Aggregator
国内最专业、最全面的 [ .NET 代码审计 ] 体系化学习交流社区
2 months 3 weeks ago
01.NET漏洞背景微软的.NET技术广泛应用于全球企业级产品,包括其知名的Exchange、SharePoi
绕过 WebShell 检测的新思路,通过 Sharp4Error 运行时报错执行命令
2 months 3 weeks ago
AI安全助手重塑SOC运作方式
2 months 3 weeks ago
随着微软六个新的AI安全副驾驶的推出,越来越多人意识到AI安全助手在安全运营中心(SOC)的价值。这些工具正在 […]
aqniu
小红书被曝高频获取用户信息,官方回应;Google Chrome零日漏洞已被在野利用,无需用户交互即可绕过沙盒保护 | 牛览
2 months 3 weeks ago
新闻速览 •小红书被曝高频获取用户信息,官方回应 •冒充客服窃取2.43亿美元,加密货币盗窃案主犯Wiz落网 […]
aqniu
CVE-2024-26297 | HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0 Web-based Management Interface improper authentication (ARUBA-PSA-2024-001)
2 months 3 weeks ago
A vulnerability, which was classified as critical, was found in HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0. This affects an unknown part of the component Web-based Management Interface. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2024-26297. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26298 | HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0 Web-based Management Interface improper authentication (ARUBA-PSA-2024-001)
2 months 3 weeks ago
A vulnerability has been found in HPE Aruba ClearPass Policy Manager up to 6.9.13/6.10.8/6.11.6/6.12.0 and classified as critical. This vulnerability affects unknown code of the component Web-based Management Interface. The manipulation leads to improper authentication.
This vulnerability was named CVE-2024-26298. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24150 | libming 0.4.8 SWF File parseSWF_TEXTRECORD memory leak (Issue 309)
2 months 3 weeks ago
A vulnerability was found in libming 0.4.8. It has been declared as problematic. This vulnerability affects the function parseSWF_TEXTRECORD of the component SWF File Handler. The manipulation leads to memory leak.
This vulnerability was named CVE-2024-24150. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-24146 | libming 0.4.8 SWF File parseSWF_DEFINEBUTTON memory leak (Issue 307)
2 months 3 weeks ago
A vulnerability classified as problematic has been found in libming 0.4.8. Affected is the function parseSWF_DEFINEBUTTON of the component SWF File Handler. The manipulation leads to memory leak.
This vulnerability is traded as CVE-2024-24146. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-25291 | Deskfiler 1.2.3 Plugin unrestricted upload
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Deskfiler 1.2.3. Affected is an unknown function of the component Plugin Handler. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-25291. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-25063 | Hikvision HikCentral Professional up to 2.5.0 URL access control
2 months 3 weeks ago
A vulnerability was found in Hikvision HikCentral Professional up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component URL Handler. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-25063. The attack may be launched remotely. There is no exploit available.
vuldb.com
Qilin
2 months 3 weeks ago
cohenido
Island Raises $250M to Replace SASE With Enterprise Browser
2 months 3 weeks ago
Startup Hits $4.8B Valuation After Series E as It Disrupts VDI, Web Filtering Tools
Island’s enterprise browser platform is gaining traction as a replacement for SASE and legacy VDI and web filtering tools. Backed by $250 million in Series E funding, the startup plans to scale up globally and enhance R&D to support secure, simplified digital work environments.
Island’s enterprise browser platform is gaining traction as a replacement for SASE and legacy VDI and web filtering tools. Backed by $250 million in Series E funding, the startup plans to scale up globally and enhance R&D to support secure, simplified digital work environments.
OpenAI's New Security Plan Rewards 'Critical' Bug Discovery
2 months 3 weeks ago
Max Payout for Bug Bounty Program Up From $20,000 to $100,000
OpenAI announced a cybersecurity initiative that aims to improve the resilience of its artificial intelligence systems by rewarding the discovery of critical vulnerabilities and improving threat mitigation. OpenAI raised the maximum payout for its bug bounty program from $20,000 to $100,000.
OpenAI announced a cybersecurity initiative that aims to improve the resilience of its artificial intelligence systems by rewarding the discovery of critical vulnerabilities and improving threat mitigation. OpenAI raised the maximum payout for its bug bounty program from $20,000 to $100,000.
CISA Budget Cuts Weaken US Election Security, Officials Warn
2 months 3 weeks ago
State and Local Election Offices Face Growing Cyber Threat Amid Federal Budget Cuts
Top-ranking current and former security officials warned Thursday that President Donald Trump's budget cuts to the Cybersecurity and Infrastructure Security Agency and other election security efforts have left U.S. election infrastructure vulnerable to escalating cyber threats.
Top-ranking current and former security officials warned Thursday that President Donald Trump's budget cuts to the Cybersecurity and Infrastructure Security Agency and other election security efforts have left U.S. election infrastructure vulnerable to escalating cyber threats.
Legacy IT Systems Could Jeopardize UK AI Plans
2 months 3 weeks ago
Outdated Systems Putting AI Adoption in the Public Sector at Risk, Report Says
Outdated IT systems and poor data-sharing practices between public offices could undermine the U.K. government's plans to deploy artificial intelligence capabilities to increase public sector efficiencies, a parliamentary committee said.
Outdated IT systems and poor data-sharing practices between public offices could undermine the U.K. government's plans to deploy artificial intelligence capabilities to increase public sector efficiencies, a parliamentary committee said.
Island Raises $250M to Replace SASE With Enterprise Browser
2 months 3 weeks ago
Startup Hits $4.8B Valuation After Series E as It Disrupts VDI, Web Filtering Tools
Island's enterprise browser platform is gaining traction as a replacement for SASE and legacy VDI and web filtering tools. Backed by $250 million in Series E funding, the startup plans to scale up globally and enhance R&D to support secure, simplified digital work environments.
Island's enterprise browser platform is gaining traction as a replacement for SASE and legacy VDI and web filtering tools. Backed by $250 million in Series E funding, the startup plans to scale up globally and enhance R&D to support secure, simplified digital work environments.
OpenAI's New Security Plan Rewards 'Critical' Bug Discovery
2 months 3 weeks ago
Max Payout for Bug Bounty Program Up From $20,000 to $100,000
OpenAI announced a cybersecurity initiative that aims to improve the resilience of its artificial intelligence systems by rewarding the discovery of critical vulnerabilities and improving threat mitigation. OpenAI raised the maximum payout for its bug bounty program from $20,000 to $100,000.
OpenAI announced a cybersecurity initiative that aims to improve the resilience of its artificial intelligence systems by rewarding the discovery of critical vulnerabilities and improving threat mitigation. OpenAI raised the maximum payout for its bug bounty program from $20,000 to $100,000.
CISA Budget Cuts Weaken US Election Security, Officials Warn
2 months 3 weeks ago
State and Local Election Offices Face Growing Cyber Threat Amid Federal Budget Cuts
Top-ranking current and former security officials warned Thursday that President Donald Trump's budget cuts to the Cybersecurity and Infrastructure Security Agency and other election security efforts have left U.S. election infrastructure vulnerable to escalating cyber threats.
Top-ranking current and former security officials warned Thursday that President Donald Trump's budget cuts to the Cybersecurity and Infrastructure Security Agency and other election security efforts have left U.S. election infrastructure vulnerable to escalating cyber threats.
Legacy IT Systems Could Jeopardize UK AI Plans
2 months 3 weeks ago
Outdated Systems Putting AI Adoption in the Public Sector at Risk, Report Says
Outdated IT systems and poor data-sharing practices between public offices could undermine the U.K. government's plans to deploy artificial intelligence capabilities to increase public sector efficiencies, a parliamentary committee said.
Outdated IT systems and poor data-sharing practices between public offices could undermine the U.K. government's plans to deploy artificial intelligence capabilities to increase public sector efficiencies, a parliamentary committee said.