Latest CyberSec News by @thecyberpicker

Latest CyberSec News by @thecyberpicker

29752 bookmarks
Custom sorting
SugarCRM 14.0.0 - SSRF/Code Injection
SugarCRM 14.0.0 - SSRF/Code Injection
SugarCRM 14.0.0 - SSRF/Code Injection. CVE-2024-58258 . webapps exploit for Multiple platform
·exploit-db.com·
SugarCRM 14.0.0 - SSRF/Code Injection
MikroTik RouterOS 7.19.1 - Reflected XSS
MikroTik RouterOS 7.19.1 - Reflected XSS
MikroTik RouterOS 7.19.1 - Reflected XSS. CVE-2025-6563 . remote exploit for Multiple platform
·exploit-db.com·
MikroTik RouterOS 7.19.1 - Reflected XSS
TOTOLINK N300RB 8.54 - Command Execution
TOTOLINK N300RB 8.54 - Command Execution
TOTOLINK N300RB 8.54 - Command Execution. CVE-2025-52089 . hardware exploit for Multiple platform
·exploit-db.com·
TOTOLINK N300RB 8.54 - Command Execution
Langflow 1.2.x - Remote Code Execution (RCE)
Langflow 1.2.x - Remote Code Execution (RCE)
Langflow 1.2.x - Remote Code Execution (RCE). CVE-2025-3248 . webapps exploit for Multiple platform
·exploit-db.com·
Langflow 1.2.x - Remote Code Execution (RCE)
Keras 2.15 - Remote Code Execution (RCE)
Keras 2.15 - Remote Code Execution (RCE)
Keras 2.15 - Remote Code Execution (RCE). CVE-2025-1550 . remote exploit for Python platform
·exploit-db.com·
Keras 2.15 - Remote Code Execution (RCE)
Google AI "Big Sleep" Stops Exploitation of Critical SQLite Vulnerability Before Hackers Act
Google AI "Big Sleep" Stops Exploitation of Critical SQLite Vulnerability Before Hackers Act
Google AI "Big Sleep" Stops Exploitation of Critical SQLite Vulnerability Before Hackers Act | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.
·thehackernews.com·
Google AI "Big Sleep" Stops Exploitation of Critical SQLite Vulnerability Before Hackers Act
Microsoft Fixed 130+ Flaws With July Patch Tuesday
Microsoft Fixed 130+ Flaws With July Patch Tuesday
with July 2025 Patch Tuesday, Microsoft fixed 137 different vulnerabilities, including 14 critical issues and an actively exploited zero-day.
·latesthackingnews.com·
Microsoft Fixed 130+ Flaws With July Patch Tuesday
Abacus dark web drug market goes offline in suspected exit scam
Abacus dark web drug market goes offline in suspected exit scam
Abacus Market, the largest Western darknet marketplace supporting Bitcoin payments, has shut down its public infrastructure in a move suspected to be an exit scam.
·bleepingcomputer.com·
Abacus dark web drug market goes offline in suspected exit scam
OpenAI's image model gets built-in style feature on ChatGPT
OpenAI's image model gets built-in style feature on ChatGPT
OpenAI's image gen model, which is available via ChatGPT for free, now lets you easily create AI images even if you're not familiar with trends or prompt engineering.
·bleepingcomputer.com·
OpenAI's image model gets built-in style feature on ChatGPT
AsyncRAT seeds family of more than 30 remote access trojans | CyberScoop
AsyncRAT seeds family of more than 30 remote access trojans | CyberScoop
ESET researchers observed tens of thousands of machines infected with AsyncRAT and its variants over the past year. The open-source malware is a popular tool among cybercriminals.
·cyberscoop.com·
AsyncRAT seeds family of more than 30 remote access trojans | CyberScoop
Waltz brushes off SignalGate questions, points finger at CISA | CyberScoop
Waltz brushes off SignalGate questions, points finger at CISA | CyberScoop
In congressional testimony, President Trump’s former national security adviser said his use of Signal to coordinate military operations was “driven by” cybersecurity guidance from CISA.
·cyberscoop.com·
Waltz brushes off SignalGate questions, points finger at CISA | CyberScoop
Google says ‘Big Sleep’ AI tool found bug hackers planned to use
Google says ‘Big Sleep’ AI tool found bug hackers planned to use
On Tuesday, Google said Big Sleep managed to discover CVE-2025-6965 — a critical security flaw that Google said was “only known to threat actors and was at risk of being exploited.”
·therecord.media·
Google says ‘Big Sleep’ AI tool found bug hackers planned to use
Windows KB5064489 emergency update fixes Azure VM launch issues
Windows KB5064489 emergency update fixes Azure VM launch issues
Microsoft has released an emergency update to fix a bug that prevents Azure virtual machines from launching when the Trusted Launch setting is disabled and Virtualization-Based Security (VBS) is enabled.
·bleepingcomputer.com·
Windows KB5064489 emergency update fixes Azure VM launch issues
North Korean XORIndex malware hidden in 67 malicious npm packages
North Korean XORIndex malware hidden in 67 malicious npm packages
North Korean threat actors planted 67 malicious packages in the Node Package Manager (npm) online repository to deliver a new malware loader called XORIndex to developer systems.
·bleepingcomputer.com·
North Korean XORIndex malware hidden in 67 malicious npm packages
Police disrupt “Diskstation” ransomware gang attacking NAS devices
Police disrupt “Diskstation” ransomware gang attacking NAS devices
An international law enforcement action dismantled a Romanian ransomware gang known as 'Diskstation,' which encrypted the systems of several companies in the Lombardy region, paralyzing their businesses.
·bleepingcomputer.com·
Police disrupt “Diskstation” ransomware gang attacking NAS devices
Vol, IA, scandale, rétropédalage : à quoi joue Wetransfer avec nos fichiers ?
Vol, IA, scandale, rétropédalage : à quoi joue Wetransfer avec nos fichiers ?
Le 15 juillet 2025, de nombreux utilisateurs de WeTransfer se sont inquiétés d’une nouvelle clause dans les conditions générales d’utilisation (CGU) du service. Censée entrer en vigueur le 8 août 2025, la clause 6.3 semblait accorder à WeTransfer des droits très larges sur les fichiers transférés, notamment leur
·numerama.com·
Vol, IA, scandale, rétropédalage : à quoi joue Wetransfer avec nos fichiers ?
MITRE Launches New Framework to Tackle Crypto Risks
MITRE Launches New Framework to Tackle Crypto Risks
MITRE has introduced AADAPT framework, a new cybersecurity framework aimed at mitigating risks in digital financial systems like cryptocurrency
·infosecurity-magazine.com·
MITRE Launches New Framework to Tackle Crypto Risks