Aggregator
【安全圈】假冒LockBit,勒索软件滥用 AWS S3窃取数据
1 year 5 months ago
【安全圈】苹果在iOS 18.2版中允许欧盟用户删除AppStore和照片等核心应用
1 year 5 months ago
【安全圈】苹果、特斯拉均受影响,新型漏洞迫使GPU无限循环,直至系统崩溃
1 year 5 months ago
CVE-2003-1308 | fvwm 2.4.17/2.5.8 fvwm-menu-directory privileges management (EDB-23414 / BID-9161)
1 year 5 months ago
A vulnerability was found in fvwm 2.4.17/2.5.8. It has been declared as problematic. This vulnerability affects unknown code of the file fvwm-menu-directory. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2003-1308. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DEF CON 32 – AppSec Village – Defeating Secure Code Review GPT Hallucinations
1 year 5 months ago
Authors/Presenters:Wang Zhilong, Xinzhi Luo
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their timely DEF CON 32 erudite content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – AppSec Village – Defeating Secure Code Review GPT Hallucinations appeared first on Security Boulevard.
Marc Handelman
【知道创宇404实验室】警惕CVE-2024-47575针对Fortinet FortiManager的认证绕过漏洞
1 year 5 months ago
How we managed Aurora Serverless V2 Idle connections in RDS Proxy and saved RDS costs by 50%
1 year 5 months ago
The post How we managed Aurora Serverless V2 Idle connections in RDS Proxy and saved RDS costs by 50% appeared first on Strobes Security.
The post How we managed Aurora Serverless V2 Idle connections in RDS Proxy and saved RDS costs by 50% appeared first on Security Boulevard.
strobes
CVE-2021-20193 | GNU Tar up to 1.33 Input File src/list.c memory leak
1 year 5 months ago
A vulnerability was found in GNU Tar up to 1.33. It has been rated as problematic. Affected by this issue is some unknown functionality of the file src/list.c of the component Input File Handler. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2021-20193. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-43701 | ARM Compiler 5 Installation default permission
1 year 5 months ago
A vulnerability has been found in ARM Compiler 5, Compiler 6, Compiler for Embedded, Compiler for Embedded FuSa, Compiler for Linux, Development Studio, Development Studio Morello Edition, Forge, Mobile Studio, DS-5 Development Studio, Fast Models, GNU Toolchain, Installer Vulnerabilities, Keil MDK and Socrates and classified as critical. Affected by this vulnerability is an unknown functionality of the component Installation. The manipulation leads to incorrect default permissions.
This vulnerability is known as CVE-2022-43701. The attack needs to be approached locally. There is no exploit available.
vuldb.com
优秀创新成果!360安全大模型再获权威肯定
1 year 5 months ago
360安全大模型获2024中国国际数字经济博览会优秀创新成果
石家庄市政府与360达成战略合作 树立全国数字经济创新发展标杆
1 year 5 months ago
石家庄市政府与360携手 助推河北省数字安全和人工智能产业升级
'Shift Left' Gets Pushback, Triggers Security Soul Searching
1 year 5 months ago
A government report's criticism of the 100x metric often used to justify fixing software earlier in development fuels a growing debate over pushing responsibility for secure code onto developers.
Robert Lemos, Contributing Writer
流程速览 | “工业征途 安全守护”工业领域数据安全实践与创新论坛
1 year 5 months ago
点击查看,预约参会。
中国网络安全市场营收攀升背后的驱动力与待解难题
1 year 5 months ago
Gartner预测安全软件、安全服务和网络安全领域将迎来显著增长。
Intelligence Insights: October 2024
1 year 5 months ago
LummaC2 lurks thanks to PowerShell pasting in this month's edition of Intelligence Insights
The Red Canary Team
Ireland fines LinkedIn €310 million over targeted advertising
1 year 5 months ago
LinkedIn received a €310 million fine from the Irish Data Protection Commission for violating European Union's law related to the processing of personal data for behavioral analysis and targeted advertising. [...]
Bill Toulas
CVE-2018-1000021 | Git up to 2.15.1 Client input validation
1 year 5 months ago
A vulnerability classified as critical has been found in Git up to 2.15.1. This affects an unknown part of the component Client. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2018-1000021. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Cisco fixes VPN DoS flaw discovered in password spray attacks
1 year 5 months ago
Cisco fixed a denial of service flaw in its Cisco ASA and Firepower Threat Defense (FTD) software, which was discovered during large-scale brute force attacks against Cisco VPN devices in April. [...]
Bill Toulas
豆包MarsCode Agent 登顶 SWE-bench Lite 评测集
1 year 5 months ago