Aggregator
CVE-2005-0736 | Linux Kernel up to 2.6.11 sys_epoll_wait memory corruption (EDB-1397 / Nessus ID 21923)
CVE-2011-5258 | OrangeHRM up to 2.6.11 index.php isAdmin cross site scripting (EDB-36379 / XFDB-71568)
纽约通过法律要求石化公司支付 750 亿美元建立气候资金
纽约通过法律要求石化公司支付 750 亿美元建立气候资金
ReliaQuest to Bring Cyber Lab Bootcamp to ReliaQuest Bowl Universities
ReliaQuest to Bring Cyber Lab Bootcamp to ReliaQuest Bowl Universities
2024 Year in Review: What We Got Right and Looking to 2025
2024 Year in Review: What We Got Right and Looking to 2025
In the final episode of the Shared Security Podcast for 2024, join us as we recap our predictions for the year, discuss what we got right and wrong, and highlight our top episodes on YouTube. We also extend a heartfelt thank you to our Patreon supporters and special guests. Plus, stay tuned for our predictions […]
The post 2024 Year in Review: What We Got Right and Looking to 2025 appeared first on Shared Security Podcast.
The post 2024 Year in Review: What We Got Right and Looking to 2025 appeared first on Security Boulevard.
reconFTW: Open-source reconnaissance automation
reconFTW is an open-source tool that simplifies and automates the reconnaissance process, delivering subdomain enumeration, vulnerability assessment, and gathering intelligence about a target. Using various techniques — such as passive and brute-force methods, permutations, certificate transparency analysis, source code scraping, analytics tracking, and DNS record analysis — reconFTW ensures comprehensive subdomain enumeration. This approach helps you uncover the most relevant and intriguing subdomains, giving you a competitive edge. Beyond enumeration, reconFTW performs vulnerability assessments, identifying … More →
The post reconFTW: Open-source reconnaissance automation appeared first on Help Net Security.
CVE-2021-3817 | wbce_cms sql injection (EDB-50609)
CVE-2024-13037 | 1000 Projects Attendance Tracking Management System 1.0 /admin/report.php attendance_report course_id sql injection
CVE-2024-13038 | CodeAstro Simple Loan Management System 1.0 Login /index.php email sql injection
Customizable bank? (Custombank) how would you use?
Machine identities are the next big target for attackers
86% of organizations had a security incident related to their cloud native environment within the last year, according to Venafi. As a result, 53% of organizations had to delay an application launch or slow down production time; 45% suffered outages or disruption to their application service; and 30% said attackers could gain unauthorized access to data, networks and systems. Security and developer teams continue to clash 88% of security leaders believe machine identities – specifically … More →
The post Machine identities are the next big target for attackers appeared first on Help Net Security.