Aggregator
商用密码方案研究 | 智慧医疗商用密码应用安全体系建设
Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution
Efficient API Interaction And Consumption With Laravel: A Beginner's Guide
CVE-2009-1872 | Adobe ColdFusion up to 8.1 searchlog.cfm startRow cross site scripting (EDB-33169 / Nessus ID 42340)
如何使用VeilTransfer评估和提升组织的数据安全态势
Technical debt of C:\Windows\System path
September 2024 Patch Tuesday forecast: Downgrade is the new exploit
I asked for a calm August 2024 Patch Tuesday in last month’s forecast article and that came to pass. The updates released were limited to the regular operating systems and all forms of Office applications. Six zero-day vulnerabilities were announced, with five in the operating systems and one in the Office applications. There were 63 CVEs addressed in the Windows 10 operating systems and associated servers and 55 CVEs addressed in Windows 11. Overall, it … More →
The post September 2024 Patch Tuesday forecast: Downgrade is the new exploit appeared first on Help Net Security.
CVE-2024-44956 | Linux Kernel up to 6.10.4 preempt_fence_work_func deadlock (458bb83119df/3cd1585e5790)
CVE-2024-44948 | Linux Kernel up to 6.10.4 mtrr_save_state state issue
CVE-2024-44953 | Linux Kernel up to 6.10.4 scsi kworker/0 ufshcd_rpm_get_sync deadlock (f13f1858a28c/3911af778f20)
CVE-2024-44954 | Linux Kernel up to 6.10.4 line6 Privilege Escalation
Microsoft removes revenge porn from Bing search using new tool
Human firewalls are essential to keeping SaaS environments safe
Businesses run on SaaS solutions: nearly every business function relies on multiple cloud-based tech platforms and collaborative work tools like Slack, Google Workspace apps, Jira, Zendesk and others. We recently surveyed security leaders and CISOs on top data security priorities and challenges. We discovered that over 70% work in organizations using 50 or more SaaS solutions, and nearly a third of the respondents reported their organization’s SaaS environments include 200 or more apps. With so … More →
The post Human firewalls are essential to keeping SaaS environments safe appeared first on Help Net Security.
JVN: 複数のキングソフト製品におけるパストラバーサルの脆弱性
RansomHub
The Next Generation of On-Chain Perpetual Futures Trading: A Conversation With Brian Purcell
Respotter: Open-source Responder honeypot
Respotter is an open-source honeypot designed to detect attackers when they launch Responder within your environment. This application identifies active instances of Responder by exploiting its behavior when responding to any DNS query. Respotter leverages LLMNR, mDNS, and NBNS protocols to query a non-existent hostname (default: Loremipsumdolorsitamet). If any of these requests receive a response, Responder is likely operating on your network. Respotter can send webhooks to Slack, Teams, or Discord. It also supports sending … More →
The post Respotter: Open-source Responder honeypot appeared first on Help Net Security.