Aggregator
CVE-2025-54690 | Xinterio Plugin up to 4.2 on WordPress file inclusion
CVE-2025-48169 | Code Engine Plugin up to 0.3.3 on WordPress privilege escalation
Play
You must login to view this content
FCC tightens rules on foreign firms building undersea cables, citing security
The agency said the cables responsible for powering that data explosion must be protected from acts of foreign sabotage.
The post FCC tightens rules on foreign firms building undersea cables, citing security appeared first on CyberScoop.
CVE-2025-53187 | ABB ASPECT 3.07 code injection
Play
You must login to view this content
CVE-2025-8866 | YugabyteDB prior 2025.x API Endpoint /metamaster/universe information disclosure
Play
You must login to view this content
CVE-2025-54063 | CherryHQ cherry-studio up to 1.5.0 URL code injection
Эпоха «уязвимости — личная проблема компании» закончилась. Теперь это вопрос национальной безопасности
CVE-2025-45146 | ModelCache for LLM up to 0.2.0 /manager/data_manager.py deserialization
CVE-2025-38499 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.2 clone_private_mnt privilege escalation
WinRAR zero-day exploited in espionage attacks against high-value targets
Endpoint Security Policy: Why It Matters and How to Get It Right
A strong endpoint security policy protects devices like laptops, phones, and servers from cyber threats. It enforces least privilege, device control, encryption, and access management to prevent breaches and ensure compliance. With tools like Netwrix, organizations can automate enforcement, monitor compliance, and adapt to evolving risks across all endpoints. Your biggest security risk isn’t your … Continued
Details emerge on WinRAR zero-day attacks that infected PCs with malware
Qilin
You must login to view this content
Researchers Warn of 'Hidden Risks' in Passwordless Account Recovery
Win-DoS’ Zero-Click Exploit Could Weaponize Windows Infrastructure for DDoS Attacks
Security researchers have uncovered a “zero-click” denial-of-service chain that can silently turn thousands of Microsoft Windows Domain Controllers (DCs) into a globe-spanning botnet, raising fresh alarms in a year already defined by record-breaking distributed-denial-of-service (DDoS) activity. DDoS attacks climbed 56% year-over-year in late-2024 according to Gcore’s latest Radar report, and Cloudflare’s network has already blocked […]
The post Win-DoS’ Zero-Click Exploit Could Weaponize Windows Infrastructure for DDoS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
House lawmakers seek better tech for Commerce in fight against foreign powers
A bipartisan bill from Reps. Crow and Kean would give the Bureau of Industry and Security IT upgrades to help keep U.S. dual-use technologies away from Russia, China and others.
The post House lawmakers seek better tech for Commerce in fight against foreign powers appeared first on CyberScoop.