Aggregator
CVE-2024-12223 | Nutanix Prism Central prior 2024.3.1 Events cross site scripting
CVE-2025-53522 | Six Apart Movable Type Password Reset less trusted source
CVE-2025-54551 | Fujifilm Healthcare Americas Synapse Mobility 8.0.0/8.0.1/8.0.2/8.1.0/8.1.1 Search external control of assumed-immutable web parameter
CVE-2025-55706 | Six Apart Movable Type Password Reset Page redirect
CVE-2025-57788 | Commvault CommCell up to 11.32.101/11.36.59 API Call hard-coded password
CVE-2025-57791 | Commvault CommCell up to 11.32.101/11.36.59 argument injection
CVE-2025-57790 | Commvault CommCell up to 11.32.101/11.36.59 absolute path traversal
CVE-2025-57789 | Commvault CommCell up to 11.32.101/11.36.59 Administrator Login storing passwords in a recoverable format
CVE-2025-54364 | Microsoft Knack 0.12.0 knack.introspection redos
CVE-2025-54363 | Microsoft Knack 0.12.0 knack.introspection redos
CVE-2025-9132 | Google Chrome up to 139.0.7258.127 V8 out-of-bounds write (ID 436181)
New GodRAT Weaponizing Screen Saver and Program Files to Attack Organizations
A sophisticated new Remote Access Trojan named GodRAT has emerged as a significant threat to financial institutions, leveraging deceptive screen saver files and steganographic techniques to infiltrate organizational networks. First detected in September 2024, this malware campaign has demonstrated remarkable persistence, with the most recent attacks observed as recently as August 12, 2025, indicating an […]
The post New GodRAT Weaponizing Screen Saver and Program Files to Attack Organizations appeared first on Cyber Security News.
0-Day Clickjacking Vulnerabilities Found in Major Password Managers like 1Password, LastPass and Others
A cybersecurity researcher has disclosed zero-day clickjacking vulnerabilities affecting eleven major password managers, potentially exposing tens of millions of users to credential theft through a single malicious click. The research, conducted by security expert Marek Tóth, reveals that attackers can exploit these vulnerabilities to steal credit card details, personal information, login credentials, and even two-factor […]
The post 0-Day Clickjacking Vulnerabilities Found in Major Password Managers like 1Password, LastPass and Others appeared first on Cyber Security News.
诚邀渠道合作伙伴共启新征程
金山等软件被常用工具弹窗推广,流氓行为传播数十万终端
LudusHound: Open-source tool brings BloodHound data to life
LudusHound is an open-source tool that takes BloodHound data and uses it to set up a working Ludus Range for safe testing. It creates a copy of an Active Directory environment using previously gathered BloodHound data. Red teams can use this lab to map attack paths and test ways to exploit misconfigurations before trying them on real systems. Blue teams can use it to practice defense strategies and strengthen AD security, testing configuration changes in … More →
The post LudusHound: Open-source tool brings BloodHound data to life appeared first on Help Net Security.
Git дарит миллионам разработчиков SHA-256. Двадцать лет ожидания оправданы
Enrollment Policies for Passwordless Authentication
Learn how to create effective enrollment policies for passwordless authentication, covering user groups, risk assessment, conditional access, and best practices for a secure transition.
The post Enrollment Policies for Passwordless Authentication appeared first on Security Boulevard.
US Intel Chief Celebrates UK Retreat on Apple Backdoor Order
U.S. Director of National Intelligence Tulsi Gabbard announced the United Kingdom has apparently reversed course on a demand for Apple to provide the government with a backdoor into its advanced iCloud encrypted protections following growing criticism from U.S. lawmakers and privacy advocates.