Aggregator
TamperedChef恶意软件兴起:欺诈应用利用经过签名的二进制文件与搜索引擎投毒劫持浏览器
8 months 3 weeks ago
安全客
谷歌新规强制要求:所有安卓应用须在2025年11月1日前全面支持16KB页面大小
8 months 3 weeks ago
安全客
Webinar | From Chaos to Control: Closing the Observability Gap and Driving Maturity
8 months 3 weeks ago
Webinar | From Chaos to Control: Closing the Observability Gap and Driving Maturity
8 months 3 weeks ago
Webinar | Next-Gen SaaS Data Protection: Product Roadmap & Feature Innovations
8 months 3 weeks ago
UK Government Backs Jaguar Land Rover With 1.5B Pound Loan
8 months 3 weeks ago
Carmaker Anticipates Phased Restart of Production
The British government will guarantee a 1.5 billion pound loan to Jaguar Land Rover as the embattled carmaker grapples with the fallout of a September cyberattack that froze production and sales across the globe. The government backed-loan shows the hack endangered "national economic security."
The British government will guarantee a 1.5 billion pound loan to Jaguar Land Rover as the embattled carmaker grapples with the fallout of a September cyberattack that froze production and sales across the globe. The government backed-loan shows the hack endangered "national economic security."
CVE-2025-57483 | tawk.to Chatbox Widget 4 cross site scripting
8 months 3 weeks ago
A vulnerability classified as problematic has been found in tawk.to Chatbox Widget 4. The affected element is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2025-57483. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2024-57412 | SunOS Omnios 5.11 TCP Packet denial of service
8 months 3 weeks ago
A vulnerability described as problematic has been identified in SunOS Omnios 5.11. Impacted is an unknown function of the component TCP Packet Handler. Executing manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2024-57412. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-61659 | magicmonty bash-git-prompt up to 2.7.1 /tmp/git-index-private$$ temp file (Issue 561)
8 months 3 weeks ago
A vulnerability marked as problematic has been reported in magicmonty bash-git-prompt up to 2.7.1. This issue affects some unknown processing of the file /tmp/git-index-private$$. Performing manipulation results in insecure temporary file.
This vulnerability was named CVE-2025-61659. The attack needs to be approached locally. There is no available exploit.
vuldb.com
CVE-2025-56795 | hay-kot Mealie up to 3.0.1 /api/recipes/ note/text cross site scripting (Issue 5677)
8 months 3 weeks ago
A vulnerability labeled as problematic has been found in hay-kot Mealie up to 3.0.1. This vulnerability affects unknown code of the file /api/recipes/. Such manipulation of the argument note/text leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-56795. The attack can be launched remotely. No exploit exists.
It is advisable to implement a patch to correct this issue.
vuldb.com
CVE-2025-56234 | Nanda AT_NA2000 Sequence Number random values
8 months 3 weeks ago
A vulnerability identified as problematic has been detected in Nanda AT_NA2000. This affects an unknown part of the component Sequence Number Handler. This manipulation causes insufficiently random values.
This vulnerability is handled as CVE-2025-56234. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-51495 | Mongoose up to 7.17 WebSocket integer overflow (EUVD-2025-31586)
8 months 3 weeks ago
A vulnerability categorized as problematic has been discovered in Mongoose up to 7.17. Affected by this issue is some unknown functionality of the component WebSocket. The manipulation results in integer overflow.
This vulnerability is known as CVE-2025-51495. Access to the local network is required for this attack. No exploit is available.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2025-56233 | Openindiana 5.11 Sequence Number random values
8 months 3 weeks ago
A vulnerability was found in Openindiana 5.11. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component Sequence Number Handler. The manipulation leads to insufficiently random values.
This vulnerability is traded as CVE-2025-56233. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-41244 | VMware VCF operations prior 9.0.1.0 privilege defined with unsafe actions (VMSA-2025-0015)
8 months 3 weeks ago
A vulnerability was found in VMware VCF operations, Tools, Aria Operations, Cloud Foundation, Telco Cloud Platform and Telco Cloud Infrastructure. It has been declared as critical. Affected is an unknown function. Executing manipulation can lead to privilege defined with unsafe actions.
This vulnerability appears as CVE-2025-41244. The attack requires local access. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-41245 | VMware Aria Operations up to 8.18.4 insecure default initialization of resource (VMSA-2025-0015)
8 months 3 weeks ago
A vulnerability was found in VMware Aria Operations, Cloud Foundation, Telco Cloud Platform and Telco Cloud Infrastructure up to 8.18.4. It has been classified as problematic. This impacts an unknown function. Performing manipulation results in insecure default initialization of resource.
This vulnerability is reported as CVE-2025-41245. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-7104 | danny-avila librechat up to 0.7.8 Request Body author/access_level/isCollaborative/projectIds dynamically-determined object attributes
8 months 3 weeks ago
A vulnerability was found in danny-avila librechat up to 0.7.8 and classified as problematic. This affects an unknown function of the component Request Body Handler. Such manipulation of the argument author/access_level/isCollaborative/projectIds leads to dynamically-determined object attributes.
This vulnerability is documented as CVE-2025-7104. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-41246 | VMware Tools prior 12.5.4/13.0.5.0 on Windows authorization
8 months 3 weeks ago
A vulnerability has been found in VMware Tools on Windows and classified as critical. The impacted element is an unknown function. This manipulation causes incorrect authorization.
This vulnerability is registered as CVE-2025-41246. The attack requires access to the local network. No exploit is available.
The affected component should be upgraded.
vuldb.com
Dutch Teens Arrested Over Alleged Spying for Pro-Russian Hackers
8 months 3 weeks ago
Dutch authorities arrest two teens recruited by pro-Russian hackers for spying missions. Learn how Russia is using disposable agents for sabotage across Europe.
Deeba Ahmed
Interpol operation disrupts romance scam and sextortion networks in Africa
8 months 3 weeks ago
Authorities arrested 260 cybercrime suspects during a two-week operation spanning 14 African countries, Interpol announced Friday. The globally coordinated summertime crackdown dubbed “Operation Contender 3.0” targeted criminal networks that facilitated romance scams and sextortion, officials said. Interpol said total losses attributed to the scam syndicates amounted to about $2.8 million, involving almost 1,500 victims. Authorities […]
The post Interpol operation disrupts romance scam and sextortion networks in Africa appeared first on CyberScoop.
Matt Kapko