Aggregator
CVE-2025-8448 | Schneider Electric EcoStruxureTM Building Operation Enterprise Server SMB information disclosure (SEVD-2025-224-04)
CVE-2025-55483 | Tenda AC6 15.03.06.23 formSetMacFilterCfg macFilterType buffer overflow
CVE-2025-8449 | Schnieder Electric EcoStruxureTM Building Operation Enterprise Server Request resource consumption (SEVD-2025-224-04 / EUVD-2025-25280)
The Future of Pentesting: Can AI Replace Human Expertise? ⎥ Jyoti Raval
Discover insights from The Elephant in AppSec episode with Jyoti Raval
The post The Future of Pentesting: Can AI Replace Human Expertise? ⎥ Jyoti Raval appeared first on Security Boulevard.
New Salty 2FA PhaaS Attacking Microsoft 365 Users to Steal Login Credentials
A sophisticated new Phishing-as-a-Service (PhaaS) framework dubbed “Salty 2FA” has emerged as a significant threat to Microsoft 365 users across the US and European industries. This previously undocumented platform employs advanced obfuscation techniques and multi-stage execution chains specifically designed to bypass two-factor authentication mechanisms while stealing corporate credentials. The framework targets organizations spanning finance, telecommunications, […]
The post New Salty 2FA PhaaS Attacking Microsoft 365 Users to Steal Login Credentials appeared first on Cyber Security News.
Этого не ждал никто: ИИ-модели от Google и OpenAI будут управлять США
CVE-2025-9264 | Xuxueli xxl-job up to 3.1.1 Jobs JobInfoController.java remove ID resource injection (Issue 3773)
CVE-2025-9263 | Xuxueli xxl-job up to 3.1.1 JobLogController.java getJobsByGroup jobGroup resource injection (Issue 3772)
Submit #631728: xuxueli xxl-job ≤ 3.1.1 IDOR [Accepted]
Submit #631704: xuxueli xxl-job ≤ 3.1.1 IDOR [Accepted]
Microsoft investigates outage impacting Copilot, Office.com
Commvault security advisory (AV25-531)
CVE-2025-9262 | wong2 mcp-cli 1.13.0 oAuth /src/oauth/provider.js redirectToAuthorization os command injection
Apache ActiveMQ Breach Reveals Unusual Attacker Behavior
Security researchers have confirmed that a recent wave of cyberattacks is exploiting a critical vulnerability in Apache ActiveMQ, allowing attackers to compromise Linux servers and install long-term persistence tools. The attackers are not only gaining access through a known remote code execution flaw but are also patching the vulnerability afterward to cover their tracks. The […]
The post Apache ActiveMQ Breach Reveals Unusual Attacker Behavior appeared first on Centraleyes.
The post Apache ActiveMQ Breach Reveals Unusual Attacker Behavior appeared first on Security Boulevard.