Aggregator
CVE-2025-56200 | Validator.js up to 13.15.15 isURL redirect (EUVD-2025-31764)
CVE-2025-56520 | Dify 1.6.0 server-side request forgery (Issue 22532)
CVE-2025-11195 | Rapid7 AppSpider Pro up to 7.5.020 Project Name improper authorization
CVE-2025-23292 | NVIDIA License System Delegated Licensing Service data query logic injection
CVE-2025-43827 | Liferay Portal/DXP authorization
CVE-2025-23293 | NVIDIA License System Delegated Licensing Service missing authentication
CVE-2025-23291 | NVIDIA License System Delegated Licensing Service cleartext storage
CVE-2025-56132 | LiquidFiles Filetransfer Server up to 4.2 password recovery (EUVD-2025-31771)
CVE-2025-56207 | Dependencies.sol 0.8.17 ERC721 _transfer
Threat Actors Hijacking MS-SQL Server to Deploy XiebroC2 Framework
A sophisticated attack campaign targeting improperly managed Microsoft SQL servers has emerged, deploying the XiebroC2 command and control framework to establish persistent access to compromised systems. The attack leverages vulnerable credentials on publicly accessible database servers, allowing threat actors to gain initial foothold and escalate privileges through a multi-stage deployment process. XiebroC2, a publicly available […]
The post Threat Actors Hijacking MS-SQL Server to Deploy XiebroC2 Framework appeared first on Cyber Security News.
CVE-2025-56513 | NiceHash QuickMiner 6.12.0 Digital Signature cryptographic issues
CVE-2025-57254 | Karthikg1908 Hospital Management System 1.0 POST Parameter user-login.php username/password sql injection
IOC Alert: Lumma Stealer Command-and-Control Domain Identified
USENIX 2025: PEPR ’25 – Unlocking Cross-Organizational Insights: Practical MPC for Cloud-Based Data Analytics
Creator, Author and Presenter: Daniele Romanini, Resolve
Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Enigma ’23 Conference content on the organization’s’ YouTube channel.
The post USENIX 2025: PEPR ’25 – Unlocking Cross-Organizational Insights: Practical MPC for Cloud-Based Data Analytics appeared first on Security Boulevard.
New MatrixPDF toolkit turns PDFs into phishing and malware lures
Chinese APT Phantom Taurus Targeted MS Exchange Servers Over 3 Years
New $50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections
WestJet confirms recent breach exposed customers' passports
APT35 Hackers Attacking Government, Military Organizations to Steal Login Credentials
In recent months, a surge in targeted intrusions attributed to the Iranian-aligned threat group APT35 has set off alarm bells across government and military networks worldwide. First detected in early 2025, the campaign leverages custom-built malware to infiltrate secure perimeters and harvest user credentials. Initial indicators of compromise point to spear-phishing emails with HTML attachments […]
The post APT35 Hackers Attacking Government, Military Organizations to Steal Login Credentials appeared first on Cyber Security News.