Aggregator
CVE-2024-1822 | PHPGurukul Tourism Management System 1.0 user-bookings.php Full Name cross site scripting
CVE-2023-37540 | HCL Sametime Chat up to 12.0.1 FP1 Secure Storage information disclosure (KB0109082)
Why I Joined Grip Security in Securing the Digital Future
Join Grip Security on its mission to redefine identity security. Discover how innovation, empathy, and culture are shaping the future of digital protection.
The post Why I Joined Grip Security in Securing the Digital Future appeared first on Security Boulevard.
Тест Тьюринга пройден. А дальше что? Чемпионы ИИ предлагают научить роботов жить, а не притворяться
OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits
Seeking Post-Mitre Management: What's Next for CVE Program?
This week's near-disruption in funding for the Mitre-administered Common Vulnerabilities and Exposures Program shows that the U.S. government no longer wants to be footing the tab. Many experts say this is an opportunity to redesign the CVE Program to be more neutral, sustainable and international.
Breakthroughs, Concerns in OpenAI's Latest Lineup
OpenAI's mid-April announcements include its most advanced reasoning models o3 and o4-mini, with a biorisk monitor, the quietly released GPT-4.1 coding family and the upcoming retirement of its costliest model, GPT-4.5. OpenAI's partners warn that the company's rushed evaluations have left gaps.
Microsoft's New Model Aims to Do More With Less
Microsoft released what it describes as the most expansive 1-bit AI model to date, BitNet b1.58 2B4T. Unlike traditional large language models that depend on GPUs and massive infrastructure, the model is built to operate efficiently on CPUs including Apple's M2 chip.
Microsoft 安全升级:Office 365 和 Office 2024 全面禁用 ActiveX 控件
CVE-2022-20536 | Google Android 13.0 RcsService.java registerBroadcastReceiver permission (A-235100180)
CVE-2022-20515 | Google Android 13.0 AccountTypePreferenceLoader.java onPreferenceClick information disclosure (A-220733496)
CVE-2022-20535 | Google Android 13.0 WifiManager.java registerLocalOnlyHotspotSoftApCallback information exposure (A-233605242)
CVE-2022-20538 | Google Android 13.0 RoleService.java getSmsRoleHolder information disclosure (A-235601770)
Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN
A server briefly linked to the notorious KeyPlug malware has inadvertently exposed a comprehensive arsenal of exploitation tools specifically designed to target Fortinet firewall and VPN appliances. The infrastructure, which security researchers have attributed to the RedGolf threat group (overlapping with APT41), was accessible for less than 24 hours before being secured, providing a rare […]
The post Leaked KeyPlug Malware Infrastructure Contains Exploit Scripts to Hack Fortinet Firewall and VPN appeared first on Cyber Security News.
FBI: Scammers pose as FBI IC3 employees to 'help' recover lost funds
ASUS AiCloud Vulnerability (CVE-2025-2492) Enables Remote Function Execution via Authentication Bypass
Мотивированное решение за сутки: как теперь блокируют зеркала
ASUS warns of critical auth bypass flaw in routers using AiCloud
5 reasons to not miss Sonatype at RSAC 2025
RSA Conference (RSAC) brings together cybersecurity practitioners from across the globe to learn about the latest cybersecurity defense strategies and tools, connect with industry peers, and share knowledge about the threat landscape.
The post 5 reasons to not miss Sonatype at RSAC 2025 appeared first on Security Boulevard.