Aggregator
CVE-2022-23457 | Oracle WebLogic Server 12.2.1.3.0/12.2.1.4.0/14.1.1.0.0 Centralized Third Party Jars path traversal (EUVD-2022-1678 / Nessus ID 242493)
AI Agent技能(Skill)详解:结构、使用与开发指南
VRP 2025 Year in Review
CVE-2020-35655 | Pillow up to 8.0.x SGI RLE Image SGIRleDecode buffer overflow (Nessus ID 236661 / WID-SEC-2022-1835)
CVE-2021-25287 | Pillow up to 8.1.x j2ku_graya_la out-of-bounds (Nessus ID 236661 / WID-SEC-2022-1835)
CVE-2021-25288 | Pillow up to 8.1.x j2ku_gray_i out-of-bounds (Nessus ID 236661 / WID-SEC-2022-1835)
CVE-2020-35653 | Pillow up to 8.0.x PCX File PcxDecode buffer overflow (Nessus ID 236661 / WID-SEC-2022-1835)
CVE-2023-50447 | Pillow up to 10.1.0 PIL.ImageMath.eval environment code injection (DLA 3724-1 / Nessus ID 210541)
CVE-2026-4519 | Python CPython up to 3.14.x API webbrowser.open input validation (ID 143930 / EUVD-2026-13712)
CVE-2026-34714 | Vim up to 9.2.0271 File os command injection (WID-SEC-2026-0904)
CVE-2026-34162 | labring FastGPT up to 4.14.7 Endpoint runTool missing authentication (EUVD-2026-17445)
CVE-2026-34200 | Nhost up to 1.40.x missing authentication (EUVD-2026-17452)
Pondurance MDR Essentials uses autonomous SOC to tackle AI-driven attacks
Pondurance announced MDR Essentials, MDR Essentials, an MDR service providing an autonomous SOC that reduces the time from threat detection to containment by 90%. Threat actors today use AI to attack at machine-speed, making it difficult for traditional cybersecurity solutions to accurately detect and contain cyber threats before they can become breaches. A recent paper from PwC notes that “in AI-driven SOCs, threats can be blocked in seconds, autonomously.” Pondurance’s MDR Essentials with the Kanati … More →
The post Pondurance MDR Essentials uses autonomous SOC to tackle AI-driven attacks appeared first on Help Net Security.
实锤!Lazarus是Axios供应链投毒幕后黑手
Атом пойман с поличным: был здесь и там одновременно. Квантовая физика перестала быть абстракцией
某公交系统漏洞分析
Bread 靶机渗透测试:利用 ACL/ACE 滥用攻击提权
Submit #780725: Shandong Hoteam Software Co., Ltd. Huatian Software InforCenter PLM <8.3.8 Remote Code Execution [Accepted]
Attack on axios software developer tool threatens widespread compromises
Researchers at numerous firms are sounding warnings about the supply-chain attack on an open-source project with 100 million weekly downloads.
The post Attack on axios software developer tool threatens widespread compromises appeared first on CyberScoop.