Aggregator
CVE-2024-32638 | Apache APISIX 3.8.0/3.9.0 forward-auth Plugin request smuggling
CVE-2023-35701 | Apache Hive 4.0.0-alpha-1 JDBC Driver code injection
CVE-2024-4321 | gaizhenbiao chuanhuchatgpt Name file inclusion
CVE-2024-4284 | mintplex-labs anything-llm up to 0.x ID resource consumption
CVE-2024-1287 | WP-FeedStats pmpro-member-directory Plugin up to 1.2.5 on WordPress access control
CVE-2020-18442 | ZZIPlib 0.13.69 unzzip_cat_file zzip_file_read infinite loop (Nessus ID 211358)
外交部警告美国,不要搞“长臂管辖”
海洋中的纳米塑料多达数千万吨
CVE-2025-53624 | webbertakken docusaurus-plugin-content-gists up to 3.x GitHub Personal Access Token information disclosure (GHSA-qf34-qpr4-5pph / EUVD-2025-20874)
CVE-2025-7407 | Netgear D6400 1.0.0.114 diag.cgi host_name os command injection (EUVD-2025-20999)
CVE-2025-53364 | parse-server up to 7.5.2/8.2.1 GraphQL Schema exposure of sensitive system information to an unauthorized control sphere (EUVD-2025-21001)
4 Arrests in Dawn Raid of Scattered-Spider Suspects
Alleged arachnid arrests: Three teenage males and a young woman hauled away by cops, suspected of hacking huge retailers.
The post 4 Arrests in Dawn Raid of Scattered-Spider Suspects appeared first on Security Boulevard.
Пощёчина BigTech: крошечная страна создала ИИ мощнее ChatGPT и отдаёт его даром
Palo Alto Networks GlobalProtect Vulnerability Allows Root User Privilege Escalation
Palo Alto Networks has disclosed a critical security vulnerability in its GlobalProtect VPN application that enables locally authenticated users to escalate their privileges to root access on macOS and Linux systems, or NT AUTHORITY\SYSTEM on Windows machines. The vulnerability, classified as an incorrect privilege assignment flaw, poses significant security risks for organizations relying on the […]
The post Palo Alto Networks GlobalProtect Vulnerability Allows Root User Privilege Escalation appeared first on Cyber Security News.
CVE-2014-3008 | Unitrends Enterprise Backup 7.3.0 comm os command injection (EDB-32885 / XFDB-92642)
Russian pro basketball player arrested for alleged role in ransomware attacks
Why your AppSec Tool Stack Is Failing in the Age of AI
The world of software development is changing fast. AI isn’t just influencing software – it’s reshaping how software is written and the components it’s made of. First, AI-generated code is accelerating development. Code is produced faster, in larger volumes, and often without the same level of review or accountability as human-written code. Second, teams are..
The post Why your AppSec Tool Stack Is Failing in the Age of AI appeared first on Security Boulevard.