Aggregator
新春集福,再添一个经典款!
Re @TalBeerySec
Japanese Companies Threatened by DPRK IT Workers
Appdome Threat Dynamics analyzes and ranks mobile threats
Appdome announced that a new AI-Native threat-management module called Threat Dynamics will be offered inside Appdome’s ThreatScope Mobile XDR. Threat Dynamics uses AI deep learning to continuously evaluate the likelihood of a successful exploit from more than 400+ attack vectors and calculate a Mobile Risk Index for each business and mobile application. This allows businesses to see how threats move across the production environment, empowering them to quickly prioritize and focus on the attack vectors … More →
The post Appdome Threat Dynamics analyzes and ranks mobile threats appeared first on Help Net Security.
SonicWall SMA appliances exploited in zero-day attacks (CVE-2025-23006)
A critical zero-day vulnerability (CVE-2025-23006) affecting SonicWall Secure Mobile Access (SMA) 1000 Series appliances is being exploited by attackers. “We strongly advises users of the SMA1000 product to upgrade to the hotfix release version to address the vulnerability,” the company said on Wednesday. About CVE-2025-23006 SonicWall Secure Mobile Access (SMA) is a unified secure access gateway used by organizations to provide employees access to applications from anywhere. The SMA 1000 series of appliances is aimed … More →
The post SonicWall SMA appliances exploited in zero-day attacks (CVE-2025-23006) appeared first on Help Net Security.
思科提醒注意严重的DoS漏洞
思科提醒注意严重的DoS漏洞
三星Galaxy S25也没有支持Qi2无线充电协议 消费者需要购买带磁铁的手机壳
I'm not sure people fully grasp the severity of this #Fortigate config dump - Kevin breaks it down in his Mastodon posts : https://cyberplace.social/@...
Re grouped and sorted by TLD https://gist.github.com/Neo23x0/e2cb09c3a193218c28424fe768605103
Space Bears
OffensiveCon 2025 – Practical Browser Fuzzing On-site Training
I extracted the domains, grouped them and sorted them by TLD https://gist.github.com/Neo23x0/e2cb09c3a193218c28424fe768605103
Выкуп – не спасение: 64% компаний теряют будущее после кибератак
DigitalOcean Per-Bucket Access Keys boosts object storage security
DigitalOcean announced Per-Bucket Access Keys for DigitalOcean Spaces, its S3-compatible object storage service. This feature provides customers with identity-based, bucket-level control over access permissions, helping to enhance their data security and simplifying management. Prior to the introduction of Per-Bucket Access Keys, many customers chose to limit the types of applications they ran on DigitalOcean infrastructure to those without object storage requirements or with minimal access management requirements in order to better control access to their … More →
The post DigitalOcean Per-Bucket Access Keys boosts object storage security appeared first on Help Net Security.
安卓GPU漏洞攻防介绍
威胁情报 | 战争下的相爱相杀,疑似GamaCopy组织利用军事诱饵对俄发起攻击
威胁情报 | 战争下的相爱相杀,疑似GamaCopy组织利用军事诱饵对俄发起攻击
Rails Apps Arbitrary File Write Vulnerability Let Attackers Execute Code Remotely
A newly exposed vulnerability in Ruby on Rails applications allows attackers to achieve Remote Code Execution (RCE) through a flaw that permits arbitrary file writing. This vulnerability, which leverages the Rails library Bootsnap, underscores the critical importance of secure file handling in web applications. What Happened? A case study, shared by security researchers, demonstrated how an […]
The post Rails Apps Arbitrary File Write Vulnerability Let Attackers Execute Code Remotely appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.