Aggregator
.NET 内网攻防实战电子报刊
1 year 2 months ago
.NET 2024年第50期 红队武器库和资源汇总
1 year 2 months ago
.NET 安全防御绕过 | 通过创建管道代替cmd.exe执行命令
1 year 2 months ago
01阅读须知此文所提供的信息只为网络安全人员对自己所负责的网站、服务器等(包括但不限于)进行检测或维护参考,未经授权请勿利用文章中的技术资料对任何计算机系统进行入侵操作。利用此文所提供的信息而造成的直
.NET 2024年第50期 红队武器库和资源汇总
1 year 2 months ago
01阅读须知此文所提供的信息只为网络安全人员对自己所负责的网站、服务器等(包括但不限于)进行检测或维护参考,未经授权请勿利用文章中的技术资料对任何计算机系统进行入侵操作。利用此文所提供的信息而造成的直
.NET 内网攻防实战电子报刊
1 year 2 months ago
01.NET内网安全攻防报刊小报童电子报刊【.NET内网安全攻防】也正式上线了,引入小报童也是为了弥补知识星球对于轻量级阅读支持的不足,为用户读者提供更佳的阅读体验。如果您对阅读体验的需求比较高,那么
全景分析:AI生态系统的安全挑战大总结
1 year 2 months ago
总结人工智能/大型语言模型(AI/LLMs)已成为科技界最炙手可热的话题。在网络安全领域,AI的角色引发了一些讨论。总体来看,AI在安全领域的影响主要分为两大类:一方面,将AI整合到现有的安全措施中,
全景分析:AI生态系统的安全挑战大总结
1 year 2 months ago
波澜壮阔
CVE-2022-48063 | GNU Binutils up to 2.39 ELF File dwarf2.c load_separate_debug_files memory allocation (Nessus ID 212944)
1 year 2 months ago
A vulnerability classified as problematic has been found in GNU Binutils up to 2.39. This affects the function load_separate_debug_files of the file dwarf2.c of the component ELF File Handler. The manipulation leads to uncontrolled memory allocation.
This vulnerability is uniquely identified as CVE-2022-48063. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50171 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 systemport bcm_sysport_xmit memory leak (Nessus ID 212956)
1 year 2 months ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. Affected is the function bcm_sysport_xmit of the component systemport. The manipulation leads to memory leak.
This vulnerability is traded as CVE-2024-50171. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50209 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 bnxt_re __alloc_pbl allocation of resources (Nessus ID 212962)
1 year 2 months ago
A vulnerability classified as problematic was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. This vulnerability affects the function __alloc_pbl of the component bnxt_re. The manipulation leads to allocation of resources.
This vulnerability was named CVE-2024-50209. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50039 | Linux Kernel up to 5.10.226/5.15.167/6.1.112/6.6.56/6.11.3 sched enqueue null pointer dereference (Nessus ID 212964)
1 year 2 months ago
A vulnerability classified as critical was found in Linux Kernel up to 5.10.226/5.15.167/6.1.112/6.6.56/6.11.3. Affected by this vulnerability is the function enqueue of the component sched. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-50039. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5288 | wolfSSL up to 5.6.x ECDSA sensitive information (Nessus ID 212968)
1 year 2 months ago
A vulnerability was found in wolfSSL up to 5.6.x. It has been classified as problematic. Affected is an unknown function of the component ECDSA Handler. The manipulation leads to insecure storage of sensitive information.
This vulnerability is traded as CVE-2024-5288. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
2024 Year in Review: Features and Improvements in Pure Signal™ Scout
1 year 2 months ago
Team Cymru is excited to share our accomplishments in delivering new features and improvements in Pure Signal™ Scout. Thank you to our...
The post 2024 Year in Review: Features and Improvements in Pure Signal™ Scout appeared first on Security Boulevard.
David Monnier
2024 Year in Review: Features and Improvements in Pure Signal™ Scout
1 year 2 months ago
Team Cymru is excited to share our accomplishments in delivering new features and improvements i
OpenAI 喊话马斯克:告我实现不了 AGI;《黑神话:悟空》获TGA 年度动作游戏;50% 年轻人始终保持在线| 极客早知道
1 year 2 months ago
TGA 年度最佳游戏爆冷《黑神话:悟空》斩获最佳动作游戏奖12 月 13 日,作为每年 TGA 的重磅压轴奖项,年度最佳游戏可谓备受关注,尤其是今年《黑神话:悟空》也在该奖项的提名名单中,无数中国观众
OpenAI 喊话马斯克:告我实现不了 AGI;《黑神话:悟空》获TGA 年度动作游戏;50% 年轻人始终保持在线| 极客早知道
1 year 2 months ago
百度、吉利就「极越汽车」发表联合声明;NotebookLM AI 支持互动交谈;OpenAI 推出 Projects功能
Insecure file uploads: A complete guide to finding advanced file upload vulnerabilities
1 year 2 months ago
File upload vulnerabilities are fun to find, they are impactful by nature and in some cases even res
一周全球重大网络安全事件速递(第五十期)
1 year 2 months ago
网安标委第二次“标准周”举办,Facebook遭受全球大规模中断……
一周全球重大网络安全事件速递(第五十期)
1 year 2 months ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证