Aggregator
CVE-2025-1189 | 1000 Projects Attendance Tracking Management System 1.0 /admin/chart1.php course_id sql injection
CVE-2025-1188 | Codezips Gym Management System 1.0 updateroutine.php tid sql injection
CVE-2025-1187 | code-projects Police FIR Record Management System 1.0 Delete Record stack-based overflow
Submit #496452: 1000 Projects Attendance Tracking Management System PHP & MySQL Project V1.0 SQL Injection [Accepted]
Massive Data Breach Allegedly Hits Waze, Over 7.6 Million Accounts for Sale
CVE-2025-1164 | code-projects Police FIR Record Management System 1.0 Add Record stack-based overflow
Submit #496409: Codezips Gym Management System in PHP with Source Code v1.0 SQL Injection [Accepted]
诚邀渠道合作伙伴共启新征程
商业公司借AI热潮释放远控后门病毒
CVE-2025-1099 | TP-Link Tapo C500 V1 Wi-Fi Camera RSA Private Key hard-coded key (CIVN-2025-0017)
CVE-2025-1175 | Kelio Visio 1/Visio X7/Visio X4 up to 5.1K HTTP POST Request /PageLoginVisio.do cross site scripting
Submit #495921: code-projects POLICE FIR RECORD MANAGEMENT SYSTEM v1.0 c stack overflow [Accepted]
New ‘BYOTB’ Attack Exploits Trusted Binaries to Evade Detection, Researchers Reveal
A recent cybersecurity presentation at BSides London 2024 has unveiled a sophisticated attack technique known as Bring Your Own Trusted Binary (BYOTB). This method leverages legitimate, trusted binaries to evade detection by advanced security measures such as Endpoint Detection and Response (EDR) systems and firewalls. The findings, presented by cybersecurity researcher David Kennedy of Jumpsec […]
The post New ‘BYOTB’ Attack Exploits Trusted Binaries to Evade Detection, Researchers Reveal appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
XE Group shifts from credit card skimming to exploiting zero-days
SAML Bypass Authentication on GitHub Enterprise Servers to Login as Other User Account
A severe security vulnerability, tracked as CVE-2025-23369, has been identified in GitHub Enterprise Server (GHES), allowing attackers to bypass SAML authentication and impersonate other user accounts. This flaw exploits quirks in the libxml2 library used during SAML response validation, enabling unauthorized access to accounts, including those with administrative privileges. The vulnerability arises from improper handling […]
The post SAML Bypass Authentication on GitHub Enterprise Servers to Login as Other User Account appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
NanoCore RAT Attack Windows Using Task Scheduler to Captures keystrokes, screenshots
NanoCore, a notorious Remote Access Trojan (RAT), continues to pose a significant threat to Windows systems. This malware, known for its espionage capabilities and modular design, is being leveraged by cybercriminals to exfiltrate sensitive data, control infected systems, and maintain persistence using advanced techniques. A recent analysis of a NanoCore sample (MD5 hash: 18B476D37244CB0B435D7B06912E9193) sheds […]
The post NanoCore RAT Attack Windows Using Task Scheduler to Captures keystrokes, screenshots appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers Exploiting Google Tag Managers to Steal Credit Card from eCommerce Sites
In a concerning development, cybercriminals are leveraging Google Tag Manager (GTM), a legitimate tool widely used by eCommerce websites, to deploy malicious scripts designed to steal credit card information. This attack vector, often referred to as Magecart or e-skimming, has been observed targeting platforms like Magento, WordPress, and OpenCart, among others. The abuse of GTM […]
The post Hackers Exploiting Google Tag Managers to Steal Credit Card from eCommerce Sites appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.