Aggregator
CVE-2025-6077 | Partner Web Application up to 4.32.1 weak credentials (EUVD-2025-23417)
CVE-2025-54792 | LocalSend up to 1.17.0 channel accessible (GHSA-424h-5f6m-x63f / EUVD-2025-23410)
CVE-2025-54796 | 9001 copyparty up to 1.18.8 Recent Uploads Page filter resource consumption (GHSA-5662-2rj7-f2v6 / EUVD-2025-23411)
CVE-2025-54790 | humhub cfiles up to 0.16.9 sql injection (GHSA-rfvq-g9rm-pgqj / EUVD-2025-23412)
CVE-2025-6076 | Partner Web Application up to 4.32.1 unrestricted upload (EUVD-2025-23418)
Submit #626297: https://phpgurukul.com/online-security-guards-hiring-system-usin online-security-guards-hiring-system-usin 1.0 SQL Injection [Duplicate]
CVE-2025-54131 | Cursor up to 1.2 command injection (GHSA-534m-3w6r-8pqr / EUVD-2025-23408)
CVE-2025-54136 | Cursor up to 1.2.4 os command injection (GHSA-24mc-g4xr-4395 / EUVD-2025-23405)
CVE-2025-54789 | humhub cfiles up to 0.6.9 cross site scripting (GHSA-cw2v-c62w-5r43 / EUVD-2025-23404)
Submit #626294: https://phpgurukul.com/human-metapneumovirus-hmpv-testing-manage human-metapneumovirus-hmpv-testing-manage 1.0 SQL Injection [Duplicate]
CVE-2025-54132 | Cursor up to 1.2 Mermaid server-side request forgery (GHSA-43wj-mwcc-x93p / EUVD-2025-23407)
Он не требует учётки и не следит за вами. Что за странный аутентификатор запустила Proton?
CVE-2025-54133 | Cursor up to 1.2 Model Context Protocol os command injection (GHSA-r22h-5wp2-2wfv / EUVD-2025-23406)
CVE-2025-54386 | Traefik up to 2.11.27/3.4.4/3.5.0-rc1 ZIP Archive path traversal (GHSA-q6gg-9f92-r9wg / EUVD-2025-23415)
CVE-2025-54782 | nestjs nest up to 0.2.0 API Endpoint command injection (GHSA-85cg-cmq5-qjm7 / EUVD-2025-23413)
CVE-2025-54424 | 1Panel up to 2.0.5 HTTPS Protocol certificate validation (GHSA-8j63-96wh-wh3j / EUVD-2025-23409)
CVE-2025-54781 | himmelblau up to 1.0.x himmelblaud_tasks Service log file (GHSA-78qg-vmrw-574w / EUVD-2025-23414)
STRATEGIC REEL: Proactive by design: Fortinet retools network defense for real-time threats
Security teams can no longer afford to wait for alerts — not when cyberattacks unfold in milliseconds.
That’s the core warning from Fortinet’s Derek Manky in a new Last Watchdog Strategic Reel recorded at RSAC 2025. As adversaries adopt AI-driven … (more…)
The post STRATEGIC REEL: Proactive by design: Fortinet retools network defense for real-time threats first appeared on The Last Watchdog.
The post STRATEGIC REEL: Proactive by design: Fortinet retools network defense for real-time threats appeared first on Security Boulevard.
Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers
A sophisticated cyber espionage campaign targeting software developers has infiltrated two of the world’s largest open source package repositories, with North Korea’s notorious Lazarus Group successfully deploying 234 malicious packages across npm and PyPI ecosystems. Between January and July 2025, this state-sponsored operation exposed over 36,000 potential victims to advanced malware designed for long-term surveillance […]
The post Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers appeared first on Cyber Security News.