Aggregator
Фишинг без ссылок и вирусов: DocuSign стал новым оружием киберпреступников
1 year 4 months ago
Мошенники нашли новый способ красть деньги с помощью легитимных сервисов.
CVE-2015-2871 | Chiyu BF-660C net.htm read/modify access control (VU#360431)
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Chiyu BF-660C. This affects an unknown part of the file net.htm. The manipulation of the argument read/modify leads to improper access controls.
This vulnerability is uniquely identified as CVE-2015-2871. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
谷歌警告安卓系统中存在被主动利用的 CVE-2024-43093 漏洞
1 year 4 months ago
安全客
网络安全信息与动态周报2024年第44期(10月28日-11月3日)
1 year 4 months ago
本周,互联网网络安全态势整体评价为良。
黑客泄露 30 万份《麻省理工科技评论》杂志用户记录
1 year 4 months ago
安全客
CVE-2024-10920 | mariazevedo88 travels-java-api up to 5.0.1 JWT Secret JwtAuthenticationTokenFilter.java doFilterInternal hard-coded key
1 year 4 months ago
A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travelsjavaapi\filters\JwtAuthenticationTokenFilter.java of the component JWT Secret Handler. The manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is handled as CVE-2024-10920. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Невидимый Linux в Windows: хакеры маскируют атаки через QEMU
1 year 4 months ago
Внутри вашего компьютера может быть скрыта полноценная ОС, которая крадет вашу личность.
Decart представил Oasis: ИИ генерирует Minecraft без единой строчки кода
1 year 4 months ago
ИИ-модель способна удивить и насторожить игроков.
Submit #433458: mariazevedo88 travels-java-api <=travels-java-api5.0.1 arbitrary user impersonation [Accepted]
1 year 4 months ago
Submit #433458 / VDB-283316
susu199
Защитник или злодей? Как исследователь попал под суд из-за разглашения утечки
1 year 4 months ago
Действия города Колумбус раскрывают подводные камни этичного хакинга.
做兼职,搞副业 | 知识大陆「项目合伙人」招募
1 year 4 months ago
专业团队支持,网安人兼职做项目的首选,从0到1运营全程无忧!
fortify sca rules分析
1 year 4 months ago
Snowflake Hacking Suspect Arrested in Canada
1 year 4 months ago
A man suspected of breaching hundreds of Snowflake accounts has been arrested
INTERPOL Disrupts Over 22,000 Malicious Servers in Global Crackdown on Cybercrime
1 year 4 months ago
INTERPOL on Tuesday said it took down more than 22,000 malicious servers linked to various cyber threats as part of a global operation.
Dubbed Operation Synergia II, the coordinated effort ran from April 1 to August 31, 2024, targeting phishing, ransomware, and information stealer infrastructure.
"Of the approximately 30,000 suspicious IP addresses identified, 76 per cent were taken down and 59
The Hacker News
DDoS по подписке: как работал теневой бизнес Судана
1 year 4 months ago
Конец эпохи Anonymous Sudan раскрыл суданский след в глобальной паутине.
CVE-2024-10919 | didi Super-Jacoco 1.0 /cov/triggerUnitCover uuid os command injection
1 year 4 months ago
A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cov/triggerUnitCover. The manipulation of the argument uuid leads to os command injection.
This vulnerability is known as CVE-2024-10919. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Medusa Blog
1 year 4 months ago
cohenido
Submit #432689: didi super-jacoco 1.0 Command Injection [Accepted]
1 year 4 months ago
Submit #432689 / VDB-283315
gaogaostone
RansomHub
1 year 4 months ago
cohenido