Aggregator
A Threat Actor Claims to be Selling Access to an Unidentified Company
1 year 3 months ago
A Threat Actor Claims to be Selling Access to an Unidentified Company
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-12902 | Global Wisdom Software ANCHOR up to 2.5.9.4/2.7.2.3 default credentials
1 year 3 months ago
A vulnerability was found in Global Wisdom Software ANCHOR up to 2.5.9.4/2.7.2.3. It has been classified as critical. This affects an unknown part. The manipulation leads to use of default credentials.
This vulnerability is uniquely identified as CVE-2024-12902. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
От смартфонов к киборгам: как 31-летний гений перевернул рынок робототехники
1 year 3 months ago
«Тысяча единиц уже готова, ещё миллион на подходе».
The Top 5 Kubernetes CVEs of 2024: Have You Patched Them Yet?
1 year 3 months ago
Keeping up to date with critical vulnerabilities related to Kubernetes can be challenging for a variety of reasons. The biggest one may be related to Kubernetes itself; it’s a complex and rapidly evolving platform, with regular updates and new features being introduced regularly (not to mention updates to APIs and add-ons). Kubernetes environments are scalable and dynamic, so sometimes vulnerabilities can have a wide-ranging impact. Staying informed about the latest vulnerabilities impacting the Kubernetes ecosystem can be difficult, in part because of the diverse attack surface K8s presents.
The post The Top 5 Kubernetes CVEs of 2024: Have You Patched Them Yet? appeared first on Security Boulevard.
Stevie Caldwell
空天地一体化综合业务网全国重点实验室第二十六期开放课题
1 year 3 months ago
申请受理截止日期:2025年2月23日
本田日产计划到 2026 年实现经营合并
1 year 3 months ago
本田和日产周一宣布全面启动经营合并磋商,力争 2026 年 8 月成立把两家车企纳入旗下的持股公司。与日产组成企业联盟的三菱汽车公司将在 2025 年 1 月底前后决定是否加入。若三家车企成功合并,那么合计销量将超过 800 万辆,位居全球第三。此举旨在调整生产以及技术互补。本田与日产拥有的品牌将持续下去。本田主导合并,将指定持股公司的社长和过半数董事。合并之后的规模将仅次于 2023 年全球销量达 1123 万辆的丰田集团、以及 923 万辆的德国大众(VW)集团。本田和日产将利用这一规模优势,提高纯电动汽车(EV)开发的投资效率,与在EV市场上领先的美国和中国新兴势力抗衡。
A Threat Actor Claims to be Selling RDP Access to an Unidentified USA-based Manufacturing Company
1 year 3 months ago
A Threat Actor Claims to be Selling RDP Access to an Unidentified USA-based Manufacturing Company
Dark Web Informer - Cyber Threat Intelligence
CVE-2023-5269 | SourceCodester Best Courier Management System 1.0 GET Parameter parcel_list.php s sql injection
1 year 3 months ago
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file parcel_list.php of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection.
This vulnerability is traded as CVE-2023-5269. Access to the local network is required for this attack. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-5270 | SourceCodester Best Courier Management System 1.0 view_parcel.php id sql injection
1 year 3 months ago
A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view_parcel.php. The manipulation of the argument id leads to sql injection.
This vulnerability is known as CVE-2023-5270. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-5272 | SourceCodester Best Courier Management System 1.0 GET Parameter edit_parcel.php id sql injection
1 year 3 months ago
A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. This affects an unknown part of the file edit_parcel.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection.
This vulnerability is uniquely identified as CVE-2023-5272. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-6898 | SourceCodester Best Courier Management System 1.0 manage_user.php id sql injection
1 year 3 months ago
A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2023-6898. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-2156 | SourceCodester Best POS Management System 1.0 admin_class.php img sql injection
1 year 3 months ago
A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. Affected is an unknown function of the file admin_class.php. The manipulation of the argument img leads to sql injection.
This vulnerability is traded as CVE-2024-2156. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-31487 | Fortinet FortiSandbox up to 4.4.4 HTTP Request path traversal (FG-IR-24-060)
1 year 3 months ago
A vulnerability has been found in Fortinet FortiSandbox up to 4.4.4 and classified as critical. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to path traversal.
This vulnerability was named CVE-2024-31487. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23671 | Fortinet FortiSandbox up to 4.0.4/4.2.6/4.4.3 HTTP Request path traversal (FG-IR-23-454)
1 year 3 months ago
A vulnerability has been found in Fortinet FortiSandbox up to 4.0.4/4.2.6/4.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-23671. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-47541 | Fortinet FortiSandbox up to 4.4.2 CLI path traversal (FG-IR-23-416)
1 year 3 months ago
A vulnerability was found in Fortinet FortiSandbox up to 4.4.2 and classified as critical. Affected by this issue is some unknown functionality of the component CLI. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2023-47541. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-47540 | Fortinet FortiSandbox up to 3.0.7/3.2.4/4.0.5/4.2.6/4.4.2 CLI os command injection (FG-IR-23-411)
1 year 3 months ago
A vulnerability has been found in Fortinet FortiSandbox up to 3.0.7/3.2.4/4.0.5/4.2.6/4.4.2 and classified as critical. This vulnerability affects unknown code of the component CLI. The manipulation leads to os command injection.
This vulnerability was named CVE-2023-47540. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21756 | Fortinet FortiSandbox up to 4.0.4/4.2.6/4.4.3 Requests os command injection (FG-IR-23-489)
1 year 3 months ago
A vulnerability was found in Fortinet FortiSandbox up to 4.0.4/4.2.6/4.4.3 and classified as critical. This issue affects some unknown processing of the component Requests Handler. The manipulation leads to os command injection.
The identification of this vulnerability is CVE-2024-21756. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21755 | Fortinet FortiSandbox up to 4.0.4/4.2.6/4.4.3 Requests os command injection (FG-IR-23-489)
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in Fortinet FortiSandbox up to 4.0.4/4.2.6/4.4.3. This issue affects some unknown processing of the component Requests Handler. The manipulation leads to os command injection.
The identification of this vulnerability is CVE-2024-21755. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
科学家在量子实验中观察到“负时间”
1 year 3 months ago
当光子穿过原子,原子会吸收部分光子,短暂的处于激发态,之后恢复正常。多伦多大学的一个研究团队试图测量原子处于激发态的时间,他们称这个时间是负值,意味着持续的时间小于零。根据发表在预印本 arXiv 尚未通过同行审议的论文,研究团队声称通过量子实验证明了负时间的存在。研究人员称这一结果凸显了量子力学的奇特,但并不意味着对时间理解的根本转变。研究结果引发了很多质疑。