Aggregator
CVE-2024-9334 | E-Kent Pallium Vehicle Tracking prior 17.10.2024 hard-coded credentials
CVE-2025-25761 | HkCms 2.3.2.240702 Appcenter.php file inclusion
Silver Fox APT Uses Winos 4.0 Malware in Cyber Attacks Against Taiwanese Organizations
Criminal group UAC-0173 targets the Notary Office of Ukraine
Palo Alto Networks Unit 42 发布了 2025 全球事件响应报告
Google’s SafetyCore App Secretly Scans All Your Photos on Android Phones
A recent surge in user reports has revealed that Google’s Android System SafetyCore—a system service designed to enable on-device content scanning—has been silently installed on Android devices running Android 9 and later since October 2024. The app, identified by the package name com.google.android.safetycore, has sparked widespread concern over privacy and transparency, with critics likening its […]
The post Google’s SafetyCore App Secretly Scans All Your Photos on Android Phones appeared first on Cyber Security News.
CVE-2024-56812 | IBM EntireX 11.1 information exposure
CVE-2024-56811 | IBM EntireX 11.1 information exposure
CVE-2024-56810 | IBM EntireX 11.1 information exposure
CVE-2024-56496 | IBM EntireX 11.1 information exposure
CVE-2024-56495 | IBM EntireX 11.1 information exposure
CVE-2024-56494 | IBM EntireX 11.1 information exposure
CVE-2024-56493 | IBM EntireX 11.1 information exposure
CVE-2025-27154 | spotipy-dev spotipy up to 2.25.0 CacheHandler default permission (GHSA-pwhh-q4h6-w599)
CVE-2024-54169 | IBM EntireX 11.1 URL path traversal
CVE-2021-42785 | TightVNC up to 1.3.10 FramebufferUpdate Packet tvnviewer.exe buffer overflow
CVE-2023-39215 | Zoom Client improper authentication
Hackers Exploited XSS Vulnerability in Popular Framework to Hijack 350+ Websites
A cross-site scripting (XSS) vulnerability within the Krpano framework, a popular tool for embedding 360° images and creating virtual tours, has been exploited to inject malicious scripts into over 350 websites. This widespread campaign manipulates search engine results and spreads spam advertisements across the internet. Security researcher Oleg Zaytsev discovered the campaign, dubbed “360XSS,” after […]
The post Hackers Exploited XSS Vulnerability in Popular Framework to Hijack 350+ Websites appeared first on Cyber Security News.