Aggregator
ShinyHunters May Have Teamed Up With Scattered Spider in Salesforce Attack Campaigns
The financially motivated threat group ShinyHunters has returned with a sophisticated series of attacks targeting Salesforce instances across high-profile enterprises in industries like retail, aviation, and insurance, after a year of relative quiet following member arrests in June 2024. ReliaQuest’s analysis reveals a coordinated infrastructure of ticket-themed phishing domains and credential-harvesting pages, such as ticket-lvmh[.]com […]
The post ShinyHunters May Have Teamed Up With Scattered Spider in Salesforce Attack Campaigns appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-8948 | projectworlds Visitor Management System 1.0 /front.php rid sql injection
CVE-2025-8947 | projectworlds Visitor Management System 1.0 /query_data.php dateF/dateP sql injection
Submit #627543: code-projects College Notes Gallery V1.0 SQL Injection [Duplicate]
CVE-2025-8946 | projectworlds Online Notes Sharing Platform 1.0 /login.php User sql injection
Submit #632003: Projectworlds Visitor Management System Project V1.0 SQL injection [Accepted]
Submit #631996: Projectworlds Visitor Management System Project V1.0 SQL injection [Duplicate]
Submit #631995: Projectworlds Visitor Management System Project V1.0 SQL injection [Accepted]
Голос в трубке стал оружием. Роскомнадзор перекрывает звонки в Telegram и WhatsApp
Patch Tuesday Update – August 2025
In total, including third-party CVEs, in this Patch Tuesday edition, Microsoft published 119 CVEs, including 8 republished CVEs. Overall, Microsoft announced 1 Zero-Day, 16 Critical, and 92 Important vulnerabilities. From an Impact perspective, Escalation of Privilege vulnerabilities accounted for 40%, while Remove Code Execution for 32% and Information Disclosure for 16%. Patches for this month …
The post Patch Tuesday Update – August 2025 appeared first on Security Boulevard.
Submit #631982: Projectworlds Online Notes Sharing Platform Project V1.0 SQL injection [Accepted]
CVE-2025-55668 | Apache Tomcat up to 9.0.105/10.1.41/11.0.7 session fixiation
CVE-2003-0466 | FreeBSD/OpenBSD/MacOS X realpath memory corruption (VU#743092 / EDB-74)
CVE-2003-0466 | wu-ftpd 2.5.0/2.6.0/2.6.1/2.6.2 fb_realpath memory corruption (VU#743092 / EDB-22976)
Microsoft removes PowerShell 2.0 from Windows 11, Windows Server
电子科技大学 | 针对自定义LLM的指令后门攻击
CVE-2023-40028 | Ghost up to 5.59.0 content/ symlink (GHSA-9c9v-w225-v5rg / EDB-52409)
LLM安全漏洞挖掘专场沙龙,PPT+回放来啦!
Patch the vulnerability: Confirm Sean Plankey as CISA director
The executive director of the National Technology Security Coalition writes that Plankey is a strong, capable leader who will strengthen public-private partnerships.
The post Patch the vulnerability: Confirm Sean Plankey as CISA director appeared first on CyberScoop.