Aggregator
资料下载 | 会计软件基本功能和服务规范、网络安全威胁2024年中报告
1 year 7 months ago
·政策
《会计软件基本功能和服务规范》
《关于加强和改进互联网财产保险业务监管有关事项的通知》
·报告
《2023互联网安全报告:“体系化主动安全”建设指南》
《网络安全威胁2024年中报告》
安全419《9问CEO》系列之:持安科技何艺
1 year 7 months ago
安全419《9问CEO》系列节目,用9个问题还原一家最真实的网络安全企业。
CVE-2024-7922 | D-Link DNS-1550-04 up to 20240814 /cgi-bin/myMusic.cgi command injection
1 year 7 months ago
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2024-7922. The attack may be launched remotely. Furthermore, there is an exploit available.
Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
It is recommended to replace the affected component with an alternative.
vuldb.com
Submit #391739: D-Link DNS 320/320L/321/323/325/327L Command Injection [Duplicate]
1 year 7 months ago
Submit #391739 / VDB-275108
BuaaIoTTeam
Submit #391720: D-Link DNS 320/320L/321/323/325/327L Command Injection [Duplicate]
1 year 7 months ago
Submit #391720 / VDB-275108
BuaaI0TTeam
Submit #391713: D-Link DNS 320/320L/321/323/325/327L Command Injection [Duplicate]
1 year 7 months ago
Submit #391713 / VDB-275108
BuaaI0TTeam
Submit #391698: D-Link DNS 320/320L/321/323/325/327L Command Injection [Duplicate]
1 year 7 months ago
Submit #391698 / VDB-275108
BuaaI0TTeam
Submit #391690: D-Link DNS 320/320L/321/323/325/327L Command Injection [Duplicate]
1 year 7 months ago
Submit #391690 / VDB-275108
BuaaI0TTeam
Submit #391689: D-Link DNS 320/320L/321/323/325/327L Command Injection [Duplicate]
1 year 7 months ago
Submit #391689 / VDB-275108
BuaaI0TTeam
Submit #391684: D-Link DNS 320/320L/321/323/325/327L Command Injection [Duplicate]
1 year 7 months ago
Submit #391684 / VDB-275108
BuaaI0TTeam
Submit #391683: D-Link DNS 320/320L/321/323/325/327L Command Injection [Duplicate]
1 year 7 months ago
Submit #391683 / VDB-275108
BuaaI0TTeam
Submit #391669: D-Link DNS 320/320L/321/323/325/327L Command Injection [Accepted]
1 year 7 months ago
Submit #391669 / VDB-275108
BuaaI0TTeam
Experts warn of exploit attempt for Ivanti vTM bug
1 year 7 months ago
Researchers at the Shadowserver Foundation observed an exploit attempt based on the public PoC for Ivanti vTM bug CVE-2024-7593. Researchers at the Shadowserver Foundation observed an exploit attempt based on the public proof of concept (PoC) for the Ivanti vTM bug, CVE-2024-7593. In Mid-August, Ivanti addressed a critical authentication bypass vulnerability, tracked as CVE-2024-7593 (CVSS […]
Pierluigi Paganini
19th August – Threat Intelligence Report
1 year 7 months ago
For the latest discoveries in cyber research for the week of 19th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The campaign of United States presidential nominee Donald Trump has had its internal communications hacked and leaked, allegedly by an Iranian threat actor. This aligns with Microsoft’s previous identification of a related […]
The post 19th August – Threat Intelligence Report appeared first on Check Point Research.
hagarb
「推安早报」0819 | Chrome、Zabbix等漏洞、红队工具更新
1 year 7 months ago
本期安全早报涵盖Chrome、Zabbix等多个软件漏洞,并介绍了红队工具更新,如Lil Pwny 3.2.0和BounceBack。同时,深度解析了CVE-2024-38148等漏洞,帮助您及时了解最新安全威胁和防御措施
「推安早报」0819 | Chrome、Zabbix等漏洞、红队工具更新
1 year 7 months ago
本期安全早报涵盖Chrome、Zabbix等多个软件漏洞,并介绍了红队工具更新,如Lil Pwny 3.2.0和BounceBack。同时,深度解析了CVE-2024-38148等漏洞,帮助您及时了解最新安全威胁和防御措施
「推安早报」0819 | Chrome、Zabbix等漏洞、红队工具更新
1 year 7 months ago
本期安全早报涵盖Chrome、Zabbix等多个软件漏洞,并介绍了红队工具更新,如Lil Pwny 3.2.0和BounceBack。同时,深度解析了CVE-2024-38148等漏洞,帮助您及时了解最新安全威胁和防御措施
「推安早报」0819 | Chrome、Zabbix等漏洞、红队工具更新
1 year 7 months ago
本期安全早报涵盖Chrome、Zabbix等多个软件漏洞,并介绍了红队工具更新,如Lil Pwny 3.2.0和BounceBack。同时,深度解析了CVE-2024-38148等漏洞,帮助您及时了解最新安全威胁和防御措施
「推安早报」0819 | Chrome、Zabbix等漏洞、红队工具更新
1 year 7 months ago
本期安全早报涵盖Chrome、Zabbix等多个软件漏洞,并介绍了红队工具更新,如Lil Pwny 3.2.0和BounceBack。同时,深度解析了CVE-2024-38148等漏洞,帮助您及时了解最新安全威胁和防御措施