Aggregator
CVE-2024-43512 | Microsoft Windows Standards-Based Storage Management Service infinite loop
3 months ago
A vulnerability, which was classified as critical, was found in Microsoft Windows Server 2012 R2/Server 2016/Server 2019/Server 2022. This affects an unknown part of the component Standards-Based Storage Management Service. The manipulation leads to infinite loop.
This vulnerability is uniquely identified as CVE-2024-43512. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43511 | Microsoft Windows up to Server 2022 23H2 Kernel toctou
3 months ago
A vulnerability, which was classified as critical, has been found in Microsoft Windows. Affected by this issue is some unknown functionality of the component Kernel. The manipulation leads to time-of-check time-of-use.
This vulnerability is handled as CVE-2024-43511. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43509 | Microsoft Windows up to Server 2022 23H2 Graphics use after free
3 months ago
A vulnerability classified as critical was found in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component Graphics. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-43509. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Kernel Kombat
3 months ago
Name: Kernel Kombat (an SLAY CTF event.)
Date: Oct. 6, 2024, 6:46 a.m. — 06 Oct. 2024, 06:46 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://zl-slay.vercel.app/
Rating weight: 0.00
Event organizers: S14y3r
Date: Oct. 6, 2024, 6:46 a.m. — 06 Oct. 2024, 06:46 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://zl-slay.vercel.app/
Rating weight: 0.00
Event organizers: S14y3r
How Major Companies Are Honoring Cybersecurity Awareness Month
3 months ago
The annual event reinforces best practices while finding new ways to build a culture where employees understand how their daily decisions affect company security. Find out how AWS, IBM, Intuit, SentinelOne, and Gallo are spreading the word.
Chris Betz
CVE-2024-43508 | Microsoft Windows 11 22H2/11 23H2/11 24H2/Server 2022 23H2 Graphics out-of-bounds
3 months ago
A vulnerability classified as problematic has been found in Microsoft Windows 11 22H2/11 23H2/11 24H2/Server 2022 23H2. Affected is an unknown function of the component Graphics. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2024-43508. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43506 | Microsoft Windows up to Server 2022 23H2 BranchCache resource consumption
3 months ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. This issue affects some unknown processing of the component BranchCache. The manipulation leads to resource consumption.
The identification of this vulnerability is CVE-2024-43506. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
二进制Pwn高级篇 | 本周更新:AWDplus
3 months ago
全新上线!入门到进阶带你全方位学习,掌握二进制漏洞挖掘的技能。
新的 Gorilla 僵尸网络在100个国家/地区发起了超过30万次 DDoS 攻击
3 months ago
该僵尸网络平均每天会发出不少于2万条分布式拒绝服务(DDoS)攻击的命令
ByteCTF逆向解析
3 months ago
看雪论坛作者ID:螺丝兔
国际 | “深度伪造”肆虐 韩国立法应对
3 months ago
近年来,随着人工智能技术的发展,使用“深度伪造”换脸技术制作的色情影像在韩国社交媒体上肆意传播,韩国女性深受其害。为从根本上清除这一社会毒瘤,保障女性权益,韩国政府不断加大打击“深度伪造”性犯罪的力度。
观点 | 如何加强对算法的治理
3 months ago
作为智能时代的核心技术,算法在深度赋能社会生活、提升社会运行效率的同时,也带来了算法黑箱、算法霸权、算法共谋、算法歧视等新问题,加强算法治理已成为不可回避的现实问题。
关注 | 国际电信联盟发布《全球网络安全指数2024年版》报告 呼吁合力应对全球网络安全挑战
3 months ago
近日,国际电信联盟发布《全球网络安全指数2024年版》报告。报告认为,随着人工智能、区块链和量子计算等新技术的快速发展,全球网络安全问题日益凸显,各类网络安全风险事件频发。报告呼吁各国采取更多措施并加强国际合作,合力应对全球网络安全挑战。
前沿 | 标识解析在油气储运行业“工业互联网+安全生产”中的应用
3 months ago
工业互联网是新一代信息通信技术与工业经济深度融合的新型基础设施、应用模式和工业生态。其中,工业互联网标识解析体系通过条形码、二维码等方式赋予物品唯一身份,实现全网资源的灵活区分和信息管理,是实现工业企业数据流通、信息交互的关键枢纽。
行业 | 安胜华信获第九届“创客中国”网络安全中小企业创新创业大赛一等奖
3 months ago
安胜华信下一代业务数据安全管控平台项目斩获企业组一等奖。
全球视野 | 国际网安快讯(第31期)
3 months ago
点击文章,了解最前沿的国际网安资讯!
CVE-2024-43505 | Microsoft Office Visio insufficient warning
3 months ago
A vulnerability was found in Microsoft Office. It has been declared as critical. This vulnerability affects unknown code of the component Visio. The manipulation leads to insufficient ui warning of dangerous operations.
This vulnerability was named CVE-2024-43505. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43504 | Microsoft Excel use after free
3 months ago
A vulnerability was found in Microsoft Excel. It has been classified as critical. This affects an unknown part. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-43504. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43503 | Microsoft SharePoint access control
3 months ago
A vulnerability was found in Microsoft SharePoint and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-43503. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com