Aggregator
泛微E-cology9 前台SQL注入漏洞
从 AI 高考聊到人类未来|张鹏×潘乱×张一甲 对谈实录
从 AI 高考聊到人类未来|张鹏×潘乱×张一甲 对谈实录
What EU’s PQC roadmap means on the ground
In this Help Net Security interview, David Warburton, Director at F5 Labs, discusses how the EU’s Post-Quantum Cryptography (PQC) roadmap aligns with global efforts and addresses both the technical and regulatory challenges of migrating to PQC. Warburton also outlines practical steps organizations must take to ensure cryptographic agility and long-term data protection. How does the EU’s PQC roadmap align with global efforts, such as those from NIST and ETSI? Are there any key differences or … More →
The post What EU’s PQC roadmap means on the ground appeared first on Help Net Security.
Mitigating CitrixBleed 2 (CVE‑2025‑5777) NetScaler Memory Disclosure with App & API Protector
CVE-2024-2913 | mintplex-labs anything-llm User Invite toctou
CVE-2024-11038 | wpbean WPB Popup for Contact Form 7 Plugin up to 1.7.5 on WordPress Shortcode wpb_pcf_fire_contact_form code injection
CVE-2025-25477 | SysPass 3.2x Header Host injection (EUVD-2025-5488)
CVE-2025-3294 | benjaminprojas WP Editor Plugin up to 1.2.9.1 on WordPress path traversal
CVE-2025-3295 | benjaminprojas WP Editor Plugin up to 1.2.9.1 on WordPress path traversal
CVE-2025-4798 | Lester Chan WP-DownloadManager Plugin up to 1.68.10 on WordPress wp-config.php denial of service (EUVD-2025-18084)
CVE-2025-4799 | WP-DownloadManager Plugin up to 1.68.10 on WordPress absolute path traversal (EUVD-2025-18083)
CVE-2025-4798 | Lester Chan WP-DownloadManager Plugin up to 1.68.10 on WordPress path traversal (EUVD-2025-18084)
CVE-2025-4315 | CubeWP Plugin up to 1.1.23 on WordPress update_user_meta privileges management (EUVD-2025-18093)
CVE-2025-25478 | SysPass 3.2.x Filename unrestricted upload (EUVD-2025-5922)
CVE-2025-25476 | SysPass 3.2.x Notification cross site scripting (EUVD-2025-5921)
CVE-2025-25461 | SeedDMS 6.0.29 Category Name cross site scripting (EUVD-2025-5943)
McDonald’s AI Hiring Bot With Password ‘123456’ Leaks Millions of Job-Seekers Data
A severe security vulnerability in McDonald’s AI-powered hiring system has exposed the personal information of potentially 64 million job applicants to unauthorized access. Key Takeaways1. McDonald's AI hiring bot exposed 64 million job applicants' personal data through weak security using password "123456."2. Researchers accessed the entire system in 30 minutes using simple password guessing and […]
The post McDonald’s AI Hiring Bot With Password ‘123456’ Leaks Millions of Job-Seekers Data appeared first on Cyber Security News.
Fake online stores look real, rank high, and trap unsuspecting buyers
Shopping on a fake online store can lead to more than a bad purchase. It could mean losing money, having your identity stolen, or even getting malware on your device. E-shop scams rose by 790% in the first quarter of 2025 compared to the same period in 2024, according to Avast. Cybercriminals might be exploiting economic uncertainty as rising tariffs push consumers to seek cheaper deals online. This makes it easier to trick people with … More →
The post Fake online stores look real, rank high, and trap unsuspecting buyers appeared first on Help Net Security.