Aggregator
17家单位联发《工业和信息化领域数据安全合规指引》
5 months ago
11月19日,17家单位联合发布《工业和信息化领域数据安全合规指引》,聚焦数据处理者在履行数据安全保护义务过程中的难点问题,明确数据安全合规依据,提供实务指引,有利于支撑数据处理者全面、准确、规范开展数据安全合规管理,提升数据安全保护能力。
关注本公众号【威努特安全网络】,在对话框回复【合规指引】获取原文。
编制单位:
工业信息安全产业发展联盟
中国钢铁工业协会
中国有色金属工业协会
中国石油和化学工业联合会
中国建筑材料联合会
中国机械工业联合会
中国汽车工业协会
中国纺织工业联合会
中国轻工业联合会
中国电子信息行业联合会
中国计算机行业协会
中国通信企业协会
中国互联网协会
中国通信标准化协会
中国中小企业国际合作协会
中国通信学会
工业和信息化部商用密码应用产业促进联盟
远程办公新范式:威努特零信任安全访问控制系统
5 months ago
基于零信任的远程办公安全解决方案。
Weekly Report: JPCERT/CCが「インターネット定点観測レポート(2024年 7-9月)」を公開
5 months ago
JPCERT/CCは、「インターネット定点観測レポート(2024年 7-9月)」を公開しました。2024年7月から9月の間に、インターネット定点観測システム「TSUBAME」で観測した結果とその分析の概要について紹介しています。
Ablative Study on Domain Adapter, Motion Module Design, and MotionLoRA Efficiency
5 months ago
Authors:(1) Yuwei Guo, The Chinese University of Hong Kong;(2) Ceyuan Yang, Shanghai Artificial I
DEF CON 32 – Bricked & Abandoned: How To Keep IoT From Becoming An IoTrash
5 months ago
Authors/Presenters: Paul Rob
JVN: FitNesseにおける複数の脆弱性
5 months ago
unclebobが提供するFitNesseには複数の脆弱性が存在します。
The Essential Guide to Social Share Images in 2024
5 months ago
As developers, we spend hours crafting great content, but often overlook how it appears when shared
CVE-2011-5028 | novell Sentinel Log Manager up to 1.2.0.1 938 filename path traversal (EDB-21082 / XFDB-71861)
5 months ago
A vulnerability was found in novell Sentinel Log Manager up to 1.2.0.1 938. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument filename leads to path traversal.
This vulnerability is known as CVE-2011-5028. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
IntelBroker and EnergyWeaponUser Have Claimed to have Leaked Tesla EV Charging Station
5 months ago
IntelBroker and EnergyWeaponUser Have Claimed to have Leaked Tesla EV Charging Station
Dark Web Informer
Russian Phobos ransomware operator faces cybercrime charges
5 months ago
Russian Phobos ransomware operator Evgenii Ptitsyn, accused of managing attacks, was extradited from South Korea to the US to face cybercrime charges. Russian Phobos ransomware operator Evgenii Ptitsyn, suspected of playing a key role in the ransomware operations, was extradited from South Korea to the US to face cybercrime charges. According to the DoJ, the […]
Pierluigi Paganini
CVE-2023-27561 | runc up to 1.1.4 volume-mount Configuration rootfs_linux.go access control (Issue 2197 / Nessus ID 211562)
5 months ago
A vulnerability was found in runc up to 1.1.4. It has been declared as critical. This vulnerability affects unknown code of the file libcontainer/rootfs_linux.go of the component volume-mount Configuration. The manipulation leads to improper access controls.
This vulnerability was named CVE-2023-27561. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2023-25809 | runc up to 1.1.4 /sys/fs/cgroup permissions (GHSA-m8cg-xc2p-r3fc / Nessus ID 211562)
5 months ago
A vulnerability, which was classified as critical, has been found in runc up to 1.1.4. Affected by this issue is some unknown functionality of the file /sys/fs/cgroup. The manipulation leads to preservation of permissions.
This vulnerability is handled as CVE-2023-25809. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-29038 | tpm2-tools Quote Data tpm2_checkquote mutable attestation or measurement reporting data (Nessus ID 211559)
5 months ago
A vulnerability classified as problematic has been found in tpm2-tools. This affects the function tpm2_checkquote of the component Quote Data Handler. The manipulation leads to mutable attestation or measurement reporting data.
This vulnerability is uniquely identified as CVE-2024-29038. The attack needs to be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-29039 | tpm2-tools pcr Selection Value tpm2_checkquote.c comparison (Nessus ID 211559)
5 months ago
A vulnerability classified as problematic was found in tpm2-tools. This vulnerability affects unknown code of the file tools/misc/tpm2_checkquote.c of the component pcr Selection Value Handler. The manipulation leads to incorrect comparison.
This vulnerability was named CVE-2024-29039. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2021-43784 | runc up to 1.0.2 on Linux integer overflow (GHSA-v95c-p5hm-xq8f / Nessus ID 211562)
5 months ago
A vulnerability was found in runc up to 1.0.2 on Linux. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to integer overflow.
This vulnerability was named CVE-2021-43784. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-28642 | runc up to 1.1.4 AppArmor /proc permissions (GHSA-g2j6-57v7-gm8c / Nessus ID 211562)
5 months ago
A vulnerability was found in runc up to 1.1.4. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /proc of the component AppArmor. The manipulation leads to preservation of permissions.
This vulnerability is known as CVE-2023-28642. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-29409 | crypto-tls RSA Key resource consumption (Nessus ID 211562)
5 months ago
A vulnerability was found in crypto-tls. It has been rated as problematic. Affected by this issue is some unknown functionality of the component RSA Key Handler. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2023-29409. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-25173 | containerd up to 1.5.17/1.6.17 Supplementary Group information disclosure (GHSA-4wjj-jwc9-2x96 / Nessus ID 211563)
5 months ago
A vulnerability classified as problematic has been found in containerd up to 1.5.17/1.6.17. This affects an unknown part of the component Supplementary Group Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2023-25173. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-1393 | X.Org Server Overlay Window use after free (FEDORA-2023-eb3c27ff25 / Nessus ID 211567)
5 months ago
A vulnerability was found in X.Org Server. It has been declared as problematic. This vulnerability affects unknown code of the component Overlay Window. The manipulation leads to use after free.
This vulnerability was named CVE-2023-1393. An attack has to be approached locally. There is no exploit available.
vuldb.com