Aggregator
记GEEKCON2025上海:在没有天花板的地方,让安全向下扎根,向上生长
记GEEKCON2025上海:在没有天花板的地方,让安全向下扎根,向上生长
QNAP警示ASP.NET Core高危漏洞波及NetBak PC备份工具
Your photo could be all AI needs to clone your voice
A photo of someone’s face may be all an attacker needs to create a convincing synthetic voice. A new study from Australia’s national science agency explores this possibility, testing how well deepfake detectors perform against FOICE (Face-to-Voice), an attack attack method that generates speech from photos. Illustration of face to voice deepfake From faces to voices A new technique is changing how voice deepfakes are made. Instead of using text or a voice sample, it … More →
The post Your photo could be all AI needs to clone your voice appeared first on Help Net Security.
Data Leak Outs Hacker Students of Iran's MOIS Training Academy
PhantomRaven Attack Discovered in 126 Malicious npm Packages, Exceeding 86,000 Downloads
The global developer community has been rocked by the emergence of PhantomRaven, a far-reaching campaign involving 126 malicious npm packages with more than 86,000 downloads. Lurking beneath the surface, these packages actively steal npm tokens, GitHub credentials, and CI/CD secrets from unsuspecting developers across the world. Despite their scale and impact, the attackers have leveraged […]
The post PhantomRaven Attack Discovered in 126 Malicious npm Packages, Exceeding 86,000 Downloads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
“地图API后台配置错误”:挖SRC的新玩具?
从文字到语音交互,AI 的下一个爆发点可能是拥有自己的身体
CVE-2023-25266 | Docmosis Tornado up to 2.9.4 Office Directory Setting privilege escalation (EUVD-2023-29228)
CVE-2023-25267 | GFI Kerio Connect 9.4.1 Patch 1 2FASetup webmail/api/jsonrpc primaryEMailAddress stack-based overflow (EUVD-2023-29229)
CVE-2019-25155 | Cure53 DOMPurify up to 1.0.10 hooks-target-blank-demo.html reverse tabnabbing (EUVD-2023-2923)
CVE-2023-25264 | Docmosis Tornado up to 2.9.4 Request improper authentication (EUVD-2023-29226)
CVE-2023-25265 | Docmosis Tornado up to 2.9.4 path traversal (EUVD-2023-29227)
CVE-2023-25263 | Stimulsoft Designer 2023.1.4/2023.1.5 Stimulsoft.report.dll hard-coded key (EUVD-2023-29225)
CVE-2023-25262 | Stimulsoft Designer Web 2023.1.3 server-side request forgery (EUVD-2023-29224)
CISA Alerts on Active Exploitation of WSUS Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about active exploitation of a critical vulnerability affecting Windows Server Update Service (WSUS). The agency updated its alert on October 29, 2025, adding crucial information about identifying vulnerable systems and detecting potential threats. Critical Flaw in Windows Server Update Service Microsoft released an […]
The post CISA Alerts on Active Exploitation of WSUS Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.