ERPNext 14.82.1 – Account Takeover via Cross-Site Request Forgery (CSRF)

# Exploit Title: ERPNext 14.82.1 – Account Takeover via Cross-Site Request Forgery (CSRF) # Google Dork: inurl:”/api/method/frappe” # Date: 2025-04-29 # Exploit Author: Ahmed Thaiban (Thvt0ne) # Vendor Homepage: https://erpnext.com # Software Link: https://github.com/frappe/erpnext # Version: <= 14.82.1, 14.74.3 (Tested) # Tested on: Linux (Ubuntu 20.04), Chrome, Firefox. # CVE : CVE-2025-28062 # Category: WebApps …

Read More

Quantum batteries could make quantum computers more efficient

Quantum batteries have theoretically exciting properties da-kuk/Getty Images Hooking up a quantum computer to a quantum battery could make it much more energy-efficient and enable machines to pack more processing power into the same physical space. Quantum batteries, like regular batteries, can store energy to provide power, but rather than using electrochemical reactions, they are…

Read More

Sustained in the brain: How lasting emotions arise from brief stimuli, in humans and mice

We don’t always understand our emotions, but we couldn’t lead normal lives without them. They steer us through life, guiding the decisions we make and the actions we take. But if they’re inappropriate or stick around for too long, they can cause trouble. Neuroscientists and psychiatrists, despite their best efforts, don’t understand nearly enough about…

Read More

Victoria’s Secret reports better-than-expected sales, narrows earnings loss

Victoria’s Secret & Co. on Wednesday reported better-than-expected sales in the first quarter, helping the U.S. lingerie giant to narrow earnings losses for the three-month period. Victoria’s Secret The Ohio-based company said sales for the three months ending May 3 totalled $1.353 billion, ​besting its previously communicated guidance range of $1.30 billion to $1.33 billion. …

Read More

[Guest Diary] Anatomy of a Linux SSH Honeypot Attack: Detailed Analysis of Captured Malware

[This is a Guest Diary by Michal Ambrozkiewicz, an ISC intern as part of the SANS.edu Bachelor’s Degree in Applied Cybersecurity (BACS) program [1].] On April 29, 2025, my Raspberry Pi-based Cowrie SSH honeypot captured a sophisticated attack campaign targeting Linux systems. This wasn’t just another automated scanner – the logs reveal a multi-stage attack…

Read More

Please Stop Asking Chatbots for Love Advice

As he sat down across from me, my patient had a rueful expression on his face. “I had a date,” he announced. “It didn’t go well.” That wasn’t unusual for this patient. For years, he’d shared tales of romantic hopes dashed. But before I could ask him what went wrong, he continued, “So I asked…

Read More

Anthropologists spotlight human toll of glacier loss

In an important contribution from the social sciences, Rice University anthropologists Cymene Howe and Dominic Boyer examine the societal consequences of global glacier loss in a commentary published today in Science. Their article appears alongside new research that estimates that more than three-quarters of the world’s glacier mass could disappear by the end of the…

Read More