Aggregator
Secure Your Spot at RSAC 2026 Conference
1 month 1 week hence
[Virtual Event] Shields Up: Key Technologies Reshaping Cybersecurity Defenses
1 month hence
Защита в промышленных масштабах: новые возможности PT ISIM 5
3 hours 56 minutes ago
Всё, что нужно знать об обновлении PT ISIM, на вебинаре 19 февраля.
А была ли материя? Ученые подозревают, что «невидимку», которую искали 50 лет, просто выдумали
4 hours 55 minutes ago
Тёмная материя — это не вещество, а ошибка в формуле?
CVE-2024-7928
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 8 - A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched ...
CVE-2024-22120
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 5 - Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
CVE-2026-20700
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 12 - A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a ...
CVE-2025-15556
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 26 - Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the ...
CVE-2024-27834
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 1 - The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
CVE-2024-27564
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 12 - pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading.
CVE-2025-41117
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 1 - Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.
Only datasources with the Jaeger HTTP API appear to be affected; ...
CVE-2026-21722
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 16 - Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange.
This did ...
CVE-2025-55182
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 20 - A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code ...
CVE-2024-43468
5 hours 39 minutes ago
Currently trending CVE - Hype Score: 12 - Microsoft Configuration Manager Remote Code Execution Vulnerability
Уволиться из OpenAI, чтобы спасти совесть. Почему лучшие умы ИИ-индустрии увольняются из корпораций в самый разгар технологического бума
5 hours 57 minutes ago
Люди, создавшие GPT, больше не хотят иметь к нему отношения.
Raw Socket 隐蔽通信实战:从 0 实现 ICMP 隧道
5 hours 58 minutes ago
在渗透测试和内网穿透场景中,ICMP 隧道是一种经典的隐蔽通信手段。市面上已经有不少成熟工具,比如 icmpsh、PingTunnel、icmptunnel 等,它们功能完善、开箱即用。但在实际使用中,我逐渐发现了一个问题:这些工具都是"黑盒"——你能用它们完成任务,却很难理解它们是如何工作的,更无法根据实际需求定制协议细节或调整流量特征。
记一次艰难的多级域内渗透过程
5 hours 58 minutes ago
该环境为多个域环境组成,涵盖多个域内知识点及利用过程。
记一次外网打点到Pickle 反序列化获取内网权限的过程
5 hours 58 minutes ago
外网打点:端口探测使用nmap进行端口探测发现存在22,80端口存活配置host文件之后,访问80端口,发现存在web页面web页面渗透测试测试功能,发现是一个聊天软件注册用户[email protected]/[email protected]发现存在点赞功能和评论功能漏洞入口XSS漏洞使用burp抓包尝试,发现存在·xss漏洞点击帖子上的“点赞”按钮后,界面会立即显示已点赞的用户列表。该列表会动态变化——每次
无境靶场-Time & Machines
5 hours 59 minutes ago
MHT:时间在流动!时间在流动!在跳舞!木大木大木大木大木大!