Aggregator
CVE-2024-47174 | NixOS nix up to 2.18.7/2.24.7 HTTPS Connection certificate validation (GHSA-6fjr-mq49-mm2c / Nessus ID 242201)
CVE-2024-45593 | NixOS nix up to 2.24.5 NAR path traversal (GHSA-h4vv-h3jq-v493 / Nessus ID 242201)
CVE-2024-27297 | NixOS nix up to 2.3.17/2.18.1/2.19.3/2.20.4 on Linux Unix Domain Socket toctou (GHSA-2ffj-w4mj-pg37 / Nessus ID 242201)
CVE-2024-38531 | NixOS nix up to 2.23.0 insecure preserved inherited permissions (Nessus ID 242201)
Veranderende wereldorde bevestigt belang van een weerbaar Nederland
Лицо админа = вы: подмена SID ломает модель персональной биометрии в Windows Hello. Эксплоит в паблике
PyPI Blocks Inbox.ru Domains After 1,500+ Fake Package Uploads
The Python Package Index (PyPI) has implemented an administrative block on the inbox.ru email domain, prohibiting its use for new user registrations and as additional verification addresses. This action stems from a recent campaign that exploited the domain to create over 250 fraudulent accounts, which in turn uploaded more than 1,500 empty projects. These bogus […]
The post PyPI Blocks Inbox.ru Domains After 1,500+ Fake Package Uploads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CNNVD关于Oracle多个安全漏洞的通报
Cloud Cost Conundrum: Rising Expenses Hinder AI Innovation in Europe
Critical SharePoint RCE Vulnerability Exploited via Malicious XML in Web Part
A severe remote code execution (RCE) vulnerability has been discovered in Microsoft SharePoint that allows attackers to execute arbitrary code through malicious XML content embedded within web parts. According to the recent report, the vulnerability, which affects the deserialization process of webpart properties, represents a significant security risk for organizations running vulnerable SharePoint installations. Technical […]
The post Critical SharePoint RCE Vulnerability Exploited via Malicious XML in Web Part appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
纠缠威胁:面向量子机器学习安全的统一杀伤链模型
WorldLeaks
You must login to view this content
Hackers Actively Exploited CitrixBleed 2 Flaw Ahead of PoC Disclosure
Cybersecurity researchers have discovered that threat actors began exploiting the critical CitrixBleed 2 vulnerability nearly two weeks before a public proof-of-concept was released, highlighting the sophisticated nature of modern attack campaigns. The vulnerability, tracked as CVE-2025-5777, represents a significant security risk for organizations running Citrix NetScaler appliances. Early Exploitation Timeline GreyNoise security researchers observed the […]
The post Hackers Actively Exploited CitrixBleed 2 Flaw Ahead of PoC Disclosure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
RCE без уязвимостей — новая реальность. Claude научил хакера обходить самого себя
US Data Breaches Head for Another Record Year After 11% Surge
Cisco Unified Intelligence Center Flaw Lets Remote Attackers Upload Arbitrary Files
A critical security vulnerability has been discovered in Cisco’s Unified Intelligence Center that allows authenticated remote attackers to upload arbitrary files to affected systems, potentially enabling complete system compromise. The flaw, tracked as CVE-2025-20274, carries a CVSS score of 6.3 and has been assigned a High security impact rating by Cisco due to the potential […]
The post Cisco Unified Intelligence Center Flaw Lets Remote Attackers Upload Arbitrary Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.