Aggregator
CVE-2025-43353 | Apple macOS up to 14.7/15.6 String memory corruption (EUVD-2025-29279)
CVE-2025-43357 | Apple iOS/iPadOS up to 18.7 App information disclosure
CVE-2025-43357 | Apple macOS up to 18.4 App information disclosure
CVE-2025-34071 | GFI Kerio Control 9.4.5 upgrade.sh missing authentication (EUVD-2025-19720)
CVE-2025-34070 | GFI Kerio Control 9.4.5 GFIAgent Service /proxy missing authentication (EUVD-2025-19721)
CVE-2025-34069 | GFI Kerio Control 9.4.5 GFIAgent Service missing authentication (EUVD-2025-19722)
CVE-2025-34081 | Contec CONPROSYS HMI System up to 3.7.6 phpinfo insertion of sensitive information into debugging code (EUVD-2025-19656)
CVE-2025-34080 | Contec CONPROSYS HMI System up to 3.7.6 getqsetting.php cross site scripting (EUVD-2025-19659)
Крупнейшая биржа для фрилансеров массово сокращает сотрудников. К чему это приведёт?
New Shai-hulud Worm Infecting npm Packages With Millions of Downloads
Top 10 Best Security Orchestration, Automation, And Response (SOAR) Tools in 2025
In the face of an ever-increasing volume of security alerts, a critical shortage of skilled cybersecurity professionals, and the growing sophistication of cyber threats, Security Operations Centers (SOCs) are often overwhelmed. This is where Security Orchestration, Automation, and Response (SOAR) tools become a game-changer. A SOAR platform centralizes security alerts, orchestrates security tools to work […]
The post Top 10 Best Security Orchestration, Automation, And Response (SOAR) Tools in 2025 appeared first on Cyber Security News.
When Guardrails Aren't Enough: Reinventing Agentic AI Security With Architectural Controls
Atlassian security advisory (AV25-596)
CVE-2025-59455 | JetBrains TeamCity up to 2025.07.1 Project race condition (EUVD-2025-29703 / WID-SEC-2025-2079)
CVE-2025-59456 | JetBrains TeamCity up to 2025.07.1 Project Archive Upload path traversal (EUVD-2025-29704 / WID-SEC-2025-2079)
From ClickFix to MetaStealer: Dissecting Evolving Threat Actor Techniques
Critical WatchGuard Vulnerability Allows Unauthenticated Attacker to Execute Arbitrary Code
A critical vulnerability has been discovered in WatchGuard’s Firebox firewalls, which could allow a remote, unauthenticated attacker to execute arbitrary code on affected devices. The flaw, tracked as CVE-2025-9242, has been assigned a critical severity rating with a CVSS score of 9.3 out of 10. WatchGuard disclosed the issue in an advisory, WGSA-2025-00015, released on […]
The post Critical WatchGuard Vulnerability Allows Unauthenticated Attacker to Execute Arbitrary Code appeared first on Cyber Security News.