Aggregator
‘Voldemort’ 恶意软件利用全球税务机构对组织发动攻击
2 months 2 weeks ago
安全客
与韩国有关联的组织 APT-C-60 利用了 WPS Office 零日漏洞
2 months 2 weeks ago
安全客
网络攻击者在可能的间谍活动中利用 Google Sheets 进行恶意软件控制
2 months 2 weeks ago
安全客
Webinar: Learn to Boost Cybersecurity with AI-Powered Vulnerability Management
2 months 2 weeks ago
Vulnerability Management / WebinarThe world of cybersecurity is in a constant state of flux. New v
Stamattina alle 11 torno a Rete Tre con “Niente panico”
2 months 2 weeks ago
2024/09/02 Stamattina alle 11 torno a Rete Tre con “Niente panico” St
网络安全巨头持续加码 AI 投资:Check Point 和 Cisco 最新收购动向
2 months 2 weeks ago
安全客
Fortra 修复了 FileCatalyst Workflow 中的两个严重漏洞
2 months 2 weeks ago
安全客
模拟“noblox.js”的恶意 npm 包会破坏 Roblox 开发人员的系统
2 months 2 weeks ago
安全客
摆脱高级威胁“达摩克利斯之剑”,科教行业再添安全“buff”
2 months 2 weeks ago
安全客
Technical Analysis of Copybara
2 months 2 weeks ago
Technical Analysis Upon launching the application, the user is shown an attacker-defined message scr
Owners of 1-Time Passcode Theft Service Plead Guilty
2 months 2 weeks ago
Three men in the United Kingdom have pleaded guilty to operating otp[.]agency, a once popular online service that helped attackers intercept the one-time passcodes (OTPs) that many websites require as a second authentication factor in addition to passwords.
Launched in November 2019, OTP Agency was a service for intercepting one-time passwords needed to log in to various websites. Scammers would enter the target’s phone number and name, and the service would initiate an automated phone call to the target that alerts them about unauthorized activity on their account.
BrianKrebs
2024-08-14 OSX BANSHEE infostealer Samples
2 months 2 weeks ago
Mila
2024-08-22 PEAKLIGHT Stealthy Memory-Only Malware Samples
2 months 2 weeks ago
Mila
CVE-2007-1814 | Xoops Core module viewcat.php cid sql injection (EDB-3620 / XFDB-33350)
2 months 2 weeks ago
A vulnerability was found in Xoops Core module. It has been rated as critical. Affected by this issue is some unknown functionality of the file viewcat.php of the component Core. The manipulation of the argument cid leads to sql injection.
This vulnerability is handled as CVE-2007-1814. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
IT worker charged over $750,000 cyber extortion plot against former employer
2 months 2 weeks ago
A former IT engineer is facing federal charges in the United States after his former employer foun
CVE-2017-6987 | Apple iOS up to 10.3.1 Kernel Memory information disclosure (HT207798 / Nessus ID 100270)
2 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Apple iOS up to 10.3.1. This issue affects some unknown processing of the component Kernel. The manipulation leads to information disclosure (Memory).
The identification of this vulnerability is CVE-2017-6987. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
马来西亚国家基建遭勒索攻击疑泄露超300GB数据
2 months 2 weeks ago
图:Prasarana官网疑似泄露超300GB数据,官方称未影响运营。8月30日消息,马来西亚公共交通运营商国家基建公司(Prasarana Malaysia Bhd)确认,社交媒体上关于其内部系统部
大模型的安全挑战及应对建议
2 months 2 weeks ago
当前,大模型技术在多个领域显著提升工作效率、改变了生产模式,并创造了巨大经济价值。例如,在金融行业,大模型被用于风险评估与市场预测;在医疗行业,它则助力图像识别与疾病诊断等。然而,这些技术带来的安全风
关键基础设施安全资讯周报20240902期
2 months 2 weeks ago
目录 技术标准规范大模型的安全发展与治理思考筑牢安全防线 加强跨境数据流动治理 行业发展动态黑客现形记!著名黑客USDoD真实身份确定!全球数据跨境流动合规 半月观察(第三十三期)Telegram创始