Aggregator
Perl больше не тот: copy-on-write, Unicode 16 и all/any в одном пакете
DragonForce
You must login to view this content
The Detection Series: Initial Access
“CitrixBleed 2” Vulnerability PoC Released – Warns of Potential Widespread Exploitation
Critical flaw in Citrix NetScaler devices echoes infamous 2023 security breach that crippled major organizations worldwide. The new critical vulnerability in Citrix NetScaler devices has security experts warning of potential widespread exploitation, drawing alarming parallels to the devastating “CitrixBleed” attacks that plagued organizations in 2023. The vulnerability, tracked as CVE-2025-5777 and dubbed “CitrixBleed 2,” allows […]
The post “CitrixBleed 2” Vulnerability PoC Released – Warns of Potential Widespread Exploitation appeared first on Cyber Security News.
如何利用ai辅助挖漏洞
Submit #607209: Bludit 3.16.2 Unrestricted Upload [Duplicate]
Submit #607203: Bludit 3.16.2 Improper Neutralization of Alternate XSS Syntax [Duplicate]
CVE-2025-7080 | Done-0 Jank up to 322caebbad10568460364b9667aa62c3080bfc17 JWT Token jwt_utils.go accessSecret/refreshSecret hard-coded password (EUVD-2025-20136)
CVE-2025-7079 | mao888 bluebell-plus up to 2.3.0 JWT Token jwt.go mySecret hard-coded password (Issue 35 / EUVD-2025-20137)
Submit #603746: https://github.com/Done-0 https://github.com/Done-0/Jank 9b7b0cb Authorization Bypass [Accepted]
Submit #603726: https://github.com/mao888 https://github.com/mao888/bluebell-plus v2.3.0 Authorization Bypass [Accepted]
CVE-2025-7078 | 07FLYCMS/07FLY-CMS/07FlyCRM up to 1.3.9 cross-site request forgery (EUVD-2025-20135)
Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure
Russian Federal Security Service (FSB) officers have detained two hackers in Siberia who conducted cyberattacks on critical infrastructure facilities under direct orders from Ukrainian intelligence services. The simultaneous arrests in the Kemerovo and Tomsk regions exposed a sophisticated cyber espionage network targeting Russia’s governmental, industrial, and financial information systems. The primary suspect, a 36-year-old resident […]
The post Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure appeared first on Cyber Security News.
Submit #603552: 07FLYCMS https://github.com/lingqifei/07fly-crm V1.3.9 CSRF [Accepted]
Submit #603132: 程序员二师兄 oasys master arbitrary file reading [Duplicate]
CVE-2025-7077 | Shenzhen Libituo Technology LBT-T300-T310 up to 2.2.3.6 /appy.cgi config_3g_para username_3g/password_3g buffer overflow (EUVD-2025-20133)
Submit #603012: LinBle LBT-T300-T310 v2.2.3.6 Buffer Overflow [Accepted]
微软 XBox 业务高管建议被裁员的员工用 AI 管理情绪
Threat Actors Turning Job Offers Into Traps, Over $264 Million Lost in 2024 Alone
Cybercriminals are exploiting the economic uncertainty and remote work trends to orchestrate sophisticated employment fraud schemes, with victims losing over $264 million in 2024 alone according to FBI reports. These malicious campaigns, known as “task scams,” represent a rapidly evolving threat landscape where fraudsters weaponize legitimate job-seeking behavior to extract cryptocurrency payments from unsuspecting victims […]
The post Threat Actors Turning Job Offers Into Traps, Over $264 Million Lost in 2024 Alone appeared first on Cyber Security News.