Aggregator
安全热点周报:PipeMagic 木马利用 Windows 零日漏洞部署勒索软件
5 months 1 week ago
记一次域渗透从MD文档XSS漏洞到命令执行漏洞获取管理员权限
5 months 1 week ago
记一次域渗透从MD文档XSS漏洞到命令执行漏洞获取管理员权限
睡眠混淆技术分享(sleep obfuscation)
5 months 1 week ago
sleep obfuscation
罗格斯大学 | 利用马尔可夫链指纹分类加密流量
5 months 1 week ago
本文提出了一种基于一阶齐次马尔可夫链的加密流量分类方法
罗格斯大学 | 利用马尔可夫链指纹分类加密流量
5 months 1 week ago
本文提出了一种基于一阶齐次马尔可夫链的加密流量分类方法
Хактивизм или шпионаж: кто на самом деле отключает воду и свет в городах
5 months 1 week ago
Когда взлом — это госзаказ.
Attacks on the education sector are surging: How can cyber-defenders respond?
5 months 1 week ago
Academic institutions have a unique set of characteristics that makes them attractive to bad actors. What's the right antidote to cyber-risk?
AI Hallucinations Create “Slopsquatting” Supply Chain Threat
5 months 1 week ago
Experts have warned that threat actors could hijack AI hallucinations in “slopsquatting” attacks
CVE-2008-0749 | Calimero.CMS 3.3 index.php ID cross site scripting (EDB-31124 / BID-27690)
5 months 1 week ago
A vulnerability was found in Calimero.CMS 3.3. It has been declared as problematic. This vulnerability affects unknown code of the file index.php. The manipulation of the argument ID leads to cross site scripting.
This vulnerability was named CVE-2008-0749. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2018-17440 | D-Link Central WiFi Manager prior 1.03r0100-Beta1 FTP Server username/password unrestricted upload (EDB-45533)
5 months 1 week ago
A vulnerability classified as critical has been found in D-Link Central WiFi Manager. This affects an unknown part of the component FTP Server. The manipulation of the argument username/password with the input admin:admin leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2018-17440. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
4 岁儿童就支持少数服从多数
5 months 1 week ago
少数服从多数(多数决原则或 Majority rule)是一种广泛使用的协调群体内冲突的决策程序。但人们是从什么时候开始接受这一原则的?中美研究人员通过微信视频等方法招募了数百名 4-9 岁儿童(中国参与者主要为汉族且生活在城市),通过多项实验证明 4 岁儿童就开始偏好多数决原则,但他们并非在任何场合都偏好使用多数决原则。儿童们认识到在很多情况下多数决原则并不合适,比如个人在做决策时并不需要遵循多数人的意愿。在群体内决策时,如果多数人推荐的是不道德行为,他们也不认为应该遵守多数决原则。
Терминатор из желе: поработал — и растаял. Робототехника стала ещё экологичнее
5 months 1 week ago
Провода, железные каркасы — всё это уже неактуально... Что насчёт свиного жира?
Who Not How is the Smart Way to Bridge Expertise Gaps and Improve Your Odds of Success
5 months 1 week ago
A Shift in Thinking That Powers Growth We are in a world where speed, adaptability, and precision are paramount, businesses are faced with more complexity...Read More
The post Who Not How is the Smart Way to Bridge Expertise Gaps and Improve Your Odds of Success appeared first on ISHIR | Software Development India.
The post Who Not How is the Smart Way to Bridge Expertise Gaps and Improve Your Odds of Success appeared first on Security Boulevard.
Rishi Khanna
CVE-2025-2563 | User Registration & Membership Plugin up to 4.1.1 on WordPress prepare_members_data improper authentication
5 months 1 week ago
A vulnerability, which was classified as critical, has been found in User Registration & Membership Plugin up to 4.1.1 on WordPress. This issue affects the function prepare_members_data. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2025-2563. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-3553 | phpshe 1.8 admin.php?mod=brand&act=del pe_delete brand_id[] sql injection
5 months 1 week ago
A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_delete of the file /admin.php?mod=brand&act=del. The manipulation of the argument brand_id[] leads to sql injection.
This vulnerability was named CVE-2025-3553. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3554 | phpshe 1.8 api.php?mod=cron&act=buyer act cross site scripting
5 months 1 week ago
A vulnerability was found in phpshe 1.8. It has been rated as problematic. This issue affects some unknown processing of the file api.php?mod=cron&act=buyer. The manipulation of the argument act leads to cross site scripting.
The identification of this vulnerability is CVE-2025-3554. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-31344 | giflib up to 5.2.2 DumpScreen2RGB buffer overflow (Nessus ID 234059)
5 months 1 week ago
A vulnerability was found in giflib up to 5.2.2. It has been classified as critical. This affects the function DumpScreen2RGB. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-31344. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
MCP 安全检查清单:AI ⼯具⽣态系统安全指南
5 months 1 week ago
本清单涵盖多个领域安全要点,旨在帮助开发者识别潜在风险并加以防范。
MCP 安全检查清单:AI ⼯具⽣态系统安全指南
5 months 1 week ago
本清单涵盖多个领域安全要点,旨在帮助开发者识别潜在风险并加以防范。