Aggregator
研究人员称,柬埔寨诈骗巨头自 2021 年以来处理了 490 亿美元的加密货币交易
CVE-2004-0676 | Fastream NETFile FTP/Web Server up to 6.7.2.1085 filename path traversal (EDB-24252 / XFDB-16613)
网络安全知识手册正式发布
恶意软件利用零日漏洞感染报废的AVTECH IP 摄像机
CVE-2007-1982 | Really Simple PHP/Ajax file inclusion (EDB-3641 / XFDB-33356)
A third of organizations suffered a SaaS data breach this year
While SaaS security is finally getting the attention it deserves, there’s still a significant gap between intent and implementation. Ad hoc strategies and other practices still fall short of a security program. The move toward decentralization has generated confusion over responsibilities, and many organizations remain unaware of which SaaS applications are used, by whom, and what is risky, according to AppOmni. Source: AppOmni “Despite greater awareness and effort, things are getting worse. Just as there … More →
The post A third of organizations suffered a SaaS data breach this year appeared first on Help Net Security.
魔形女再袭?最新 Android 通杀漏洞 CVE-2024-31317 分析与利用研究
CVE-2007-1851 | Really Simple PHP/Ajax 2007-03-23 controller_v4.php __class path traversal (EDB-3641 / XFDB-33357)
因与媒体共享勒索事件实情,美国一研究人员被政府起诉
微软观察到伊朗 APT 组织使用 Tickler 恶意软件攻击卫星设备
CVE-2007-6597 | IPortalX Beta 1 forum/login_user.asp Date cross site scripting (EDB-30940 / XFDB-39249)
CVE-2007-1978 | Php Fusion Arcade Module 1.00 index.php cid sql injection (EDB-3640 / XFDB-33361)
【中秋众测】TSRC新活动重磅来袭,诚邀您的参与!
Transport for London discloses ongoing “cyber security incident”
CVE-2019-7257 | Nortek Linear eMerge E3 File Upload unrestricted upload (ID 155254 / EDB-47622)
お知らせ:インシデント対応状況(日次)公開終了のお知らせ
Admins of MFA bypass service plead guilty to fraud
Leadership Lessons from the First 100 Episodes of CISO Stories - Todd Fitzgerald - BSW Vault
最终议程 | EISS-2024企业信息安全峰会之深圳站(09.20/周五)
EISS企业安全峰会始办于2016年,在上海、北京、深圳等地已成功举办20届。EISS由安世加主办,并得到众多行业协会、机构以及媒体等共同参与支持,已成为国内具备广泛影响力的行业安全盛会。大会以“直面信息安全挑战,创造最佳实践”为主题,聚焦企业信息安全技术与实践等热点话题,致力于推进企业信息安全体系建设,加强企业信息安全管理,助推企业信息安全生态圈的健康发展。EISS-2024企业信息安全峰会之深圳站将于2024年09月20日举行,本次是EISS系列峰会第21届,届时约有300+来自全国各地的企业CS0、安全专家出席,共同探讨企业信息安全现状与未来。