Aggregator
McFlaw: Hacker Breaches McDonald's Portal With URL Trick
10 months 1 week ago
Hacking Was the Easy Part, Notifying McDonald's the Extremely Difficult Bit
A security researcher gained access to McDonald's global marketing portal by changing a single word in its URL, uncovering a slew of additional vulnerabilities. The hard part was notifying the burger giant about the flaws, says self-described ethical hacker "BobDaHacker."
A security researcher gained access to McDonald's global marketing portal by changing a single word in its URL, uncovering a slew of additional vulnerabilities. The hard part was notifying the burger giant about the flaws, says self-described ethical hacker "BobDaHacker."
Drug R&D Firm's IT, Data Encrypted in Alleged Qilin Attack
10 months 1 week ago
Inotiv Inc. Tells SEC Some Business Operations Disrupted, No Recovery Date in Sight
Inotiv, a drug research and development firm, told federal regulators that it's been dealing with a cyberattack since Aug. 8 that has encrypted some IT systems and data, and is disrupting certain business operations. Ransomware gang Qilin has listed the company as a victim on its dark website.
Inotiv, a drug research and development firm, told federal regulators that it's been dealing with a cyberattack since Aug. 8 that has encrypted some IT systems and data, and is disrupting certain business operations. Ransomware gang Qilin has listed the company as a victim on its dark website.
Anthropic Tests Safeguard for AI 'Model Welfare'
10 months 1 week ago
Claude Models May Shut Down Harmful Chats in Some Edge Cases
Anthropic introduced a safeguard to its Claude artificial intelligence platform that allows certain models to end conversations in cases of persistently harmful or abusive interactions. The company said it's doing so not to protect human users, but as a way to mitigate risks to the models.
Anthropic introduced a safeguard to its Claude artificial intelligence platform that allows certain models to end conversations in cases of persistently harmful or abusive interactions. The company said it's doing so not to protect human users, but as a way to mitigate risks to the models.
Russian Hackers Accused in Wave of Water Sector Cyberattacks
10 months 1 week ago
Successful Breaches Renew Fears of Operational Vulnerabilities Across Water Sector
Russia is suspected of escalating cyberattacks on European water utilities, including attempts to sabotage Polish and Norwegian water facilities and dams, signaling a broader threat to global critical infrastructure as state-backed actors exploit critical OT weaknesses amid global conflict.
Russia is suspected of escalating cyberattacks on European water utilities, including attempts to sabotage Polish and Norwegian water facilities and dams, signaling a broader threat to global critical infrastructure as state-backed actors exploit critical OT weaknesses amid global conflict.
FBI: Russia-linked group Static Tundra exploit old Cisco flaw for espionage
10 months 1 week ago
FBI警告俄罗斯关联组织Static Tundra利用Cisco 7年前漏洞CVE-2018-0171进行网络间谍活动,主要针对美国及全球关键基础设施和特定行业,窃取配置数据并建立持久访问。
FBI: Russia-linked group Static Tundra exploit old Cisco flaw for espionage
10 months 1 week ago
FBI warns FSB-linked group Static Tundra is exploiting a 7-year-old Cisco IOS/IOS XE flaw to gain persistent access for cyber espionage. The FBI warns that Russia-linked threat actor Static Tundra exploits Simple Network Management Protocol (SNMP) and end-of-life networking devices running an unpatched vulnerability (CVE-2018-0171) in Cisco Smart Install (SMI) to target organizations in the […]
Pierluigi Paganini
深度求索正式发布并开源DeepSeek-V3.1模型 提供128K上下文 调整API价格
10 months 1 week ago
深度求索发布并开源DeepSeek-V3.1模型,采用混合架构整合思考与非思考模式,并提升效率。支持Anthropic API格式接入Claude Code框架。API价格自9月6日起调整为输入缓存0.5元/百万、非缓存4元/百万。
We Put Agentic AI Browsers to the Test - They Clicked, They Paid, They Failed
10 months 1 week ago
/r/netsec 是一个由社区管理的技术信息安全聚合平台,旨在为安全从业者、学生、研究人员和黑客提供有价值的信息。
Финансовые документы, Skype и скрытый код — новый троянец GodRAT атакует брокеров и трейдеров
10 months 1 week ago
Вредонос крадёт данные из Chrome и Microsoft Edge.
Grok AI也出现将用户聊天暴露给搜索引擎的错误 同样没有做好必要的提醒和反爬
10 months 1 week ago
Grok AI 和 ChatGPT 均出现用户分享对话被搜索引擎抓取的问题。用户生成分享链接时未获提醒且无反爬措施, 致超30万条包含敏感信息的会话被公开。OpenAI 已下线并道歉, 但 xAI 未采取行动。
Want Stronger Frontend Skills? Spend a Week On-Call
10 months 1 week ago
Den Odell探讨了未来前端开发的趋势、技术发展及性能优化。
CVE-2025-9253 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_doSpecifySiteSurvey ssidhex stack-based overflow
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function RP_doSpecifySiteSurvey of the file /goform/RP_doSpecifySiteSurvey. The manipulation of the argument ssidhex leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2025-9253. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-9263 | Xuxueli xxl-job up to 3.1.1 JobLogController.java getJobsByGroup jobGroup resource injection (Issue 3772)
10 months 1 week ago
A vulnerability categorized as problematic has been discovered in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to improper control of resource identifiers.
This vulnerability is traded as CVE-2025-9263. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-7221 | GiveWP Plugin up to 4.5.0 on WordPress give_update_payment_status authorization
10 months 1 week ago
A vulnerability, which was classified as problematic, has been found in GiveWP Plugin up to 4.5.0 on WordPress. This affects the function give_update_payment_status. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2025-7221. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-8592 | Inspiro Plugin up to 2.1.2 on WordPress Installation inspiro_install_plugin cross-site request forgery
10 months 1 week ago
A vulnerability, which was classified as problematic, was found in Inspiro Plugin up to 2.1.2 on WordPress. This impacts the function inspiro_install_plugin of the component Installation Handler. The manipulation results in cross-site request forgery.
This vulnerability was named CVE-2025-8592. The attack may be performed from a remote location. There is no available exploit.
vuldb.com
CVE-2025-8607 | FunnelKit SlingBlocks Plugin up to 1.6.0 on WordPress Countdown Block cross site scripting
10 months 1 week ago
A vulnerability has been found in FunnelKit SlingBlocks Plugin up to 1.6.0 on WordPress and classified as problematic. Affected is an unknown function of the component Countdown Block Handler. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-8607. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-9250 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 /goform/setPWDbyBBS hint stack-based overflow (EUVD-2025-25406)
10 months 1 week ago
A vulnerability described as critical has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts the function setPWDbyBBS of the file /goform/setPWDbyBBS. Such manipulation of the argument hint leads to stack-based buffer overflow.
This vulnerability is referenced as CVE-2025-9250. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-9251 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 /goform/sta_wps_pin Ssid stack-based overflow (EUVD-2025-25402)
10 months 1 week ago
A vulnerability classified as critical has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function sta_wps_pin of the file /goform/sta_wps_pin. Performing manipulation of the argument Ssid results in stack-based buffer overflow.
This vulnerability is identified as CVE-2025-9251. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-9252 | Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 DisablePasswordAlertRedirect hint stack-based overflow (EUVD-2025-25401)
10 months 1 week ago
A vulnerability classified as critical was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function DisablePasswordAlertRedirect of the file /goform/DisablePasswordAlertRedirect. Executing manipulation of the argument hint can lead to stack-based buffer overflow.
This vulnerability is tracked as CVE-2025-9252. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com