Aggregator
CVE-2018-0734 | Oracle API Gateway 11.1.2.4.0 OpenSSL information disclosure (Nessus ID 211827 / ID 176538)
CVE-2018-0734 | Oracle Tuxedo 12.1.1.0.0 OpenSSL information disclosure (Nessus ID 211827 / ID 176538)
CVE-2018-0734 | Oracle MySQL Enterprise Backup up to 3.12.3/4.1.2 information disclosure (Nessus ID 211827 / ID 176538)
CyCognito Report Highlights Rising Cybersecurity Risks in Holiday E-Commerce
Desertstorm Claims to have Leaked FTP Access of Radio Rencontre
Top Cyber Attacker Techniques, August–October 2024
DEF CON 32 – The Rise and Fall of Binary Exploitation
Authors/Presenters: Stephen Sims
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – The Rise and Fall of Binary Exploitation appeared first on Security Boulevard.
Cloudflare incident on November 14, 2024, resulting in lost logs
CVE-2009-4612 | Mortbay Jetty up to 6.1.21 cross site scripting (EDB-9887 / Nessus ID 44320)
SecWiki News 2024-11-26 Review
Chrome扩展攻击指南(三):全局视角 by tmr
Chrome扩展攻击指南(二):漏洞分析 by tmr
Chrome扩展攻击指南(一):基础知识 by tmr
更多最新文章,请访问SecWiki
Fog
Kill
勒索软件忙招人,2024 年网络安全五大新趋势
勒索软件袭击供应链管理公司 Blue Yonder,导致客户配送系统中断
Supply Chain Ransomware Attack Hits Starbucks, UK Grocers
Coffee store giant Starbucks was among other organizations affected by a ransomware attack this month on cloud managed service provider Blue Yonder, a Panasonic subsidiary that has more than 3,000 customers. Two UK grocery chains also were impacted.
The post Supply Chain Ransomware Attack Hits Starbucks, UK Grocers appeared first on Security Boulevard.
Lazarus Group 利用带有 “RustyAttr” 的 xattr 来逃避检测
PyPI Python 库“aiocpa”发现通过 Telegram Bot 泄露加密密钥
Researchers reveal exploitable flaws in corporate VPN clients
Researchers have discovered vulnerabilities in the update process of Palo Alto Networks (CVE-2024-5921) and SonicWall (CVE-2024-29014) corporate VPN clients that could be exploited to remotely execute code on users’ devices. CVE-2024-5921 CVE-2024-5921 affects various versions of Palo Alto’s GlobalProtect App on Windows, macOS and Linux, and stems from insufficient certification validation. It enables attackers to connect the GlobalProtect app to arbitrary servers, the company confirmed, and noted that this may result in attackers installing malicious … More →
The post Researchers reveal exploitable flaws in corporate VPN clients appeared first on Help Net Security.