CVE-2025-32931 - DevDojo Voyager Command Injection Vulnerability April 14, 2025 at 04:15PM https://ift.tt/LQiAvGF #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon

CVE-2025-32931 - DevDojo Voyager Command Injection Vulnerability April 14, 2025 at 04:15PM https://ift.tt/LQiAvGF #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon
If the compromised package "worked" to the extent that it did what it said it does until someone asks it to do something different, it could conceivably migrate into non adversary controlled repositories and from there into the greater network.
So crazy talk or CVE? Hard to tell the difference these days.
#infosec #cve
3/3
Huntress Documents In-The-Wild Exploitation of Critical Gladinet Vulnerabilities – Source: www.securityweek.com https://ciso2ciso.com/huntress-documents-in-the-wild-exploitation-of-critical-gladinet-vulnerabilities-source-www-securityweek-com/ #rssfeedpostgeneratorecho #SupplyChainSecurity #CyberSecurityNews #Malware&Threats #securityweekcom #CVE-2025-30406 #securityweek #0CISO2CISO #CrushFTP #Gladinet #Triofox
Trend Micro Flags Incomplete Nvidia Patch That Leaves AI Containers Exposed – Source: www.securityweek.com https://ciso2ciso.com/trend-micro-flags-incomplete-nvidia-patch-that-leaves-ai-containers-exposed-source-www-securityweek-com/ #rssfeedpostgeneratorecho #ArtificialIntelligence #CyberSecurityNews #containerescape #vulnerabilities #securityweekcom #CVE-2024-0132 #securityweek #TrendMicro #NVIDIA
Threat Actor Allegedly Selling Fortinet Firewall Zero-Day Exploit – Source: www.securityweek.com https://ciso2ciso.com/threat-actor-allegedly-selling-fortinet-firewall-zero-day-exploit-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Malware&Threats #vulnerabilities #securityweekcom #CVE-2022-42475 #CVE-2023-27997 #CVE-2024-21762 #securityweek #ThreatMon #FEATURED #Fortinet #FortiOS
This potential exploit came up in conversation this weekend.
Theoretically, one way to weaponize slopsquatting, which is to create many (number to be determined) repositories on Github that use a loadable package that promises one thing but has a back door in it to enable an adversary to take control. #infosec #cve
1/3
CVE-2025-2160 - Pega Platform Cross-Site Scripting Vulnerability April 14, 2025 at 03:15PM https://ift.tt/RFn9eim #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon
CVE-2025-2563 - "WordPress User Registration & Membership Privilege Escalation Vulnerability" April 14, 2025 at 06:15AM https://ift.tt/fZHPrbW #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon
IBM Aspera Faspex Flaw Allows Injection of Malicious JavaScript in Web UI https://gbhackers.com/ibm-aspera-faspex-flaw/ #CVE/vulnerability #CyberSecurityNews #Vulnerability #cybersecurity
Chinese APT Group Targets Ivanti VPN Vulnerabilities to Breach Networks https://gbhackers.com/chinese-apt-group-targets-ivanti-vpn-vulnerabilities/ #CVE/vulnerability #CyberSecurityNews #Vulnerability #cybersecurity
I had a chat with Aaron Frost from HeroDevs about #EOL and #CVE. It's a surprisingly complicated topic
If you're unsure an old version is affected, should you assume it is or isn't affected by a vulnerability?
https://opensourcesecurity.io/2025/2025-04-cve_eol_aaron_frost/
"APT그룹 추적 보고서 - Larva-24005" published by Ahnlab. #CVE-2019-0708, #Larva-24005, #RandomQuery, #DPRK, #CTI https://asec.ahnlab.com/ko/87453/
CVE-2025-3546 - H3C Magic NX15/Business Ethernet Switch HTTP Command Injection Vulnerability April 14, 2025 at 02:15AM https://ift.tt/58ovOkw #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon
CVE-2025-3545 - H3C Magic NX Series HTTP POST Request Handler Command Injection Vulnerability April 14, 2025 at 02:15AM https://ift.tt/9jgK3wk #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon
CVE-2025-3544 - H3C Magic NX15/30 Pro/400/BE18000 HTTP POST Request Handler Command Injection April 14, 2025 at 01:15AM https://ift.tt/cDj8NkG #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon
CVE-2025-3543 - H3C Magic NX Series HTTP POST Request Handler Command Injection Vulnerability April 14, 2025 at 01:15AM https://ift.tt/qO42XYk #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon
CVE-2025-3542 - H3C Magic NX15, Magic NX400 and Magic R3010 Command Injection Vulnerability April 14, 2025 at 12:15AM https://ift.tt/pV0BhjK #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon
CVE-2025-3541 - H3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 Command Injection Vulnerability April 13, 2025 at 11:15PM https://ift.tt/ZtRJiy0 #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon
CVE-2025-3540 - H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 Command Injection Vulnerability April 13, 2025 at 11:15PM https://ift.tt/MLxV4a5 #CVE #IOC #CTI #ThreatIntelligence #ThreatIntel #Cybersecurity #Recon