#vulnerabilities

Xavier «X» Santolaria :verified_paw: :donor:0x58@infosec.exchange
2025-05-03

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #18/2025 is out!

It includes the following and much more:

🇫🇷 🇷🇺 France has linked Russian APT to 12 #cyberattacks on French Orgs.;

🇺🇸 Cybersecurity experts demand the reinstatement of Chris Krebs' security clearances and the withdrawal of the investigation;

🐛 🍎 #Vulnerabilities in Apple's #AirPlay Protocol;

🚉 New York's Metropolitan Transportation Authority plans to use #AI and cameras to detect potential subway crimes before they happen;

🇨🇳 @SentinelOne Targeted by Chinese #PurpleHaze Group;

🔐 #Microsoft sets all new accounts #passwordless by default;

🇺🇸 💸 The #Trump administration plans to cut $491 million from #CISA's budget;

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

2025-05-01

A couple of days ago, I unearthed my first #computer, an #MSX straight from the ‘80s. It was lost in some box in the basement for who knows how long. Just feeling its power switch gave me the goosebumps…

This discovery came after sharing my hacker’s origin story with Nic Fillingham and Wendy Zenone in a new episode of Microsoft’s #BlueHat #Podcast.

thecyberwire.com/podcasts/the-

Join us while we chat about my first-ever #CVE, overlooked #vulnerabilities that continue to pose significant risks today, #ActiveDirectory and #password security, my unexpected journey into #bugbounty hunting and my involvement in the #ZeroDayQuest, how to learn new things, mentorship and positive leadership, and of course pineapple pizza 🍍🍕

This is how you make a hacker
N-gated Hacker Newsngate
2025-04-30

GitHub's latest feature, DeepSeek-Prover-V2, promises to write better code with AI, find , and even automate workflows—all while you navigate a labyrinthine menu system likely designed by an M.C. Escher imitator 🎨🔍. Meanwhile, coders everywhere are left wondering if the AI can also automate crying into their keyboards at 3 AM 😭⌨️.
github.com/deepseek-ai/DeepSee

2025-04-30

Топ самых интересных CVE за апрель 2025 года

Публикуем нашу традиционную подборку ключевых CVE ушедшего месяца. В апреле главным событием стала RCE в SSH-библиотеке Erlang/OTP: десяточка по CVSS, простейший эксплойт, проверки концепции в сети на следующий день. Критической RCE-уязвимостью с нулевой интеракцией также отметился фреймворк PyTorch. Нулевой день на обход MotW исправили в WinRAR; аналогичная уязвимость остаётся без патча в WinZip. В ПО для передачи файлов CrushFTP закрыли критическую CVE на обход аутентификации. Уязвимость под RCE также пропатчили в Gladinet CentreStack. И наконец, нулевым днём под произвольный код отметились и ОС от Apple — причём через обработку аудипотока. Об этом и других интересных CVE апреля читайте под катом!

habr.com/ru/companies/tomhunte

#cve #vulnerability #vulnerability_assessment #vulnerabilities #vulnerability_scanning #уязвимости

knoppixknoppix95
2025-04-29

Researchers have revealed that defenses against "juice jacking" on and can be easily bypassed.

Malicious chargers exploit to steal .

The new "ChoiceJacking" technique allows attackers to user consent and access sensitive files.

Avoid using public charging USB ports to your data.

arstechnica.com/security/2025/

2025-04-29

🔐 The Evolution of CVEs: From Humble Beginnings to Record-Breaking Growth 🔐

Since 1999, the Common Vulnerabilities and Exposures (CVE) system has transformed how the cybersecurity community identifies, tracks, and responds to software vulnerabilities. What started as a small, standardized list of just over 300 vulnerabilities has exploded into a global, indispensable resource with nearly 40,000 CVEs logged in 2024 alone - a staggering 38% increase from the previous year!

In my latest article, I explore the fascinating journey of CVEs through three pivotal eras:

1️⃣ The Formative Years (1999–mid-2000s): Establishing a common language for vulnerability identification.

2️⃣ The Expansion and Integration Years (2005–2016): Building robust infrastructure, standardizing severity scoring, and integrating CVEs into enterprise security workflows.

3️⃣ The Acceleration Era (2016–Present): A surge driven by automation, open-source growth, and expanded reporting authorities, leading to unprecedented annual CVE volumes.

Looking ahead, 2025 is forecasted to break new records with an estimated 49,000 CVEs-a 22.5% jump over 2024. This relentless growth underscores the increasing complexity of software ecosystems and the critical need for proactive vulnerability management.

If you want to understand how the CVE system evolved and why staying ahead of this expanding threat landscape matters more than ever, check out the full article here: ciso.pm/the-history-of-cves/

#Cybersecurity #Vulnerabilities #CVE #InfoSec #RiskManagement #SecurityTrends #CyberRisk

A massive amount of CVEs rated 9.8 flying about
knoppixknoppix95
2025-04-28

has partially resumed operations after a significant that exposed and led to a nearly two-week .

The site attributes its struggles to financial constraints and pressure from advertisers, which have limited its ability to maintain .

4chan's team remains defiant, emphasizing the site's unique role in online culture.

techcrunch.com/2025/04/27/4cha

2025-04-26

Seven new GNAs have been registered on GCVE.EU !

We're glad to see the community grow and are open to new GNA applications

🔗 JSON gcve.eu/dist/gcve.json
🔗 Why and How to become a GNA gcve.eu/about/#eligibility-and

#cve #gcve #vulnerabilities #cybersecurity

Xavier «X» Santolaria :verified_paw: :donor:0x58@infosec.exchange
2025-04-26

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #17/2025 is out!

It includes the following and much more:

🇺🇸 👋🏻 Two top officials from #CISA resigned;

🇺🇸 💬 U.S. Defense Secretary Pete Hegseth caught in another information leak;

📊 Yearly Threat Intelligence Reports Released;

🇺🇸 💸 U.S. lost record $16.6 billion to #cybercrime in 2024;

🇺🇸 5.5 Million Patients Affected by #DataBreach at Yale New Haven Health;

🐛 💥 VulnCheck spotted 159 actively exploited #vulnerabilities in first few months of 2025;

🇺🇸 🇨🇳 FBI is seeking public help to identify Chinese hackers known as #SaltTyphoon and offers $10 million reward;

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

2025-04-25

A Python client for the Global CVE Allocation System has been released.

by @cedric

#cve #gcve #vulnerabilities #vulnerability

🔗 github.com/gcve-eu/gcve

2025-04-25

The first publication of the GCVE-BCP-01 - Signature Verification of the Directory File

🔗 More information about BCP gcve.eu/bcp/
🔗 GCVE-BCP-01 gcve.eu/bcp/gcve-bcp-01/

#cve #vulnerabilities #cybersecurity #vulnerability #gcve

MrsNo1SpecialMrsNo1Special
2025-04-24

We talk a lot about technical vulnerabilities in cybersecurity — but what about emotional vulnerabilities? What happens when users don’t feel smart enough, tech-savvy enough, or confident enough to even try? Welcome to the overlooked world of digital impostor syndrome. It’s not just a...

medium.com/@mrsno1special/digi

#

2025-04-24

The digital signature of the directory file was added in response to requests from various open-source developers and GNAs.

#cve #gcve #vulnerabilities #opensource

🔗 FAQ gcve.eu/faq/#q13-is-the-json-f
🔗 Directory file gcve.eu/dist/

2025-04-23

NEW - 🍇💾📥

Fedora Kernel spottet in the wild 🏞️

Version: 6.14.3
Repo: updates-testing

How To Install:
### sudo dnf update --enablerepo=*updates-testing kernel* ###

because sometimes testing kernels aren't flagged as security updates.

🦜
🐻
Supercharging your fedora experience.

codeberg.org/divested/brace

#divested #DivestedComputingGroup

#DCG

#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus #hackernews
#opensource #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #foss #freeyourmind #thematrix #linuxkernel
#kernel #update #systemd #windows #ubuntu #efi #dkms #sysadmin #omemo #banana #fyi #asap #adblocker #ublockorigin #haskell #python #golang #javascript #llm

2025-04-23

New Research Alert: Attackers are exploiting a dangerous class of cyber flaws—resurgent vulnerabilities. Learn how they work, why they matter, and what defenders can do. Full analysis ⬇️
#Cybersecurity #GreyNoise #Vulnerabilities

greynoise.io/blog/greynoise-un

2025-04-23

In this year’s DBIR, vulnerabilities in Virtual Private Networks (VPNs) and edge devices were particular areas of concern, accounting for 22% of the CVE-related breaches in this year’s report, almost eight times the amount of 3% found in the 2024 report.

tenable.com/209928

#dbir #vulnerabilities #vpn #patching #infosec

Alexandre Dulaunoyadulau@infosec.exchange
2025-04-23

While digging into some #Fortinet vulnerabilities, I discovered a set of CVEs that were rejected for being unused.

I'm wondering how this is actually helping vulnerability management. Does this mean those will be never used? or something else?

#vulnerability #cve #vulnerabilities

🔗 vulnerability.circl.lu/vuln/cv

Rejected for Fortinet - "not used"Rejection because unused?

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst