Aggregator
欧洲刑警组织逮捕 25 名分享 AI 儿童色情的用户
3rd March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 3rd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Orange Group has confirmed a cyberattack on its Romanian branch, in which a hacker linked to the HellCat ransomware group stole 6.5GB of data over a month. The breach exposed 380,000 email […]
The post 3rd March – Threat Intelligence Report appeared first on Check Point Research.
Google Launches Shielded Email to Keep Your Address Hidden from Apps
Google is rolling out a new privacy-focused feature called Shielded Email, designed to prevent apps and services from accessing users’ primary email addresses during sign-ups. The feature, first discovered in a Google Play Services APK teardown by Android Authority months ago, will generate unique email aliases for each app or website, shielding users’ real addresses from potential data […]
The post Google Launches Shielded Email to Keep Your Address Hidden from Apps appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2002-1165 | Sendmail up to 8.12.6 SMRSH privileges management (EDB-21884 / Nessus ID 13981)
Attackers Automating Vulnerability Exploits with Few Hours of Disclosure
The cybersecurity landscape of 2024 witnessed an unprecedented increase in mass internet exploitation, driven by attackers’ ability to automate vulnerability exploits within hours of disclosure. GreyNoise’s 2025 Mass Internet Exploitation Report reveals a systematic industrialization of cyberattacks, with threat actors leveraging both cutting-edge and decades-old vulnerabilities to compromise systems at scale. From ransomware campaigns to […]
The post Attackers Automating Vulnerability Exploits with Few Hours of Disclosure appeared first on Cyber Security News.
Submit #510955: i-DRIVE Dashcam i11, i12 Improper Access Control for Register Interface [Accepted]
Submit #510952: i-DRIVE Dashcam i11, i12 Improper Access Controls [Accepted]
Submit #510951: i-DRIVE Dashcam i11, i12 Authentication Bypass by Primary Weakness [Accepted]
Submit #510950: i-DRIVE Dashcam i11, i12 Plaintext Password in Configuration File [Accepted]
Submit #510949: i-DRIVE Dashcam i11, i12 Use of Default Credentials [Accepted]
U.S. Halts Cyber Operations Targeting Russia
The United States has paused offensive cyber operations against Russia under an order from Defense Secretary Pete Hegseth, causing debates over geopolitical strategy and domestic cybersecurity priorities. While U.S. Cyber Command—a Unified Combatant Command overseeing military cyber operations—adheres to the directive, the Cybersecurity and Infrastructure Security Agency (CISA) insists its defensive posture remains unchanged. The […]
The post U.S. Halts Cyber Operations Targeting Russia appeared first on Cyber Security News.
JavaGhost Leveraging Amazon IAM Permissions To Trigger Phishing Attack
Unit 42, the threat intelligence team at Palo Alto Networks, has identified a sophisticated threat actor group named JavaGhost that has evolved from website defacement to executing persistent phishing campaigns using compromised AWS environments. The group, active since at least 2022, exploits overly permissive Amazon Identity and Access Management (IAM) permissions to leverage victims’ Simple […]
The post JavaGhost Leveraging Amazon IAM Permissions To Trigger Phishing Attack appeared first on Cyber Security News.
Bubba AI推出开源合规平台 Comp AI,助力10万家初创企业实现安全合规
Submit #506526: D-Link DAP-1562 1.10 NULL Pointer Dereference [Accepted]
Submit #506106: D-Link DAP-1562 1.10 Buffer Overflow [Accepted]
芹菜西兰花中的天然成分能抑制白发
CISA Adds Five Known Exploited Vulnerabilities to Catalog
CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2023-20118 Cisco Small Business RV Series Routers Command Injection Vulnerability
- CVE-2022-43939 Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability
- CVE-2022-43769 Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
- CVE-2018-8639 Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
- CVE-2024-4885 Progress WhatsUp Gold Path Traversal Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.