Aggregator
CVE-2006-3811 | Mozilla Firefox 1.5/1.5.0.1/1.5.0.2/1.5.0.3/1.5.0.4 FireMenuItemActiveEvent integer coercion (MFSA2006-55 / VU#527676)
CVE-2006-3812 | Mozilla Firefox 1.5/1.5.0.1/1.5.0.2/1.5.0.3/1.5.0.4 chrome URI integer coercion (MFSA2006-56 / VU#398492)
CVE-2006-3810 | Mozilla Firefox 1.5/1.5.0.1/1.5.0.2/1.5.0.3/1.5.0.4 JavaScript XPCNativeWrapper integer coercion (MFSA2006-54 / VU#911004)
CVE-2006-4956 | Neosys Neon WebMail up to 5.7 in_name cross site scripting (EDB-28610 / XFDB-29091)
CVE-2012-4870 | FreePBX 2.9 /index_amp.php context cross site scripting (Unofficial Patch / EDB-18649)
销售数据表明英特尔的新CPU可能确实比较垃圾 AMD 9800X3D在德国销量爆棚
Chainsaw: Open-source tool for hunting through Windows forensic artefacts
Chainsaw is an open-source first-response tool for quickly detecting threats in Windows forensic artefacts, including Event Logs and the MFT file. It enables fast keyword searches through event logs and identifies threats using built-in Sigma detection and custom detection rules. Chainsaw features Hunt for threats using Sigma detection rules and custom detection rules Search and extract forensic artefacts by string matching and regex patterns Create execution timelines by analyzing Shimcache artefacts and enriching them with … More →
The post Chainsaw: Open-source tool for hunting through Windows forensic artefacts appeared first on Help Net Security.
33,542 Ivanti Connect Secure Instances Exposed as Exploitation of CVE-2025-0282 Unfolds
A critical security vulnerability, CVE-2025-0282, has been identified and exploited in the wild, affecting Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways. This stack-based buffer overflow vulnerability, rated with a CVSS score of 9.0, allows unauthenticated attackers to execute arbitrary code remotely. The flaw impacts versions of Ivanti Connect Secure prior to 22.7R2.5, […]
The post 33,542 Ivanti Connect Secure Instances Exposed as Exploitation of CVE-2025-0282 Unfolds appeared first on Cyber Security News.
I created a website to apply my knowledge of AI and Natural Language Processing into something useful
外国车企的「智能树」,原来是这么「点歪」的
外国车企的「智能树」,原来是这么「点歪」的
CVE-2007-1264 | Enigmail 0.94.2 --status-fd (EDB-29690 / Nessus ID 24809)
CVE-2000-0516 | Intel Shiva Access Manager 5.0.0 on Solaris Credential cleartext storage (EDB-20003 / XFDB-4612)
CVE-2006-4954 | Neosys Neon WebMail up to 5.7 in_id privileges management (EDB-28609 / XFDB-29089)
Time for a change: Elevating developers’ security skills
Organizations don’t know their software engineers’ security skills because they don’t assess them in the interview process. Trying to do that in an interview is challenging, of course, given the time it takes for a proper assessment. However, given the industry push toward shift-left, it’s just not good enough – for the developer or the organization – to simply view security as a teachable skill and move forward with the same processes. Given the right … More →
The post Time for a change: Elevating developers’ security skills appeared first on Help Net Security.