Aggregator
CVE-2008-3858 | IBM DB2 Universal Database up to 9.0 access control (ID 19515 / XFDB-45138)
CVE-2008-3839 | Sun OpenSolaris up to Snv 87 NFS Server denial of service (Nessus ID 34066 / ID 115929)
CVE-2008-3862 | Trend Micro OfficeScan 7.3/8.0 CGI Program memory corruption (Nessus ID 34490 / ID 116001)
CVE-2008-3862 | Trend Micro OfficeScan CGI Parser memory corruption (Nessus ID 34490 / ID 116001)
CVE-2008-3870 | Sun Solaris 8.0/9.0 numeric error (Nessus ID 13405 / ID 116436)
Cyber threats are changing and here’s what you should watch for
In this Help Net Security video, Stefan Tanase, Cyber Intelligence Expert at CSIS, gives an overview of how cybercriminals are changing their tactics, including using legitimate tools to avoid detection and developing more advanced info-stealing malware. Tanase also talks about new social engineering tricks like fake CAPTCHAs, changes in ransomware patterns, and the rise of mobile phishing attacks.
The post Cyber threats are changing and here’s what you should watch for appeared first on Help Net Security.
清华大学 | 基于HTTP/2服务器推送和签名HTTP交换的跨源Web攻击
CVE-2012-5223 | Crawlability vbseo up to 3.6.0 preg_replace char_repl code injection (EDB-18424 / XFDB-72689)
CVE-2010-3900 | Christian Dywan Midori up to 0.2.4 Certificates authentication spoofing (Nessus ID 53764 / ID 165174)
CVE-2010-4523 | opensc up to 0.11.13 card-acos5.c memory corruption (ID 4913 / Nessus ID 72073)
CVE-2008-3877 | Acoustica Mixcraft 3.0/4.1/4.2 memory corruption (EDB-6322 / ID 118017)
CVE-2008-3879 | Ultrashareware Ultra Office Control up to 2.0.2008.801 ActiveX Control OfficeCtrl.ocx first input validation (EDB-6319 / ID 115945)
CVE-2010-2264 | Apple Safari up to 4.0.5 information disclosure (USN-1006-1 / Nessus ID 47751)
AI forces security leaders to rethink hybrid cloud strategies
Hybrid cloud infrastructure is under mounting strain from the growing influence of AI, according to Gigamon. Cyberthreats grow in scale and sophistication As cyberthreats increase in both scale and sophistication, breach rates have surged to 55% during the past year, representing a 17% year-on-year rise, with AI-generated attacks emerging as a key driver of this growth. Security and IT teams are being pushed to a breaking point, with the economic cost of cybercrime now estimated … More →
The post AI forces security leaders to rethink hybrid cloud strategies appeared first on Help Net Security.
When AI Fights Back: Threats, Ethics, and Safety Concerns
In this episode, we explore an incident where Anthropic’s AI, Claude, didn’t just resist shutdown but allegedly blackmailed its engineers. Is this a glitch or the beginning of an AI uprising? Along with co-host Kevin Johnson, we reminisce about past episodes, discuss AI safety and ethics, and examine the implications of AI mimicking human behaviors […]
The post When AI Fights Back: Threats, Ethics, and Safety Concerns appeared first on Shared Security Podcast.
The post When AI Fights Back: Threats, Ethics, and Safety Concerns appeared first on Security Boulevard.
微软告警:Windows 10五月安全更新可能导致BitLocker恢复界面弹出
微软已经确认,一些Windows 10和Windows 10企业LTSC 2021系统将在安装2025年5月的安全更新后启动到BitLocker恢复。
BitLocker Windows安全功能对存储驱动器进行加密,以防止数据被盗,Windows计算机通常在TPM(可信平台模块)更新或硬件更改等事件后进入BitLocker恢复模式,以重新访问受保护的驱动器。
上周,微软证实了这个问题,并表示正在调查“少数”Windows 10电脑在安装KB5058379更新后显示BitLocker恢复屏幕的报告。
在受影响的设备上,在安装更新后,Windows可能无法启动足够多的时间来触发自动修复。在启用了BitLocker的设备上,BitLocker需要输入用户的BitLocker恢复密钥来启动自动修复。
检查Windows事件查看器的受影响用户还将在系统事件日志中看到带有0x800F0845错误的LSASS错误和安装失败事件。此外,虽然有些设备在启动修复失败后会进入BitLocker恢复循环,但其他设备在多次尝试安装KB5058379后会成功回滚到以前安装的更新。
用户可以通过登录到BitLocker恢复屏幕门户与微软帐户检索BitLocker恢复密钥。此支持页提供了有关如何在Windows中查找恢复密钥的进一步详细信息。
微软表示,他们正在调查这一问题,一旦获得有关根本原因的更多信息,他们将提供更新。
BitLocker恢复屏幕
在微软承认这个问题之前,许多Windows用户和管理员报告说,在安装了KB5058379累积更新(作为2025年5月补丁星期二的一部分发布)后,他们看到设备意外地进入Windows恢复环境(WinRE)并显示BitLocker恢复屏幕。
目前,这些报告指出联想、戴尔和惠普的各种系统配置和设备都受到了影响,所以目前还不清楚这是由特定的硬件还是软件问题引起的。
要在系统卡在BitLocker恢复提示符上回到Windows,可以尝试从BIOS中禁用英特尔可信执行技术(TXT)。如果失败了,也可以尝试禁用安全引导、虚拟化技术(如果问题仍然存在)或固件保护。
2024年8月,微软修复了另一个问题,即在安装2024年7月的Windows安全更新后,在Windows 10、Windows 11和Windows Server系统上触发BitLocker恢复提示。
2022年8月,在KB5012170安全更新导致一些设备启动进入BitLocker恢复屏幕后,Windows设备也受到了类似问题的影响。