Aggregator
GlobalFoundries 收购 MIPS
ServiceNow Platform Vulnerability Let Attackers Exfiltrate Sensitive Data
A significant vulnerability in ServiceNow’s platform, designated CVE-2025-3648 and dubbed “Count(er) Strike,” enables attackers to exfiltrate sensitive data, including PII, credentials, and financial information. This high-severity vulnerability exploits the record count UI element on list pages through enumeration techniques and query filters, potentially affecting all ServiceNow instances with hundreds of tables at risk. Key Takeaways1. […]
The post ServiceNow Platform Vulnerability Let Attackers Exfiltrate Sensitive Data appeared first on Cyber Security News.
Submit #609068: Live Helper Chat lhc-php-resque extension for Live Helper Chat < 0ce7b4f1193c0ed6c6e31a960fafededf979eef2 Cross Site Scripting [Accepted]
CVE-2025-7434 | Tenda FH451 up to 1.0.0.9 POST Request /goform/addressNat fromAddressNat page stack-based overflow (EUVD-2025-21101)
CVE-2025-53364 | parse-server up to 7.5.2/8.2.1 GraphQL Schema exposure of sensitive system information to an unauthorized control sphere (EUVD-2025-21001)
CVE-2025-6395 | GnuTLS _gnutls_figure_common_ciphersuite null pointer dereference (EUVD-2025-21000)
Apache Tomcat webshell application for RCE
Apache Tomcat webshell application for RCE A webshell application and interactive shell for pentesting Apache Tomcat servers. Features Webshell plugin for Apache Tomcat. Execute system commands via an API with ?action=exec. Download files from the...
The post Apache Tomcat webshell application for RCE appeared first on Penetration Testing Tools.
Submit #609058: Tenda FH451 v1.0.0.9 Stack-based Buffer Overflow [Accepted]
gallia: comprehensive penetration testing toolchain for cars
Gallia Gallia is an extendable pentesting framework with the focus on the automotive domain. The scope of the toolchain is conducting penetration tests from a single ECU up to whole cars, with the main...
The post gallia: comprehensive penetration testing toolchain for cars appeared first on Penetration Testing Tools.
《星露谷物语》成为 Steam 平台最受好评的游戏
CVE-2025-27614 | j6t gitk up to 2.50.0 os command injection (GHSA-g4v5-fjv9-mhhc / EUVD-2025-21004)
CVE-2025-44251 | Ecovacs Deebot T10 1.7.2 Wifi Credential missing encryption
CVE-2025-46334 | j6t git-gui up to 2.50.0 sh.exe os command injection (GHSA-7px4-9hg2-fvhx / EUVD-2025-21003)
UK Arrests Woman and Three Men for Cyberattacks on M&S Co-op and Harrods
CVE-2025-46835 | j6t git-gui up to 2.50.0 argument injection (GHSA-xfx7-68v4-v8fg / EUVD-2025-21002)
CVE-2025-27613 | j6t gitk up to 2.50.0 Command Argument os command injection (GHSA-f3cw-xrj3-wr2v / EUVD-2025-21005)
Топ-кварк + анти-топ: частицы, обречённые на одиночество, столкнулись. Назло всем законам
Hackers Abused GitHub to Spread Malware Mimic as VPN
A sophisticated malware campaign has emerged exploiting the trusted GitHub platform to distribute malicious software disguised as legitimate tools. Threat actors have successfully weaponized the popular code repository to host and distribute the notorious Lumma Stealer malware, masquerading it as helpful utilities like “Free VPN for PC” and “Minecraft Skin Changer.” This deceptive campaign demonstrates […]
The post Hackers Abused GitHub to Spread Malware Mimic as VPN appeared first on Cyber Security News.