Aggregator
CVE-2025-3777 | huggingface transformers up to 4.52.0 URL Validation image_utils.py startswith information disclosure (EUVD-2025-20211)
CVE-2025-3225 | run-llama llama_index up to 0.12.28 Sitemap XML xml entity expansion (EUVD-2025-20207)
CVE-2025-3046 | run-llama llama_index up to 0.12.27 Symbolic Link ObsidianReader path traversal (EUVD-2025-20216)
CVE-2025-3044 | run-llama llama_index up to 0.12.22.post1 MD5 Hash ArxivReader expected behavior violation
CVE-2025-6210 | run-llama llama_index up to 0.5.1 Hardlink load_data path traversal (EUVD-2025-20210)
CVE-2025-3466 | langgenius dify up to 1.1.2 insufficient isolation of system-dependent functions (EUVD-2025-20212)
CVE-2025-3262 | huggingface transformers up to 4.50.x chat.py SETTING_RE redos (EUVD-2025-20217)
Альтман молчал месяцами. Теперь ясно почему: GPT-5 стирает границы между текстом, видео и разумом
CVE-2025-3626 | Frauscher FDS102 up to 2.13.2 WebUI os command injection (VDE-2025-030)
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2014-3931 Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability
- CVE-2016-10033 PHPMailer Command Injection Vulnerability
- CVE-2019-5418 Rails Ruby on Rails Path Traversal Vulnerability
- CVE-2019-9621 Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Nine Years and Counting: NICE RAMPS Communities Keep Expanding Opportunities in Cybersecurity Work and Learning
CVE-2025-5472 | run-llama llama_index up to 0.12.37 JSONReader recursion (EUVD-2025-20209)
CVE-2025-3263 | huggingface transformers up to 4.50.x transformers.configuration_utils get_configuration_file redos (EUVD-2025-20215)
CVE-2025-6386 | parisneo lollms up to 20.0 parisneo/lollms authenticate_user information exposure (EUVD-2025-20213)
CVE-2025-3264 | huggingface transformers up to 4.50.x dynamic_module_utils.py get_imports redos (EUVD-2025-20214)
New Phishing Attack Impersonates DWP to Steal Credit Card Information from Users
A sophisticated phishing campaign targeting UK residents has been active since late May 2025, with a significant surge in activity during the second half of June. This malicious operation impersonates the Department for Work and Pensions (DWP), a key UK government body responsible for welfare and pension services, by sending fraudulent SMS messages to unsuspecting […]
The post New Phishing Attack Impersonates DWP to Steal Credit Card Information from Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVSS 9.8 из 10: один клик — и ваш Mac — ловушка, а вы — жертва
1000+ New Fake Domains Mimic Amazon Prime Day Registered to Hunt Online Shoppers
As Amazon Prime Day 2025 approaches on July 8-11, millions of eager shoppers are preparing their wish lists and hunting for the best deals. However, cybercriminals are equally prepared, having registered over 1,000 new fake domains resembling Amazon in June alone. Alarmingly, 87% of these domains have already been flagged as malicious or suspicious, with […]
The post 1000+ New Fake Domains Mimic Amazon Prime Day Registered to Hunt Online Shoppers appeared first on Cyber Security News.