Aggregator
CVE-2022-41601 | Huawei HarmonyOS Fingerprint Trusted Application heap-based overflow
CVE-2022-42234 | UCMS 1.6 Template Management Module file inclusion
CVE-2017-20149 | MikroTik RouterOS up to 6.37.4/6.38.4 Web Server memory corruption
Google 开发 Android 桌面模式
Google strengthens secure enterprise access from BYOD Android devices
Google has introduced Device Trust from Android Enterprise, a new solution for making sure that private Android devices used for work are secure enough to access corporate resources and data. Device Trust from Android Enterprise (Source: Google) What is Device Trust from Android Enterprise? Android Enterprise is a set of tools and APIs from Google that helps businesses securely manage Android phones and tablets used by employees for work. Key features allow: Management of work … More →
The post Google strengthens secure enterprise access from BYOD Android devices appeared first on Help Net Security.
WEB前端逆向在nodejs环境中复用webpack代码
Pwn2Own Berlin: The Full Schedule
Willkommen and welcome to the inuaguaral Pwn2Own Berlin! Not only is this our first time at the OffensiveCon conference, but it’s also our first time including an AI category in the event. We’ve assembled some of the finest security researchers in the world to test the security of these systems, and we can’t wait to see what happens. We had our random drawing for the order of events earlier today, and from that, we have put together the following schedule. Please note that all times are local to Berlin and may change at any point.
Jump to: Day One Day Two Day Three
Day One
Thursday, May 15 – 1030
Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) targeting NVIDIA Triton Inference Server in the AI category for $30000 and 3 Master of Pwn Points.
Thursday, May 15 – 1100
Pumpkin (@u1f383) from DEVCORE Research Team targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for $20000 and 2 Master of Pwn Points.
Thursday, May 15 – 1130
Chen Le Qi (@cplearns2h4ck) of STARLabs SG targeting Microsoft Windows 11 in the Local Escalation of Privilege category for $30000 and 3 Master of Pwn Points.
Thursday, May 15 – 1230
Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) targeting Chroma in the AI category for $20000 and 2 Master of Pwn Points.
Thursday, May 15 – 1300
Hyunwoo Kim (@V4bel) and Wongi Lee (@_qwerty_po) of Theori targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for $20000 and 2 Master of Pwn Points.
Ronen Shustin (@ronenshh) Nir Ohfeld (@nirohfeld) of Wiz Research targeting NVIDIA Triton Inference Server in the AI category for $30000 and 3 Master of Pwn Points.
Thursday, May 15 – 1330
Marcin Wiązowski targeting Microsoft Windows 11 in the Local Escalation of Privilege category for $30000 and 3 Master of Pwn Points.
Thursday, May 15 – 1430
Team Prison Break (Best of the Best 13th) targeting Oracle VirtualBox in the Virtualization category for $40000 and 4 Master of Pwn Points.
Billy(@st424204) and Ramdhan(@n0psledbyte) of STAR Labs targeting Docker Desktop in the Cloud/Container category for $60000 and 6 Master of Pwn Points.
Thursday, May 15 – 1500
Viettel Cyber Security (@vcslab) targeting NVIDIA Triton Inference Server in the AI category for $30000 and 3 Master of Pwn Points.
Thursday, May 15 – 1530
Hyeonjin Choi (@d4m0n_8) of Out Of Bounds targeting Microsoft Windows 11 in the Local Escalation of Privilege category for $30000 and 3 Master of Pwn Points.
Day Two
Friday, May 16 – 1000
Mohand Acherir & Patrick Ventuzelo (@pat_ventuzelo) of FuzzingLabs (@fuzzinglabs) targeting NVIDIA Triton Inference Server in the AI category for $30000 and 3 Master of Pwn Points.
Friday, May 16 – 1030
Dinh Ho Anh Khoa (@_l0gg) of Viettel Cyber Security targeting Microsoft SharePoint in the Server category for $100000 and 10 Master of Pwn Points.
Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG targeting VMware ESXi in the Virtualization category for $150000 and 15 Master of Pwn Points.
Friday, May 16 – 1100
Edouard Bochin (@le_douds) and Tao Yan (@Ga1ois) from Palo Alto Networks targeting Mozilla Firefox - Renderer Only in the Web Browser category for $50000 and 5 Master of Pwn Points.
Friday, May 16 – 1130
Benny Isaacs (@benny_isaacs), Nir Brakha, Sagi Tzadik (@sagitz_) of Wiz Research targeting Redis in the AI category for $40000 and 4 Master of Pwn Points.
Friday, May 16 – 1200
Ho Xuan Ninh (@Xuanninh1412) and Tri Dang (@trichimtrich) from Qrious Secure targeting NVIDIA Triton Inference Server in the AI category for $30000 and 3 Master of Pwn Points.
Friday, May 16 – 1230
Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) targeting Microsoft SharePoint in the Server category for $100000 and 10 Master of Pwn Points.
Friday, May 16 – 1430
Viettel Cyber Security (@vcslab) targeting Oracle VirtualBox in the Virtualization category for $40000 and 4 Master of Pwn Points.
Friday, May 16 – 1500
Gerrard Tai of STAR Labs SG Pte.Ltd. targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for $20000 and 2 Master of Pwn Points.
Friday, May 16 – 1630
Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) targeting Oracle VirtualBox in the Virtualization category for $40000 and 4 Master of Pwn Points.
Day Three
Saturday, May 17 – 1030
Angelboy (@scwuaptx) from DEVCORE Research Team targeting Microsoft Windows 11 in the Local Escalation of Privilege category for $30000 and 3 Master of Pwn Points.
Nir Ohfeld (@nirohfeld) Shir Tamari (@shirtamari) of Wiz Research targeting NVIDIA Container Toolkit in the AI category for $30000 and 3 Master of Pwn Points.
Saturday, May 17 – 1100
@namhb1 @havancuong000 @HieuTra34558978 of FPT NightWolf targeting NVIDIA Triton Inference Server in the AI category for $30000 and 3 Master of Pwn Points.
Saturday, May 17 – 1200
Manfred Paul (@[email protected]) targeting Mozilla Firefox - Renderer Only in the Web Browser category for $50000 and 5 Master of Pwn Points.
Dung and Nguyen (@MochiNishimiya) of STARLabs targeting Oracle VirtualBox with EoP with Windows kernel vulnerability addon in the Virtualization category for $90000 and 9 Master of Pwn Points.
Saturday, May 17 – 1400
Billy(@st4242404) and Bruce(@bruce30262) of STAR Labs targeting NVIDIA Triton Inference Server in the AI category for $30000 and 3 Master of Pwn Points.
Corentin BAYET (@OnlyTheDuck) from @Reverse_Tactics targeting VMware ESXi in the Virtualization category for $150000 and 15 Master of Pwn Points.
Saturday, May 17 – 1600
Thomas Bouzerar (@MajorTomSec) and Etienne Helluy-Lafont from Synacktiv (@Synacktiv) targeting VMware Workstation in the Virtualization category for $80000 and 8 Master of Pwn Points.
Miloš Ivanović (infosec.exchange/@ynwarcs) targeting Microsoft Windows 11 in the Local Escalation of Privilege category for $30000 and 3 Master of Pwn Points.
The Results
We’ll be blogging and tweeting results in real-time throughout the competition. Be sure to keep an eye on the blog for the latest information. We’ll also be posting live results on Twitter, Mastodon, LinkedIn, and Bluesky, so follow us on your favorite social platform for the latest news, and keep an eye on the #P2OBerlin hashtag for continuing coverage.
©2025 Trend Micro Incorporated. All rights reserved. PWN2OWN, ZERO DAY INITIATIVE, ZDI, and Trend Micro are trademarks or registered trademarks of Trend Micro Incorporated. All other trademarks and trade names are the property of their respective owners.
避开 AI 日益困难,但退出的自由必须被保护
Global Powers Intensify Cyber Warfare with Covert Digital Strikes on Critical Systems
The digital frontlines of modern conflict have expanded dramatically in 2025, with state-sponsored hackers from China, Russia, North Korea, and Iran executing sophisticated attacks against energy grids, telecommunications networks, and transportation systems worldwide. These operations, often masked as routine cybercrime, are reshaping national security paradigms while testing the resilience of democracies and allied partnerships. China’s […]
The post Global Powers Intensify Cyber Warfare with Covert Digital Strikes on Critical Systems appeared first on Cyber Security News.
Android Enterprise Launches Device Trust For Enhanced Security
[Control systems] Siemens security advisory (AV25-272)
SecWiki News 2025-05-14 Review
Getting started with Conditional Access: Comparing Entra ID Conditional Access with Okta
CVE-2005-2340 | Apple QuickTime 7.0/7.0.1/7.0.2/7.0.3 GIF Image memory corruption (VU#629845 / Nessus ID 20395)
CVE-2007-6481 | Sun Ray Server Software 3.0 (XFDB-39132 / SBV-25800)
CVE-2009-2673 | Sun JRE/JDK 1.5.0/1.6.0 access control (Nessus ID 43774 / ID 185074)
CVE-2007-5905 | Adobe ColdFusion 7.0/8.0 credentials management (XFDB-38446 / SBV-29676)
As US CVE Database Fumbles, EU ‘Replacement’ Goes Live
Diesen Kuß der ganzen Welt! European Union Vulnerability Database (EUVD) launches this week. And not a moment too soon.
The post As US CVE Database Fumbles, EU ‘Replacement’ Goes Live appeared first on Security Boulevard.