Aggregator
CVE-2025-46732 | OpenCTI up to 6.6.5 GrapQL improper authorization (GHSA-535g-qp2c-h7vp)
CVE-2025-46000 | Filemanager 2.5.0 SVG File filemanager.rsc.class.php unrestricted upload (EUVD-2025-21885)
CVE-2025-46002 | Filemanager up to 2.5.0 HTTP Request filemanager.php path traversal (Exploit 38945 / EUVD-2025-21878)
CVE-2025-50126 | rsjoomla RSBlog Component up to 1.14.5 on Joomla jform[tags_text] cross site scripting (EUVD-2025-21868)
Scavenger Malware Hijacks Popular npm Packages to Attack Developers
A sophisticated supply chain attack targeting JavaScript developers emerged on Friday, July 18th, 2025, when cybercriminals compromised multiple popular npm packages to distribute the newly identified “Scavenger” malware. The attack primarily focused on eslint-config-prettier, a widely-used code formatting package, along with several other development tools including eslint-plugin-prettier, snyckit, @pkgr/core, and napi-postinstall. The compromise was discovered […]
The post Scavenger Malware Hijacks Popular npm Packages to Attack Developers appeared first on Cyber Security News.
Defending Against ToolShell: SharePoint’s Latest Critical Vulnerability
Defending Against ToolShell: SharePoint’s Latest Critical Vulnerability
Pavel Durov Warns: New Extortion Wave Targets Telegram Users for Digital Assets
Pavel Durov, the founder of Telegram, has issued a warning about a new wave of extortion emerging within the platform. The scheme involves fraudsters demanding that users surrender valuable digital assets—rare Telegram gifts, premium...
The post Pavel Durov Warns: New Extortion Wave Targets Telegram Users for Digital Assets appeared first on Penetration Testing Tools.