掘记录
Google Gemini взломали через логи, историю браузера и пересказ сайтов — одновременно
How To Simplify CISA's Zero Trust Roadmap with Modern Microsegmentation
Microsoft: Media Creation Tool broken on Windows 11 Arm64 PCs
Undead Operating Systems Haunt Enterprise Security Networks
CISA Warns of Cisco IOS and IOS XE SNMP Vulnerabilities Exploited in Attacks
Cisco’s Simple Network Management Protocol (SNMP) implementations in IOS and IOS XE have come under intense scrutiny following reports of active exploitation in the wild. First disclosed in August 2025, CVE-2025-20352 describes a critical buffer overflow in the SNMP engine that allows unauthenticated remote attackers to execute arbitrary code. The vulnerability arises when an oversized […]
The post CISA Warns of Cisco IOS and IOS XE SNMP Vulnerabilities Exploited in Attacks appeared first on Cyber Security News.
Seniors targeted in global Facebook scam spreading new Android malware
Tonic.ai + Microsoft: Accelerating AI adoption with privacy-compliant synthetic data
Tonic.ai is thrilled to join the Microsoft for Startups Pegasus Program. We're bringing our privacy-compliant synthetic data solutions to Microsoft Azure customers.
The post Tonic.ai + Microsoft: Accelerating AI adoption with privacy-compliant synthetic data appeared first on Security Boulevard.
CVE-2023-44762 | Concrete CMS 9.2.1 Settings Tags cross site scripting (EUVD-2023-2673)
CVE-2023-22551 | Simple FTP Client and Server FTP/server_ftp.c malloc size_packet memory corruption (EUVD-2023-26691)
CVE-2023-44771 | Zenario CMS 9.4.59197 Page Layout cross site scripting (EUVD-2023-2671)
CVE-2023-43875 | Intelliants Subrion CMS 4.2.1 dbhost/dbname/dbuser/adminusername/adminemail cross site scripting (EUVD-2023-2665)
CVE-2025-7060 | Monitorr up to 1.7.6m Installer mkdbajax.php datadir input validation (EUVD-2025-20012)
CVE-2025-53489 | GoogleDocs4MW Extension up to 1.42.6/1.43.1 on Mediawiki cross site scripting (EUVD-2025-19889)
CVE-2025-53490 | CampaignEvents Extension up to 1.43.1 on Mediawiki cross site scripting (EUVD-2025-19890)
CVE-2022-48720 | Linux Kernel up to 5.10.98/5.15.21/5.16.7 macsec_dellink memory leak (Nessus ID 235407)
Cloudflare 赞助 Ladybird 浏览器引擎项目
North Korea’s IT workers are targeting firms beyond tech, crypto, and the U.S.
North Korea’s clandestine IT Worker (ITW) program, which is long known for targeting U.S. technology firms and crypto firms, has broadened its scope to attempt to infiltrate a variety of industries worldwide, including finance, healthcare, public administration, and professional services. Okta’s threat researchers have identified over 130 identities associated with DPRK-linked facilitators and workers, which collectively pursued more than 6,500 interviews across 5,000+ companies until mid-2025, and have found that the threat is far more … More →
The post North Korea’s IT workers are targeting firms beyond tech, crypto, and the U.S. appeared first on Help Net Security.