Aggregator
CoreDNS Vulnerability Allows Attackers to Poison DNS Cache and Block Updates
A critical flaw in CoreDNS’s etcd plugin can let attackers pin DNS records in caches for years, effectively blocking legitimate updates. This vulnerability, tracked as CVE-2025-58063, stems from incorrect handling of etcd lease IDs. It affects every CoreDNS release from version 1.2.0 onward and was patched in version 1.12.4, as per a report by Researcher […]
The post CoreDNS Vulnerability Allows Attackers to Poison DNS Cache and Block Updates appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-58313 | Huawei HarmonyOS 5.0.1/5.1.0 Device Standby race condition
CVE-2025-58276 | Huawei HarmonyOS/EMUI Home Screen access control
CVE-2025-58280 | Huawei HarmonyOS 5.0.1/5.1.0 Ark eTS prototype pollution
CVE-2025-58281 | Huawei HarmonyOS 5.0.1/5.1.0 Runtime Interpreter out-of-bounds
CVE-2025-58296 | Huawei HarmonyOS 5.0.1/5.1.0 Audio race condition
CVE-2025-9632 | PhpList Subber Plugin up to 1.1 on WordPress bulk_action_handler cross-site request forgery
CVE-2025-9631 | AutoCatSet Plugin up to 2.1.4 on WordPress autocatset_ajax cross-site request forgery
CVE-2025-9628 | AMO.CRM Plugin up to 1.0.1 on WordPress Setting settings_page cross-site request forgery
CVE-2025-9623 | Admin in English with Switch Plugin up to 1.1 on WordPress Setting enable_eng cross-site request forgery
CVE-2025-9634 | Plugin Updates Blocker Plugin up to 0.2 on WordPress pub_save cross-site request forgery
CVE-2025-9627 | Run Log Plugin up to 1.7.10 on WordPress Setting oirl_plugin_options cross-site request forgery
CVE-2025-9633 | LH Signing Plugin up to 2.83 on WordPress Setting plugin_options cross-site request forgery
猫抓插件应用一例(2)
Kenyan Filmmakers Targeted with FlexiSPY Spyware Tracking Messages and Social Media
The revelation that commercially available FlexiSPY spyware was clandestinely installed on devices belonging to Kenyan filmmakers while in police custody has ignited fresh concerns over press freedom and governmental overreach. Forensic analysis conducted by the Citizen Lab at the University of Toronto confirmed that two of the filmmakers’ phones were infected with the intrusive software […]
The post Kenyan Filmmakers Targeted with FlexiSPY Spyware Tracking Messages and Social Media appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
«Дыра» по умолчанию. Стандартная настройка в корпоративных VPN открывает дверь для вымогателей
Attackers Abuse Kubernetes DNS to Extract Git Credentials from ArgoCD
A newly discovered attack method targeting ArgoCD and Kubernetes that could give red-teamers fresh ammo and blue-teamers fresh headaches. This technique lets an attacker abuse Kubernetes DNS to steal powerful Git credentials from ArgoCD, potentially taking over entire Git accounts. Why Target ArgoCD and Kubernetes? In 2025, data exfiltration attacks are a major threat in […]
The post Attackers Abuse Kubernetes DNS to Extract Git Credentials from ArgoCD appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Boost the Performance and Security — and Lower the Costs — of AI Apps
CISA Releases Eleven Industrial Control Systems Advisories
CISA released eleven Industrial Control Systems (ICS) advisories on September 11, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-254-01 Siemens SIMOTION Tools
- ICSA-25-254-02 Siemens SIMATIC Virtualization as a Service (SIVaaS)
- ICSA-25-254-03 Siemens SINAMICS Drives
- ICSA-25-254-04 Siemens SINEC OS
- ICSA-25-254-05 Siemens Apogee PXC and Talon TC Devices
- ICSA-25-254-06 Siemens Industrial Edge Management OS (IEM-OS)
- ICSA-25-254-07 Siemens User Management Component (UMC)
- ICSA-25-254-08 Schneider Electric EcoStruxure
- ICSA-25-254-09 Schneider Electric Modicon M340, BMXNOE0100, and BMXNOE0110
- ICSA-25-254-10 Daikin Security Gateway
- ICSA-25-035-06 Schneider Electric Modicon M340 and BMXNOE0100/0110, BMXNOR0200H (Update A)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.