Aggregator
CVE-2025-7888 | TDuckCloud tduck-platform 5.1 UserFormDataMapper.java UserFormDataMapper formKey sql injection (EUVD-2025-22009)
Submit #615270: Dunamu StockPlus 7.62.10 Task Hijacking [Accepted]
Submit #615250: CallApp Caller ID 2.0.4 Task Hijacking [Accepted]
Submit #615210: TDuckCloud tduck-platform 5.1 SQL Injection [Accepted]
New Veeam Themed Phishing Attack Using Weaponized Wav File to Attack users
A sophisticated phishing campaign targeting organizations has emerged, exploiting the trusted reputation of Veeam Software through weaponized WAV audio files delivered via email. The attack represents an evolution in social engineering tactics, combining traditional phishing techniques with audio-based deception to bypass conventional security measures and user awareness training. The malicious campaign begins with seemingly legitimate […]
The post New Veeam Themed Phishing Attack Using Weaponized Wav File to Attack users appeared first on Cyber Security News.
Китайцы создали робота, неотличимого от Адама Сэндлера на прогулке
Unicorn-BinaryNinja 去除csel-br 间接跳转混淆
锁定今晚20:30 | 张银奎带你拆解异常处理、GIC 配置与 Linux 内核中断(直播间惊喜抽奖)
Unicorn-BinaryNinja 去除csel-br 间接跳转混淆
锁定今晚20:30 | 张银奎带你拆解异常处理、GIC 配置与 Linux 内核中断(直播间惊喜抽奖)
New CrushFTP 0-Day Vulnerability Exploited in the Wild to Gain Access to Servers
A critical zero-day flaw in the CrushFTP managed file-transfer platform was confirmed after vendor and threat-intelligence sources confirmed active exploitation beginning on 18 July 2025 at 09:00 CST. Tracked as CVE-2025-54309, the bug allows unauthenticated attackers to obtain full administrative control of vulnerable servers over HTTPS. CrushFTP says the issue was inadvertently resolved in builds […]
The post New CrushFTP 0-Day Vulnerability Exploited in the Wild to Gain Access to Servers appeared first on Cyber Security News.