Aggregator
CVE-2025-5034 | wp-file-download Plugin up to 6.2.5 on WordPress cross site scripting
CVE-2025-5944 | Element Pack Addons for Elementor Plugin up to 8.0.0 on WordPress data-caption cross site scripting
CVE-2025-53256 | YayCommerce YaySMTP Plugin up to 6.8.1 on WordPress sql injection (EUVD-2025-19394)
CVE-2025-6363 | code-projects Simple Pizza Ordering System 1.0 /adding-exec.php ingname sql injection (EUVD-2025-18785)
CVE-2025-6296 | code-projects Hostel Management System 1.0 /empty_rooms.php search_box sql injection (EUVD-2025-18711)
CVE-2025-6281 | OpenBMB XAgent up to 1.0.0 /conv/community path traversal (Issue 415 / EUVD-2025-18701)
CVE-2025-4955 | WP-FeedStats tarteaucitron.io Plugin up to 1.9.4 on WordPress Query Parameter cross site scripting (EUVD-2025-18664)
MacOS пал: северокорейцы проникли туда, где Apple считала себя неуязвимой
测试 Firefox 120 到 Firefox 141 在 Linux 下的性能
Chrome Cookie Encryption Bypassed: “C4 Attack” Exploits Padding Oracle to Steal Cookies
Google has once again drawn the attention of cybersecurity experts following its implementation of a new user data protection mechanism in the Chrome browser—AppBound Cookie Encryption. Although the initiative reflects an ambitious stride toward...
The post Chrome Cookie Encryption Bypassed: “C4 Attack” Exploits Padding Oracle to Steal Cookies appeared first on Penetration Testing Tools.
GitPhish: Open-source GitHub device code flow security assessment tool
GitPhish is an open-source security research tool built to replicate GitHub’s device code authentication flow. It features three core operating modes: an authentication server, automated landing page deployment, and an administrative management interface. GitPhish can be accessed via a command-line interface or a web dashboard, offering comprehensive features such as logging, analytics, and token management. “We designed GitPhish explicitly for security teams looking to conduct assessments and build detection capabilities around Device Code Phishing in … More →
The post GitPhish: Open-source GitHub device code flow security assessment tool appeared first on Help Net Security.
StealthMACsec strengthens Ethernet network security
StealthCores launched StealthMACsec, a comprehensive IEEE 802.1AE compliant MACsec engine that brings advanced side-channel countermeasures to Ethernet network security. Building on the proven security foundation of StealthAES, StealthMACsec delivers line-rate processing up to 10 Gbps on FPGA and even faster on ASIC while maintaining the highest levels of protection against sophisticated attacks. As Ethernet networks become increasingly critical to defense, industrial, and embedded systems, the need for link-layer security has never been greater. StealthMACsec addresses … More →
The post StealthMACsec strengthens Ethernet network security appeared first on Help Net Security.