Aggregator
CVE-2025-54136 | Cursor up to 1.2.4 os command injection (GHSA-24mc-g4xr-4395 / EUVD-2025-23405)
CVE-2025-54789 | humhub cfiles up to 0.6.9 cross site scripting (GHSA-cw2v-c62w-5r43 / EUVD-2025-23404)
Submit #626294: https://phpgurukul.com/human-metapneumovirus-hmpv-testing-manage human-metapneumovirus-hmpv-testing-manage 1.0 SQL Injection [Duplicate]
CVE-2025-54132 | Cursor up to 1.2 Mermaid server-side request forgery (GHSA-43wj-mwcc-x93p / EUVD-2025-23407)
Он не требует учётки и не следит за вами. Что за странный аутентификатор запустила Proton?
CVE-2025-54133 | Cursor up to 1.2 Model Context Protocol os command injection (GHSA-r22h-5wp2-2wfv / EUVD-2025-23406)
CVE-2025-54386 | Traefik up to 2.11.27/3.4.4/3.5.0-rc1 ZIP Archive path traversal (GHSA-q6gg-9f92-r9wg / EUVD-2025-23415)
CVE-2025-54782 | nestjs nest up to 0.2.0 API Endpoint command injection (GHSA-85cg-cmq5-qjm7 / EUVD-2025-23413)
CVE-2025-54424 | 1Panel up to 2.0.5 HTTPS Protocol certificate validation (GHSA-8j63-96wh-wh3j / EUVD-2025-23409)
CVE-2025-54781 | himmelblau up to 1.0.x himmelblaud_tasks Service log file (GHSA-78qg-vmrw-574w / EUVD-2025-23414)
STRATEGIC REEL: Proactive by design: Fortinet retools network defense for real-time threats
Security teams can no longer afford to wait for alerts — not when cyberattacks unfold in milliseconds.
That’s the core warning from Fortinet’s Derek Manky in a new Last Watchdog Strategic Reel recorded at RSAC 2025. As adversaries adopt AI-driven … (more…)
The post STRATEGIC REEL: Proactive by design: Fortinet retools network defense for real-time threats first appeared on The Last Watchdog.
The post STRATEGIC REEL: Proactive by design: Fortinet retools network defense for real-time threats appeared first on Security Boulevard.
Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers
A sophisticated cyber espionage campaign targeting software developers has infiltrated two of the world’s largest open source package repositories, with North Korea’s notorious Lazarus Group successfully deploying 234 malicious packages across npm and PyPI ecosystems. Between January and July 2025, this state-sponsored operation exposed over 36,000 potential victims to advanced malware designed for long-term surveillance […]
The post Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers appeared first on Cyber Security News.
SafePay Ransomware Infected 260+ Victims Across Multiple Countries
A new ransomware threat has emerged as one of the most aggressive cybercriminal operations of 2025, with SafePay ransomware claiming responsibility for over 265 successful attacks spanning multiple continents. The group, which first appeared in September 2024 with limited activity targeting just over 20 victims, has dramatically escalated its operations since early 2025, establishing itself […]
The post SafePay Ransomware Infected 260+ Victims Across Multiple Countries appeared first on Cyber Security News.
Transitioning from Software Engineering to Cybersecurity — Advice?
Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS
The ransomware landscape experienced a significant shift in the second quarter of 2025 as Qilin ransomware emerged as the dominant threat following the unexpected collapse of RansomHub, previously the most prolific ransomware-as-a-service operation. This transition has reshaped the cybercriminal ecosystem, with Qilin capitalizing on the vacuum left by RansomHub’s abrupt cessation of operations in early […]
The post Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS appeared first on Cyber Security News.