Aggregator
【研究报告】澳大利亚与太平洋国家达成协议以遏制我国影响力
1 year 3 months ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
俄罗斯国防部揭露:美国在非洲秘密建立生物实验室网络
1 year 3 months ago
2024年12月24日俄罗斯武装部队辐射、化学和生物防护部队 (RChBZ) 举行了第一次简报会。会议主题为美国在非洲的军事生物活动。图:RChBZ部队副总司令阿列克谢·维克托罗维奇·尔蒂谢夫少将。此
Apache Traffic Control 中的严重 SQL 注入漏洞 CVSS 评分为 9.9
1 year 3 months ago
error code: 521
Apache Traffic Control 中的严重 SQL 注入漏洞 CVSS 评分为 9.9
1 year 3 months ago
Apache 软件基金会 (ASF) 已发布安全更新来修复流量控制中的一个严重安全漏洞,如果成功利用该漏洞,攻击者可以在数据库中执行任意结构化查询语言 (SQL) 命令。 该 SQL 注入漏洞的编号为CVE-2024-45387,在 CVSS 评分系统中的评分为 9.9 分(满分 10.0 分)。 项目维护人员在一份公告中表示:“Apache Traffic Control <= 8.0.1、>= 8.0.0 中的 Traffic Ops 中存在一个 SQL 注入漏洞,允许具有‘管理员’、‘联合’、‘操作’、‘门户’或‘指导’角色的特权用户通过发送特制的 PUT 请求对数据库执行任意 SQL 。 ” Apache Traffic Control是内容分发网络 (CDN) 的开源实现。它于 2018 年 6 月被AS宣布为顶级项目 (TLP)。 腾讯云鼎安全实验室研究员罗远发现并报告了该漏洞。该漏洞已在 Apache Traffic Control 8.0.2 版本中得到修复。 此次开发正值 ASF解决了Apache HugeGraph-Server (CVE-2024-43441) 1.0 至 1.3 版本中的身份验证绕过漏洞。1.5.0 版本中已发布了针对该缺陷的修复程序。 它还发布了针对 Apache Tomcat(CVE-2024-56337)中一个重要漏洞的补丁,该漏洞可能在某些条件下导致远程代码执行(RCE)。 建议用户将其实例更新到软件的最新版本,以防范潜在威胁。 转自军哥网络安全读报,原文链接:https://mp.weixin.qq.com/s/AlMi5CgBPNhmkSF0h-fhzQ 封面来源于网络,如有侵权请联系删除
内容转载
CVE-2015-3105 | Adobe Flash Player up to 18.0.0.x memory corruption (APSB15-11 / EDB-37448)
1 year 3 months ago
A vulnerability was found in Adobe Flash Player up to 18.0.0.x. It has been classified as critical. Affected is an unknown function. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2015-3105. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Scared about CCDC
1 year 3 months ago
CVE-2013-3487 | Ait-pro Bulletproof-security up to .48.9 400.php cross site scripting (ID 12908 / XFDB-86160)
1 year 3 months ago
A vulnerability classified as problematic has been found in Ait-pro Bulletproof-security. Affected is an unknown function of the file 400.php. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2013-3487. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-3526 | Wptrafficanalyzer Trafficanalyzer up to 3.3.2 aoid cross site scripting (ID 121167 / Nessus ID 66176)
1 year 3 months ago
A vulnerability was found in Wptrafficanalyzer Trafficanalyzer and classified as problematic. This issue affects some unknown processing. The manipulation of the argument aoid leads to cross site scripting.
The identification of this vulnerability is CVE-2013-3526. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2013-3520 | VMware vCenter Chargeback Manager up to 2.5 File Validation code injection (VMSA-2013-0008 / EDB-27046)
1 year 3 months ago
A vulnerability classified as critical was found in VMware vCenter Chargeback Manager up to 2.5. Affected by this vulnerability is an unknown functionality of the component File Validation Handler. The manipulation leads to code injection.
This vulnerability is known as CVE-2013-3520. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-3543 | AXIS Media Control Activex Control 6.2.10.11 ActiveX Control AxisMediaControlEmb.dll access control (EDB-26173 / ID 121519)
1 year 3 months ago
A vulnerability classified as critical has been found in AXIS Media Control Activex Control 6.2.10.11. Affected is an unknown function in the library AxisMediaControlEmb.dll of the component ActiveX Control. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2013-3543. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
公益+专属SRC新年福利活动上线!新年礼盒大揭秘!
1 year 3 months ago
快来看看新年礼盒有什么
公益+专属SRC新年福利活动上线!新年礼盒大揭秘!
1 year 3 months ago
2025新年福利为 2025 蓄势待发2024——2025新年礼盒大揭秘超大面包盒储物筐01羊羔绒超可爱编制收纳筐超大容量 满足收纳创意造型 有趣百搭还可以做猫窝哦~HAPPY NEW YEARHAP
美国成瘾治疗中心(AAC)遭遇黑客攻击,40万名患者个人信息泄露
1 year 3 months ago
error code: 521
美国成瘾治疗中心(AAC)遭遇黑客攻击,40万名患者个人信息泄露
1 year 3 months ago
美国成瘾治疗中心(AAC)是一家营利性成瘾治疗连锁机构,其遭遇网络安全事件,导致 422,424 人的个人记录泄露。 根据该公司发送给受影响人员的通知函,泄露的数据可能包括姓名、地址、电话号码、出生日期、医疗记录号和其他标识符。 ACC 表示,社会安全号码和健康保险信息也可能被泄露,但患者的治疗信息或支付卡数据不会泄露。 这家总部位于田纳西州布伦特伍德的公司在今年 9 月 26 日左右发现了一起网络安全事件,并表示已立即展开调查。该公司已通知执法部门并聘请第三方网络安全专家提供帮助。 调查确定,9 月 23 日至 9 月 26 日期间,“未经授权的一方”从 AAC 系统中窃取了一些数据。 该公司告诉客户:“我们对受影响的数据进行了彻底审查,以确定涉及哪些信息以及与数据相关的个人。”该公司还表示,“目前”尚未发现与该事件有关的任何身份盗窃或欺诈行为。 此次泄密事件影响了 AAC 及其附属供应商的客户,包括 AdCare、Greenhouse、Desert Hope Center、Oxford Treatment Center、Recovery First、Sunrise House、River Oaks Treatment Center 和 Laguna Treatment Hospital。 近期一系列网络安全事件让多家医疗服务提供商成为攻击目标。Regional Care 的数据泄露事件发生于 9 月中旬,本月初已报告此事,影响 22.5 万人。 总部位于马里兰州的静脉修复中心 (CVR)遭遇重大数据泄露,影响了 446,000 人的数据;而位于马萨诸塞州的安娜雅克医院 (AJH) 遭遇的攻击则导致超过 316,000 人的数据受到影响。 攻击者针对医疗保健机构主要有两个原因:这些机构通常保护不力,而且他们保存的数据非常有价值。例如,攻击者可以利用泄露的信息进行健康身份欺诈,使恶意攻击者能够获得处方药。 转自军哥网络安全读报,原文链接:https://mp.weixin.qq.com/s/WVVU9xYidj3jr_xORgV7sA 封面来源于网络,如有侵权请联系删除
内容转载
お知らせ:JPCERT/CC Eyes「近年の水飲み場攻撃事例 Part2」
1 year 3 months ago
Recent Cases of Watering Hole Attacks, Part 2
1 year 3 months ago
Continuing from the previous article, Part 2 covers another case of a watering hole attack. This time, we will look at the case of a media-related website exploited in 2023. Flow of the attack Figure 1 shows the flow of...
朝長 秀誠 (Shusei Tomonaga)
Cybersecurity Resolutions: Skill Sets to Prioritize in 2025
1 year 3 months ago
Key Focus Areas for Cybersecurity Professionals in 2025
As we enter 2025, the cybersecurity landscape demands more than just maintaining the status quo. New threats, evolving technologies, and heightened regulatory scrutiny require professionals to set clear resolutions that sharpen their abilities and expand their impact.
As we enter 2025, the cybersecurity landscape demands more than just maintaining the status quo. New threats, evolving technologies, and heightened regulatory scrutiny require professionals to set clear resolutions that sharpen their abilities and expand their impact.
Demystifying Cyber Resilience: Building a Robust Defense
1 year 3 months ago
InfoSec Officer Shervin Evans on Preparing Organizations to Withstand Cyberthreats
Cyber resilience takes a broader approach, emphasizing the ability to withstand, recover and adapt to cyber incidents. The article explains the key components of cyber resilience, its importance and how organizations can implement it to build stronger defenses.
Cyber resilience takes a broader approach, emphasizing the ability to withstand, recover and adapt to cyber incidents. The article explains the key components of cyber resilience, its importance and how organizations can implement it to build stronger defenses.
伊朗宣布解封Google Play及WhatsApp并计划继续解除更多限制以逐渐开放互联网
1 year 3 months ago