Aggregator
CVE-2025-54713 | magepeopleteam Taxi Booking Manager for WooCommerce Plugin up to 1.3.0 on WordPress authentication bypass
CVE-2025-54750 | FunnelKit Funnel Builder Plugin up to 3.11.1 on WordPress filename control
苹果将在印度组装更多新款 iPhone
North Korea Uses GitHub in Diplomat Cyber Attacks as IT Worker Scheme Hits 320+ Firms
Microsoft Issues Out-of-Band Update to Fix Recovery Issues
AI失控?兰德《加强人工智能失控事件应急准备和应对》解读
研究员发现5G网络安全漏洞:可实时嗅探流量、拒绝服务、网络降级
Конец «Кибер-армии Йемена». Хакер, похитивший 4 млн аккаунтов, попался на лайках в Instagram
万元美刀的信息泄露骚思路
TrafficGPT:高效长流量生成和分类的利器
议题征集|“安全重构·智启未来”第十六期「度安讲」 技术沙龙议题报名!
成果分享 | [USENIX Security 2025] XSSky:融合动静态分析,精准狙击XSS漏洞的新一代“利剑”
CVE-2025-5497 | slackero phpwcms up to 1.9.45/1.10.8 Feedimport processing.inc.php cnt_text deserialization (EUVD-2025-16727)
Hackers Exploiting Apache ActiveMQ Vulnerability to Gain Access to Cloud Linux Systems
A sophisticated campaign uncovered where adversaries are exploiting CVE-2023-46604, a critical remote code execution vulnerability in Apache ActiveMQ, to compromise cloud-based Linux systems. In this case, attackers are patching the very vulnerability they exploited to maintain exclusive access and evade detection, demonstrating advanced operational security practices typically reserved for nation-state actors. Key Takeaways1. Attackers exploit […]
The post Hackers Exploiting Apache ActiveMQ Vulnerability to Gain Access to Cloud Linux Systems appeared first on Cyber Security News.
CVE-2025-9228 | Mobile Industrial Robots MiR Robots/MiR Fleet up to 2.x Note authorization
CVE-2025-9225 | Mobile Industrial Robots MiR Robots/MiR Fleet up to 2.x Web Interface cross site scripting
CVE-2025-5260 | Pik Online Yazılım Çözümleri up to 3.1.4 server-side request forgery
Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware
Cybersecurity researchers have uncovered a sophisticated campaign by the Paper Werewolf threat actor group, also known as GOFFEE, targeting Russian organizations through the exploitation of critical vulnerabilities in WinRAR archiving software. The campaign, active since July 2025, demonstrates the group’s advanced capabilities in leveraging both known and previously undiscovered security flaws to establish persistent access […]
The post Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware appeared first on Cyber Security News.