Aggregator
CVE-2025-30975 | Add Custom Codes Plugin up to 4.80 on WordPress privilege escalation
CVE-2025-55296 | LibreNMS up to 25.7.x Alert Template cross site scripting (GHSA-vxq6-8cwm-wj99)
CVE-2025-55291 | Shaarli up to 0.14.x cross site scripting (GHSA-7w7w-pw4j-265h)
CVE-2025-43731 | Liferay Portal/DXP Message Board cross site scripting
CVE-2025-7693 | Rockwell Automation PLC denial of service
Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures
CVE-2025-55299 | 7ritn VaulTLS up to 0.9.0 weak password (GHSA-pjfr-pj3h-cw8m)
Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection
The next three posts will cover high severity vulnerabilities in the Amazon Q Developer VS Code Extension (Amazon Q Developer), which is a very popular coding agent, with over 1 million downloads.
It is vulnerable to prompt injection from untrusted data and its security depends heavily on model behavior.
At a high level Amazon Q Developer can leak sensitive information from a developer’s machine, e.g. API keys, to external servers via DNS requests. An adversary can also exploit this behavior during an indirect prompt injection attack.
CVE-2025-55293 | Meshtastic Firmware up to 2.6.2 improper authentication (GHSA-95pq-gj5v-4fg2)
CVE-2025-55300 | komari-monitor komari up to 1.0.4 Terminal Websocket Endpoint cross site scripting (GHSA-q355-h244-969h)
CVE-2025-55288 | MGeurts genealogy up to 4.3.x cross site scripting (GHSA-3h8x-g9xj-rhwg / EUVD-2025-25149)
CVE-2025-55287 | MGeurts genealogy up to 4.3.x cross site scripting (GHSA-j457-9m86-6q5r / EUVD-2025-25150)
«Быстрее и стабильнее». Физики научились совмещать две несовместимые характеристики кубитов
Nebraska man gets 1 year in prison for $3.5M cryptojacking scheme
BSidesSF 2025: Inside The Information Stealer Ecosystem: From Compromise To Countermeasure
Creator, Author and Presenter:
Our deep appreciation to Security BSides - San Francisco and the Creators, Authors and Presenters for publishing their BSidesSF 2025 video content on YouTube. Originating from the conference’s events held at the lauded CityView / AMC Metreon - certainly a venue like no other; and via the organization's YouTube channel.
Additionally, the organization is welcoming volunteers for the BSidesSF Volunteer Force, as well as their Program Team & Operations roles. See their succinct BSidesSF 'Work With Us' page, in which, the appropriate information is to be had!
The post BSidesSF 2025: Inside The Information Stealer Ecosystem: From Compromise To Countermeasure appeared first on Security Boulevard.