Aggregator
【漏洞通告】Cherry Studio 命令注入漏洞(CVE-2025-54074)
CVE-2025-7384 | Database for Contact Form 7, WPforms, Elementor Forms Plugin get_lead_detail denial of service (EUVD-2025-24539)
CVE-2025-6715 | LatePoint Plugin up to 5.1.93 on WordPress layout path traversal (EUVD-2025-24546)
Fortinet warns about FortiSIEM vulnerability with in-the-wild exploit code (CVE-2025-25256)
Fortinet has released patches for a critical OS command injection vulnerability (CVE-2025-25256) in FortiSIEM, after practical exploit code surfaced in the wild. About CVE-2025-25256 FortiSIEM is a security information and event management platform used by organizations to collect, correlate and analyze logs, events, and alerts from across an organization’s IT and security infrastructure, to help detect threats and investigate incidents. CVE-2025-25256 is caused by improper neutralization of special elements and may allow unauthenticated attackers to … More →
The post Fortinet warns about FortiSIEM vulnerability with in-the-wild exploit code (CVE-2025-25256) appeared first on Help Net Security.
CVE-2003-0495 | Ledscripts.com Lednews 0.7 cross site scripting (EDB-22777 / Nessus ID 11741)
CVE-2003-0507 | Microsoft Windows up to 2000 SP3 Active Directory stack-based overflow (VU#594108 / Nessus ID 26921)
诚邀渠道合作伙伴共启新征程
2025-08微软漏洞通告
CVE-2025-8731 | TRENDnet TI-G160i/TI-PG102i/TPL-430AP up to 20250724 SSH Service default credentials (EUVD-2025-23997)
安全419《甲方安全建设精品采购指南》案例入围厂商名单公布
Webinar: What the Next Wave of AI Cyberattacks Will Look Like — And How to Survive
T00ls生日月之际,十七周年征文与人物专访正式启动
US Authorities Seize $1m from BlackSuit Ransomware Group
CVE-2025-5988 | Red Hat Ansible Automation Platform 2 cross-site request forgery (EUVD-2025-23518 / Nessus ID 243449)
APT-C-36(盲眼鹰)组织在新攻击活动中升级对抗手段
ShinySp1d3r: союз ShinyHunters и Scattered Spider, бросивший вызов LockBit и DragonForce
英国政府建议居民删除邮件以节省用水
Ondata di attacchi brute-force contro le VPN Fortinet, poi FortiManager
Ukrainian Web3team Weaponizing NPM Package to Attack Job Seekers and Steal Sensitive Data
A sophisticated cybercriminal operation disguised as a Ukrainian Web3 development team has been targeting job seekers through weaponized NPM packages, security researchers warn. The attack leverages fake interview processes to trick unsuspecting candidates into downloading and executing malicious code that steals cryptocurrency wallets, browser data, and sensitive personal information. The campaign centers around a seemingly […]
The post Ukrainian Web3team Weaponizing NPM Package to Attack Job Seekers and Steal Sensitive Data appeared first on Cyber Security News.