Aggregator
每周勒索威胁摘要
3 months ago
1.Qilin勒索团伙公布了新的受害者
2.Play勒索团伙公布新的受害公司
3.INC Ransom团伙公布新的受害公司
远程控制木马EndClient通过滥用遭泄露的代码签名证书来规避防病毒软件检测
3 months ago
安全客
二进制供应链安全平台Binarly Transparency Platform 3.5发布,新增对Java归档文件与JVM字节码的深度支持
3 months ago
安全客
思科发布警告:黑客正积极在野利用其ASA与FTD防火墙中的零日远程代码执行漏洞
3 months ago
安全客
Django框架中存在多处安全漏洞,可引发SQL注入与拒绝服务攻击
3 months ago
安全客
238支全球顶尖战队上演AI攻防巅峰对决,腾讯云黑客松-智能渗透挑战赛即将开启!
3 months ago
由腾讯云鼎实验室-腾讯安全众测平台发起的「黑客松-智能渗透挑战赛」即将拉开战幕!
CVE-2025-12862 | projectworlds Online Notes Sharing Platform 1.0 userprofile.php image unrestricted upload
3 months ago
A vulnerability, which was classified as critical, was found in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted upload.
This vulnerability is listed as CVE-2025-12862. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2025-12861 | DedeBIZ up to 6.3.2 /admin/spec_add.php flags[] sql injection
3 months ago
A vulnerability, which was classified as critical, has been found in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the file /admin/spec_add.php. This manipulation of the argument flags[] causes sql injection.
This vulnerability is tracked as CVE-2025-12861. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
Submit #679802: projectworlds Online Notes Sharing Platform 1.0 Unrestricted Upload [Accepted]
3 months ago
Submit #679802 / VDB-331509
K1nako
CVE-2025-12860 | DedeBIZ up to 6.3.2 /admin/freelist_main.php orderby sql injection
3 months ago
A vulnerability classified as critical was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. The manipulation of the argument orderby results in sql injection.
This vulnerability is identified as CVE-2025-12860. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-12859 | DedeBIZ up to 6.3.2 templets_one_edit.php ids sql injection
3 months ago
A vulnerability classified as critical has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_edit.php. The manipulation of the argument ids leads to sql injection.
This vulnerability is referenced as CVE-2025-12859. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
活动回顾|慢雾(SlowMist)亮相第十届香港金融科技周 2025
3 months ago
慢雾将继续为构建更安全、更可信的区块链生态而努力!
Submit #679692: DedeBIZ CMS v6.3.2 SQL Injection [Accepted]
3 months ago
Submit #679692 / VDB-331508
ZZCTD
勒索月报 | 360披露10月勒索软件流行态势:AI“养蛊”新变种,防御难度陡增
3 months ago
勒索软件进入“AI驱动”进化新阶段:360报告揭示病毒变种呈现智能化特征
360首席科学家潘剑锋当选世界互联网大会人工智能专委会副主任委员
3 months ago
360作为中国“AI+安全”领军企业,将深度参与全球人工智能治理与产业推进工作。
CVE-2025-46413 | BUFFALO WSR-1800AX4 weak password hash (EUVD-2025-38245)
3 months ago
A vulnerability described as problematic has been identified in BUFFALO WSR-1800AX4, WSR-1800AX4S, WSR-1800AX4B and WSR-1800AX4-KH. This affects an unknown function. Executing manipulation can lead to password hash with insufficient computational effort.
The identification of this vulnerability is CVE-2025-46413. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
Сверхразум — но с поводком. Microsoft создаёт ИИ, которому запрещено думать, меняться и действовать без человека
3 months ago
0 % свободы, 100 % подчинения: как сдержать восстание машин, когда они поумнеют окончательно?
CVE-2025-10870 | DIAL CentrosNet up to 2.64 ultralogin.php ultralogin sql injection
3 months ago
A vulnerability marked as critical has been reported in DIAL CentrosNet up to 2.64. The impacted element is an unknown function of the file /centrosnet/ultralogin.php. Performing manipulation of the argument ultralogin results in sql injection.
This vulnerability was named CVE-2025-10870. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
Submit #679111: DedeBIZ DedeBIZ CMS v6.3.2 SQL Injection [Accepted]
3 months ago
Submit #679111 / VDB-331507
ZZCTD