Aggregator
摆脱高级威胁“达摩克利斯之剑”,科教行业再添安全“buff”
4 months 2 weeks ago
安全客
Technical Analysis of Copybara
4 months 2 weeks ago
Technical Analysis Upon launching the application, the user is shown an attacker-defined message scr
Owners of 1-Time Passcode Theft Service Plead Guilty
4 months 2 weeks ago
Three men in the United Kingdom have pleaded guilty to operating otp[.]agency, a once popular online service that helped attackers intercept the one-time passcodes (OTPs) that many websites require as a second authentication factor in addition to passwords.
Launched in November 2019, OTP Agency was a service for intercepting one-time passwords needed to log in to various websites. Scammers would enter the target’s phone number and name, and the service would initiate an automated phone call to the target that alerts them about unauthorized activity on their account.
BrianKrebs
2024-08-14 OSX BANSHEE infostealer Samples
4 months 2 weeks ago
Mila
2024-08-22 PEAKLIGHT Stealthy Memory-Only Malware Samples
4 months 2 weeks ago
Mila
CVE-2007-1814 | Xoops Core module viewcat.php cid sql injection (EDB-3620 / XFDB-33350)
4 months 2 weeks ago
A vulnerability was found in Xoops Core module. It has been rated as critical. Affected by this issue is some unknown functionality of the file viewcat.php of the component Core. The manipulation of the argument cid leads to sql injection.
This vulnerability is handled as CVE-2007-1814. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
IT worker charged over $750,000 cyber extortion plot against former employer
4 months 2 weeks ago
A former IT engineer is facing federal charges in the United States after his former employer foun
CVE-2017-6987 | Apple iOS up to 10.3.1 Kernel Memory information disclosure (HT207798 / Nessus ID 100270)
4 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Apple iOS up to 10.3.1. This issue affects some unknown processing of the component Kernel. The manipulation leads to information disclosure (Memory).
The identification of this vulnerability is CVE-2017-6987. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
马来西亚国家基建遭勒索攻击疑泄露超300GB数据
4 months 2 weeks ago
图:Prasarana官网疑似泄露超300GB数据,官方称未影响运营。8月30日消息,马来西亚公共交通运营商国家基建公司(Prasarana Malaysia Bhd)确认,社交媒体上关于其内部系统部
大模型的安全挑战及应对建议
4 months 2 weeks ago
当前,大模型技术在多个领域显著提升工作效率、改变了生产模式,并创造了巨大经济价值。例如,在金融行业,大模型被用于风险评估与市场预测;在医疗行业,它则助力图像识别与疾病诊断等。然而,这些技术带来的安全风
关键基础设施安全资讯周报20240902期
4 months 2 weeks ago
目录 技术标准规范大模型的安全发展与治理思考筑牢安全防线 加强跨境数据流动治理 行业发展动态黑客现形记!著名黑客USDoD真实身份确定!全球数据跨境流动合规 半月观察(第三十三期)Telegram创始
CVE-2003-0561 | IglooFTP Pro 3.8 memory corruption (EDB-22891)
4 months 2 weeks ago
A vulnerability classified as critical has been found in IglooFTP Pro 3.8. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2003-0561. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Irish Wildlife Park Warns Customers to Cancel Credit Cards Following Breach
4 months 2 weeks ago
Fota Wildlife Park in Co Cork has told visitors to its website to cancel credit and debit cards, following a cyber-attack
CVE-2014-5830 | Farm Frenzy Gold 1.0.1 X.509 Certificate cryptographic issues (VU#582497)
4 months 2 weeks ago
A vulnerability classified as critical was found in Farm Frenzy Gold 1.0.1. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-5830. The attack can only be done within the local network. There is no exploit available.
vuldb.com
Verkada to pay $2.95 million for alleged CAN-SPAM Act violations
4 months 2 weeks ago
The Federal Trade Commission (FTC) requires security camera vendor Verkada to create a comprehensive information security program as part of a settlement after multiple security failures enabled hackers to access live video feeds from internet-connected cameras. [...]
Bill Toulas
Verkada to pay $2.95M for security failures leading to breaches
4 months 2 weeks ago
The Federal Trade Commission (FTC) proposes a $2.95 million penalty on security camera vendor Verkada for multiple security failures that enabled hackers to access live video feeds from 150,000 internet-connected cameras. [...]
Bill Toulas
Конец эры безнаказанности: опасные алгоритмы ставят под удар будущее соцсетей
4 months 2 weeks ago
TikTok и другие платформы могут столкнуться с миллионами исков.
SecWiki News 2024-09-02 Review
4 months 2 weeks ago
CVE-2017-6986 | Apple macOS up to 10.12.4 iBooks memory corruption (HT207797 / Nessus ID 100270)
4 months 2 weeks ago
A vulnerability was found in Apple macOS up to 10.12.4. It has been rated as critical. Affected by this issue is some unknown functionality of the component iBooks. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2017-6986. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com