Aggregator
HGAME2025杭州电子科技大学网络攻防大赛 PWN writeup
1 year 4 months ago
Updated Shadowpad Malware Leads to Ransomware Deployment
1 year 4 months ago
In this blog, we discuss about how Shadowpad is being used to deploy a new undetected ransomware family. They deploy the malware exploiting weak passwords and bypassing multi-factor authentication
Daniel Lunghi
高效稳定:光伏电站WiFi全覆盖技术方案
1 year 4 months ago
切实提高光伏电站的运行效率和安全性。
Ransomware Attack Update for 19th of February 2025
1 year 4 months ago
Ransomware Attack Update for 19th of February 2025
Dark Web Informer - Cyber Threat Intelligence
【LLMSC@ISSTA】第一届大模型供应链研讨会征稿通知
1 year 4 months ago
本次研讨会旨在汇聚学术界和工业界的各方力量,交流领域内的最新研究进展,共同探讨大语言模型供应链的机遇与挑战。
【LLMSC@ISSTA】第一届大模型供应链研讨会征稿通知
1 year 4 months ago
本次研讨会旨在汇聚学术界和工业界的各方力量,交流领域内的最新研究进展,共同探讨大语言模型供应链的机遇与挑战。
CVE-2025-21355: Microsoft Bing Remote Code Execution Vulnerability
1 year 4 months ago
CVE-2025-21355: Microsoft Bing Remote Code Execution Vulnerability
Dark Web Informer - Cyber Threat Intelligence
Career Spotlight: Cloud Security Specialist
1 year 4 months ago
Demand for Cloud Security Skills Is Growing, Offering Good Pay and New Challenges
Cloud services support a wide range of applications from finance to healthcare systems and have become prime targets for cybercriminals, making cloud security a major concern for cybersecurity organizations. The need to secure the cloud is driving demand for skilled cloud security specialists.
Cloud services support a wide range of applications from finance to healthcare systems and have become prime targets for cybercriminals, making cloud security a major concern for cybersecurity organizations. The need to secure the cloud is driving demand for skilled cloud security specialists.
Live Webinar | Thrive in Chaos: How to Get Your Minimum Viable Company Back Online
1 year 4 months ago
Infostealers Tied to Stolen AI and Defense Credentials
1 year 4 months ago
Information-Stealing Malware Continues to Feed Markets for Stolen Credentials
Defense sector and military agency employees, and artificial intelligence service users, all show signs of having been infected by information-stealing malware, as the market for buying and selling stolen credentials continues to thrive, experts warn.
Defense sector and military agency employees, and artificial intelligence service users, all show signs of having been infected by information-stealing malware, as the market for buying and selling stolen credentials continues to thrive, experts warn.
Menlo Buys CDR Vendor Votiro to Protect Collaboration Tools
1 year 4 months ago
CDR, DLP Provider Will Help Safeguard Cloud-Based Applications, Collaboration Tools
Menlo Security bought a data and file security vendor led by a longtime IBM executive to secure cloud-based applications and collaboration tools. Votiro's CDR and DLP tools will neutralize threats in real time and facilitate AI-driven data protection without disrupting user workflows.
Menlo Security bought a data and file security vendor led by a longtime IBM executive to secure cloud-based applications and collaboration tools. Votiro's CDR and DLP tools will neutralize threats in real time and facilitate AI-driven data protection without disrupting user workflows.
Military Health Firm Pays $11.2M to Settle Cyber Fraud Case
1 year 4 months ago
DOJ Says Contractor Falsely Claimed to Meet Critical Cyber Requirements
A military health benefits administrator has agreed to pay $11.2 million to settle allegations that the company falsely certified compliance with cybersecurity requirements - including patch management - for three years in a contract with the U.S. Department of Defense.
A military health benefits administrator has agreed to pay $11.2 million to settle allegations that the company falsely certified compliance with cybersecurity requirements - including patch management - for three years in a contract with the U.S. Department of Defense.
South Korea Keeps DeepSeek AI Chatbot Off App Stores
1 year 4 months ago
Regulators Cite Privacy Concerns Over DeepSeek's Data Collection Practices
The Personal Information Protection Commission, South Korea's data protection regulator, has directed Chinese artificial intelligence company DeepSeek AI to withdraw its chatbot application from official app stores pending an inquiry into the chatbot's compliance with data protection rules.
The Personal Information Protection Commission, South Korea's data protection regulator, has directed Chinese artificial intelligence company DeepSeek AI to withdraw its chatbot application from official app stores pending an inquiry into the chatbot's compliance with data protection rules.
Insight Partners, VC Giant, Falls to Social Engineering
1 year 4 months ago
The startup incubator and PR firm with holdings in more than 70 cybersecurity firms has announced a data breach with as-yet-unknown effects.
Tara Seals, Managing Editor, News, Dark Reading
Russian Groups Target Signal Messenger in Spy Campaign
1 year 4 months ago
These sorts of attacks reveal growing adversary interest in secure messaging apps used by high-value targets for communication, Google says.
Jai Vijayan, Contributing Writer
网络钓鱼即服务平台 Darcula 现已支持自动生成针对任何品牌的钓鱼工具包
1 year 4 months ago
Darcula PhaaS 推出新版本,支持自动生成任何品牌的钓鱼工具包,克隆合法网站并窃取数据。Netcraft警告其易用性将大幅增加钓鱼攻击量,威胁全球网络安全!
Statement to the Intelligence and Security Committee by Director-General Andrew Clark 19 February 2025
1 year 4 months ago
Russia-linked APTs target Signal messenger
1 year 4 months ago
Russia-linked threat actors exploit Signal ‘s “linked devices” feature to hijack accounts, per Google Threat Intelligence Group. Google Threat Intelligence Group (GTIG) researchers warn of multiple Russia-linked threat actors targeting Signal Messenger accounts used by individuals of interest to Russian intelligence. The experts speculate that the tactics, techniques, and procedures used to target Signal will […]
Pierluigi Paganini
CVE-2024-52995 | Adobe Substance3D Sampler up to 4.5.1 heap-based overflow (apsb24-100 / Nessus ID 212762)
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Adobe Substance3D Sampler up to 4.5.1. Affected is an unknown function. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-52995. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com