Aggregator
CVE-2025-10327 | MiczFlor RPi-Jukebox-RFID up to 2.8.0 shuffle.php playlist os command injection (EUVD-2025-29077)
CVE-2025-10326 | MiczFlor RPi-Jukebox-RFID up to 2.8.0 single.php playlist os command injection (EUVD-2025-29078)
Submit #643527: daylightstudio FUEL-CMS 1.5.2 XSS [Duplicate]
Submit #643524: daylightstudio FUEL-CMS 1.5.2 XSS [Duplicate]
Sidewinder Hackers Exploit LNK Files to Deploy Malicious Scripts
In a striking evolution of its tactics, the Sidewinder advanced persistent threat (APT) group—also known as APT-C-24 or “Rattlesnake”—has adopted a novel delivery mechanism leveraging Windows shortcut (LNK) files to orchestrate complex, multi-stage intrusions across South Asia. Active since at least 2012 and targeting governments, energy utilities, military installations, and mining operations in Pakistan, Afghanistan, […]
The post Sidewinder Hackers Exploit LNK Files to Deploy Malicious Scripts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #643523: daylightstudio FUEL-CMS 1.5.2 XSS [Duplicate]
CVE-2025-43775 | Liferay Portal/DXP remote app title cross site scripting (WID-SEC-2025-2041)
Submit #643512: MiczFlor RPi-Jukebox-RFID 2.8.0 Command Injection [Accepted]
Submit #643511: MiczFlor RPi-Jukebox-RFID 2.8.0 Command Injection [Accepted]
Submit #643500: MiczFlor RPi-Jukebox-RFID 2.8.0 Command Injection [Accepted]
Axios Vulnerability Enables Attackers to Crash Node.js Applications via Data Handle Abuse
A critical security vulnerability has been discovered in the popular Axios HTTP client library that allows attackers to crash Node.js applications through malicious data URL handling. The flaw, tracked as CVE-2025-58754, affects all versions of Axios before 1.11.0 and has been assigned a CVSS 3.1 score of 7.5, indicating high severity. Vulnerability Mechanics The vulnerability stems […]
The post Axios Vulnerability Enables Attackers to Crash Node.js Applications via Data Handle Abuse appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.