Aggregator
【安全圈】OpenAI 被币圈黑客盗号,15 个月内第四起
1 year 8 months ago
【安全圈】ChatGPT 客户端曝“记忆”漏洞,黑客可令 AI “转发对话记录”
1 year 8 months ago
【安全圈】寻求刺激入侵视频监控系统,一男子被山东警方采取刑事强制措施
1 year 8 months ago
A cyberattack on Kuwait Health Ministry impacted hospitals in the country
1 year 8 months ago
The Kuwait Health Ministry is recovering from a cyberattack that disrupted systems at multiple hospitals and disabled the Sahel healthcare app. Kuwait’s Health Ministry was the victim of a cyberattack that took systems at several of the country’s hospitals offline. The cyber attack also impacted the Ministry of Health website, which is still offline, and […]
Pierluigi Paganini
CVE-2024-42152 | Linux Kernel up to 5.10.221/5.15.162/6.1.97/6.6.38/6.9.8 nvmet_sq_destroy allocation of resources (Nessus ID 207773)
1 year 8 months ago
A vulnerability has been found in Linux Kernel up to 5.10.221/5.15.162/6.1.97/6.6.38/6.9.8 and classified as problematic. This vulnerability affects the function nvmet_sq_destroy. The manipulation leads to allocation of resources.
This vulnerability was named CVE-2024-42152. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43830 | Linux Kernel up to 6.1.102/6.6.43/6.10.2 trigger deactivate allocation of resources (Nessus ID 207773)
1 year 8 months ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.1.102/6.6.43/6.10.2. Affected is the function deactivate of the component trigger. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2024-43830. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26638 | Linux Kernel up to 6.1.75/6.6.14/6.7/6.7.2 nbd uninitialized pointer (Nessus ID 207773)
1 year 8 months ago
A vulnerability was found in Linux Kernel up to 6.1.75/6.6.14/6.7/6.7.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component nbd. The manipulation leads to uninitialized pointer.
This vulnerability is known as CVE-2024-26638. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36919 | Linux Kernel up to 6.8.9 bnx2fc mm/vmalloc.c Privilege Escalation (Nessus ID 207773)
1 year 8 months ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.8.9. Affected by this vulnerability is an unknown functionality of the file mm/vmalloc.c of the component bnx2fc. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2024-36919. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-47101 | Linux Kernel up to 5.15.11 asix_common.c asix_mdio_read uninitialized pointer (d259f621c859/8035b1a2a37a / Nessus ID 207773)
1 year 8 months ago
A vulnerability was found in Linux Kernel up to 5.15.11 and classified as problematic. Affected by this issue is the function asix_mdio_read of the file drivers/net/usb/asix_common.c. The manipulation leads to uninitialized pointer.
This vulnerability is handled as CVE-2021-47101. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26939 | Linux Kernel up to 6.1.87/6.6.28/6.8.2/6.9-rc1 i915 lib/debugobjects.c __active_retire use after free (Nessus ID 207773)
1 year 8 months ago
A vulnerability has been found in Linux Kernel up to 6.1.87/6.6.28/6.8.2/6.9-rc1 and classified as critical. Affected by this vulnerability is the function __active_retire in the library lib/debugobjects.c of the component i915. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-26939. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
U.S. Charges Three Iranian Nationals for Election Interference and Cybercrimes
1 year 8 months ago
U.S. federal prosecutors on Friday unsealed criminal charges against three Iranian nationals who are allegedly employed with the Islamic Revolutionary Guard Corps (IRGC) for their targeting of current and former officials to steal sensitive data.
The Department of Justice (DoJ) accused Masoud Jalili, 36, Seyyed Ali Aghamiri, 34, and Yasar (Yaser) Balaghi, 37, of participating in a conspiracy
The Hacker News
CVE-2024-40972 | Linux Kernel up to 6.9.6 ext4 ext4_xattr_set_entry allocation of resources (111103907234/0a46ef234756 / Nessus ID 207773)
1 year 8 months ago
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.9.6. Affected is the function ext4_xattr_set_entry of the component ext4. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2024-40972. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26595 | Linux Kernel up to 6.6.13/6.7.1 mlxsw mlxsw_sp_acl_tcam_region_destroy null pointer dereference (817840d125a3/d0a1efe417c9/efeb7dfea8ee / Nessus ID 207773)
1 year 8 months ago
A vulnerability was found in Linux Kernel up to 6.6.13/6.7.1. It has been rated as critical. This issue affects the function mlxsw_sp_acl_tcam_region_destroy of the component mlxsw. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2024-26595. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26600 | Linux Kernel up to 6.8-rc2 on SRP phy send_srp null pointer dereference (Nessus ID 207773)
1 year 8 months ago
A vulnerability was found in Linux Kernel up to 6.8-rc2 on SRP. It has been declared as critical. This vulnerability affects the function send_srp of the component phy. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-26600. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
An Anti-Facial Recognition Mask: Fighting for Privacy
1 year 8 months ago
My Thoughts to Protect PrivacyA mask designed to deny AI-based facial recognition from all angles.
How Long Does it Take You to Successfully Identify Phishing Emails?
1 year 8 months ago
Please fill out the form to read this article*** This is a Security Blogge
CVE-2020-8656 | EyesOfNetwork 5.3 API api_functions.php username sql injection (ID 156266 / EDB-48169)
1 year 8 months ago
A vulnerability classified as critical has been found in EyesOfNetwork 5.3. Affected is an unknown function of the file include/api_functions.php of the component API. The manipulation of the argument username leads to sql injection.
This vulnerability is traded as CVE-2020-8656. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Debunking Hiring Superstitions: Things That Aren't Really a Thing
1 year 8 months ago
(This post originally appeared on AdatoSystems.com)According to medical experts, people believe sup
CVE-2014-7057 | magzter Hong Kong Tatler Society 3 X.509 Certificate cryptographic issues (VU#582497)
1 year 8 months ago
A vulnerability classified as critical was found in magzter Hong Kong Tatler Society 3. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-7057. Access to the local network is required for this attack. There is no exploit available.
vuldb.com