Aggregator
Cost Optimization Done Right — Even in a Volatile Economy
5 hours 49 minutes ago
Beyond the Org Chart: How CHROs Need to Approach Organization Design
5 hours 49 minutes ago
The Future of HR: Clear the Hurdles, Reap the Benefits
5 hours 49 minutes ago
CVE-2025-21075
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 7 - Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.
CVE-2025-33183
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 7 - NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data ...
CVE-2025-66516
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 16 - Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.
This CVE covers the same ...
CVE-2025-13032
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 1 - Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privelages via pool overflow.
CVE-2025-66478
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 54 - Rejected reason: This CVE is a duplicate of CVE-2025-55182.
CVE-2025-55182
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 83 - A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code ...
CVE-2025-12762
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 19 - pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting ...
CVE-2025-9242
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 12 - An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway ...
CVE-2025-43300
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 7 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12. Processing a malicious image file may result in memory corruption. Apple is aware of a report that this issue may have ...
CVE-2025-21836
5 hours 53 minutes ago
Currently trending CVE - Hype Score: 12 - In the Linux kernel, the following vulnerability has been resolved:
io_uring/kbuf: reallocate buf lists on upgrade
IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it
was created for legacy selected buffer and has been emptied. It violates
the requirement ...
AstrBot 远程代码执行(CVE-2025-55449)漏洞分析
6 hours 44 minutes ago
因使用固定JWT密钥,AstrBot存在认证绕过及RCE漏洞,攻击者可上传恶意插件执行任意代码。
实战——记一次利用AI实现逆向绕过防重放、sgin值伪造,全数据包加密
6 hours 46 minutes ago
实战——记一次利用AI实现逆向绕过防重放、sgin值伪造,全数据包加密
NjRAT 样本分析
6 hours 53 minutes ago
本文针对远程访问木马 NjRAT 的变种 0.7d Green Edition 进行样本分析,从静态与动态两个层面系统梳理其关键特征。静态分析还原了其基于 .NET 的结构、入口流程、安装与持久化机制(自复制、自启动、防火墙放行、USB 传播)以及将自身标记为关键进程从而导致强制终止触发 BSOD 的自保护逻辑。动态分析则通过系统与网络行为观察其注册表和文件操作、C2 上线与心跳协议、Base64
Apache Causeway (CVE-2025-64408) 反序列化远程代码执行漏洞分析
6 hours 54 minutes ago
Apache Causeway 是 Apache 基金会开源的 Java 企业级领域建模框架,基于 Spring Boot 架构,能够为实体类、领域服务和 ViewModel 自动生成 Web 界面与 API 接口,广泛应用于企业级管理系统的构建。
在受影响的版本中,框架在处理 ViewModel 的书签(bookmark)与 URL 片段时存在严重的安全缺陷:**系统将客户端可控的内容直接作为
JNDI注入攻防全解析:从低版本RCE到高版本绕过分析
6 hours 57 minutes ago
前言我们将从最经典的低版本 RMI/LDAP + 远程 Codebase 利用切入,剖析 Reference 如何触发远程类加载、静态块如何成为 RCE 的第一落点;继而聚焦高版本 JDK 的防护逻辑——为何 trustURLCodebase 默认关闭后传统利用失效?又如何通过“本地工厂”这一合法身份实现权限跃迁?文中详细拆解了三种主流绕过路径:Tomcat 的 BeanFactory:借 EL
先知安全沙龙第11场 - AI应用安全攻防实录
7 hours ago
先知安全沙龙第11场 - AI应用安全攻防实录