Aggregator
WordPress Gravity Forms 开发者账号被黑,被用于分发带后门插件
4 months 4 weeks ago
安全客
Cursor IDE被植入恶意 VSCode 插件,导致 50 万美元加密货币被盗
4 months 4 weeks ago
安全客
英国启动漏洞研究计划,邀请外部专家参与网络安全研究
4 months 4 weeks ago
安全客
Trustwave 推出专为 Microsoft 用户打造的钓鱼防护服务
4 months 4 weeks ago
安全客
CVE-2025-43856:热门自托管照片平台 Immich 被披露存在 OAuth2 账户劫持漏洞
4 months 4 weeks ago
安全客
技嘉主板UEFI固件曝严重安全漏洞 攻击者可在SMM环境下执行任意代码
4 months 4 weeks ago
安全客
Interlock勒索软件采用“FileFix”手法投递恶意程序
4 months 4 weeks ago
安全客
PerfektBlue漏洞链曝光:汽车面临蓝牙黑客攻击风险,或致信息娱乐系统遭劫持
4 months 4 weeks ago
安全客
Китай захватил 70% американского неба без единого выстрела
4 months 4 weeks ago
Китайские дроны — новая угроза Пентагону?
Zyxel security advisory (AV25-423)
4 months 4 weeks ago
Canadian Centre for Cyber Security
98% вашей ДНК считались балластом. Теперь туда добрался ИИ от Google. И всё переписал
4 months 4 weeks ago
Добро пожаловать в чёрный ящик генома.
North Korean XORIndex malware hidden in 67 malicious npm packages
4 months 4 weeks ago
North Korean threat actors planted 67 malicious packages in the Node Package Manager (npm) online repository to deliver a new malware loader called XORIndex to developer systems. [...]
Bill Toulas
Attackers Hide JavaScript in SVG Images to Lure Users to Malicious Sites
4 months 4 weeks ago
Beware! SVG images are now being used with obfuscated JavaScript for stealthy redirect attacks via spoofed emails. Get insights from Ontinue's latest research on detection and defence.
Deeba Ahmed
Самые точные часы в истории. Настолько точные, что ставят под вопрос саму секунду
4 months 4 weeks ago
Они приручили алюминий и заставили его считать до 19 знаков после запятой.
Android Malware Konfety evolves with ZIP manipulation and dynamic loading
4 months 4 weeks ago
A new Konfety Android malware variant uses a malformed ZIP and obfuscation to evade detection, posing as fake apps with no real functionality. Zimperium zLabs researchers are tracking a new, sophisticated Konfety Android malware variant that uses an “evil-twin” tactic and duplicate package names to avoid detection. The new Konfety malware variants use malformed ZIP, […]
Pierluigi Paganini
CVE-2024-5822 | gaizhenbiao ChuanhuChatGPT up to 20240410 server-side request forgery
4 months 4 weeks ago
A vulnerability was found in gaizhenbiao ChuanhuChatGPT up to 20240410. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2024-5822. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-53947 | Apache Superset up to 4.0.x sql injection
4 months 4 weeks ago
A vulnerability was found in Apache Superset up to 4.0.x and classified as critical. Affected by this issue is the function query_to_xml_and_xmlschema/table_to_xml/table_to_xml_and_xmlschema. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-53947. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-29869 | Apache Hive up to 4.0.0 permission assignment
4 months 4 weeks ago
A vulnerability classified as problematic was found in Apache Hive up to 4.0.0. This vulnerability affects unknown code. The manipulation leads to incorrect permission assignment.
This vulnerability was named CVE-2024-29869. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-45588 | Fortinet FortiClientMac up to 7.0.10/7.2.3 Configuration File /tmp file inclusion (FG-IR-23-345)
4 months 4 weeks ago
A vulnerability was found in Fortinet FortiClientMac up to 7.0.10/7.2.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tmp of the component Configuration File Handler. The manipulation leads to file inclusion.
This vulnerability is handled as CVE-2023-45588. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com