Aggregator
CVE-2024-45302 | RestSharp up to 111.x RestRequest.AddHeader crlf injection (GHSA-4rr6-2v9v-wcpc)
CVE-2024-8328 | Hwa Jiuh Digital Technology Easy Test Online Learning and Testing Platform prior 24A01 cross site scripting
从0到1、从需求到上线:我如何结合大模型和专业素养来完成一个实际项目
ZDI-CAN-23382: Mintty
JVN: IPCOMにおける処理時間の相違に起因する情報漏えいの脆弱性
CVE-2024-1543 | wolfSSL up to 5.6.5 Side-Channel Protected T-Table timing discrepancy
CVE-2024-8329 | Gether Technology 6SHR System sql injection
CVE-2024-8327 | Hwa Jiuh Digital Technology Easy Test Online Learning and Testing Platform prior 24A01 page sql injection
CVE-2024-8330 | Gether Technology 6SHR System unrestricted upload
CVE-2024-2502 | Silabs SE up to 2.2.5 Temper unusual condition
CVE-2024-45488 | One Identity Safeguard for Privileged Passwords up to 7.0.5.0/7.4.1/7.5.1 Cookie improper authorization
直播预热 | 中国电信网络安全宣传月启动暨电信安全中国行·苏州站活动
CVE-2024-1545 | wolfSSL up to 5.6.6 on Linux/Windows wolfCrypt rsa.c RsaPrivateDecryption improper restriction of software interfaces to hardware features
CVE-2024-2881 | wolfSSL up to 5.6.6 on Linux wolfCrypt ed25519.c in wc_ed25519_sign_msg Rowhammer improper restriction of software interfaces to hardware features
网络安全警报:游戏行业面临的黑客威胁
网络安全警报:游戏行业面临的新威胁
A macro look at the most pressing cybersecurity risks
Forescout’s 2024H1 Threat Review is a new report that reviews the current state of vulnerabilities, threat actors, and ransomware attacks in the first half of 2024 and compares them to H1 2023. “Attackers are looking for any weak point to breach IT, IoT, and OT devices, and organizations that don’t know what they have connected to their networks or if it’s secured are being caught flat-footed,” said Barry Mainz, Forescout CEO. “To mitigate these extensive … More →
The post A macro look at the most pressing cybersecurity risks appeared first on Help Net Security.
专访宇树科技王兴兴:在人形机器人的巨变前夜,做一个敏锐的谨慎派
21款APP及SDK存在侵害用户权益行为被通报
关于侵害用户权益行为的APP(SDK)通报
(2024年第7批,总第42批)
工业和信息化部高度重视用户权益保护工作,依据《个人信息保护法》《网络安全法》《电信条例》《电信和互联网用户个人信息保护规定》等法律法规,持续整治APP侵害用户权益的违规行为。
近期,我部组织第三方检测机构进行抽查,共发现21款APP及SDK存在侵害用户权益行为(详见附件),现予以通报。
上述APP及SDK应按有关规定进行整改,整改落实不到位的,我部将依法依规组织开展相关处置工作。
附件:工业和信息化部通报存在问题的APP(SDK)名单
工业和信息化部信息通信管理局
2024年8月27日
文章来源自:工业和信息化部信息通信管理局