Aggregator
CVE-2025-9184 | Mozilla Thunderbird up to 141 memory corruption
CVE-2025-8364 | Mozilla Firefox up to 140 on Android blob URL ui layer
CVE-2025-43745 | Liferay Portal/DXP up to 7.4.3.132 Authenticated User Via Endpoint endpoint cross-site request forgery
CVE-2025-55740 | Anipaleja nginx-defender up to 1.4.x default credentials (GHSA-pr72-8fxw-xx22)
CVE-2025-55295 | StuffAnThings qbit_manage up to 4.5.3 restore_config_from_backup backup_id path traversal (GHSA-vh56-26wq-vvfv)
CVE-2025-52338 | LogicData eCommerce Framework 5.0.9.7000 password recovery
CVE-2025-43743 | Liferay Portal/DXP Calendar information exposure
CVE-2025-52337 | LogicData eCommerce Framework 5.0.9.7000 Content Explorer Feature unrestricted upload
CVE-2025-55303 | withastro up to 4.16.17/5.13.1 Image Optimization Endpoint /_image cross site scripting (GHSA-xf8x-j4p2-f749)
CVE-2025-55733 | ThinkInAIXYZ deepchat up to 0.3.0 URL code injection (GHSA-hqr4-4gfc-5p2j)
CVE-2025-55306 | Mouy-leng GenX_FX up to 1.0.0 Environment Variable insufficiently protected credentials (GHSA-2xjq-pvwj-mvm6)
CVE-2025-33008 | IBM Sterling B2B Integrator/Sterling File Gateway 6.2.1.0 Web UI cross site scripting
CVE-2025-2988 | IBM Sterling B2B Integrator/Sterling File Gateway up to 6.1.2.7/6.2.0.4/6.2.1.0 exposure of sensitive system information to an unauthorized control sphere
Amazon Q Developer: Remote Code Execution with Prompt Injection
The Amazon Q Developer VS Code Extension (Amazon Q) is a popular coding agent, with over 1 million downloads.
The extension is vulnerable to indirect prompt injection, and in this post we discuss a vulnerability that allowed an adversary (or also the AI for that matter) to run arbitrary commands on the host without the developer’s consent.
The resulting impact of the vulnerability is the same as CVE-2025-53773 that Microsoft fixed in GitHub Copilot, however AWS did not issue a CVE when patching the vulnerabiliy.
CVE-2024-44373 | AllSky 2023.05.01_04 /includes/save_file.php path/content path traversal
Russian Hacktivists Take Aim at Polish Power Plant, Again
论甲方安全建设的主矛盾
Optimistic Outlooks: Why NHIs Are Key to Future Security
Why Are NHIs Crucial to the Future of Security? Are you seeking a forward-thinking, adaptive approach to cybersecurity? This is where Non-Human Identities (NHIs) come into play. Traditional protective measures struggle to keep up. With a focus on NHIs, the future of security seems more optimistic, empowering organizations to proactively deal with potential threats instead […]
The post Optimistic Outlooks: Why NHIs Are Key to Future Security appeared first on Entro.
The post Optimistic Outlooks: Why NHIs Are Key to Future Security appeared first on Security Boulevard.
Are You Certain Your DevOps Are Secure?
How Secure Are Your DevOps in Today’s Cloud Environments? Is the security of your DevOps teams a definite assurance for you? Or is there an underlying, nagging doubt that perhaps there exists gaps in your Non-Human Identities (NHIs) and secrets? NHIs are machine identities utilized, marrying a unique “Secret” with permission granted by a server. […]
The post Are You Certain Your DevOps Are Secure? appeared first on Entro.
The post Are You Certain Your DevOps Are Secure? appeared first on Security Boulevard.