Aggregator
【安全圈】黑客伪装成 Google 招聘人员窃取 Gmail 登录信息
Apple urges users to update iPhone and Mac to patch font bug
Apple urges users to update iPhone and Mac to patch font bug
AI Tops Cybersecurity Investment Priorities, PwC Finds
CVE-2025-40928 | MLEHMANN JSON::XS up to 4.03 on Perl heap-based overflow (Nessus ID 264365 / WID-SEC-2025-2171)
Top Data Breaches In September 2025
CVE-2025-41246 | VMware Tools prior 12.5.4/13.0.5.0 on Windows authorization (EUVD-2025-31579 / WID-SEC-2025-2153)
CVE-2025-41245 | VMware Aria Operations up to 8.18.4 insecure default initialization of resource (VMSA-2025-0015 / WID-SEC-2025-2153)
CVE-2023-40546 | rhboot shim up to 15.7 on ARM mok mok.c mirror_one_esl format string (EUVD-2023-45117 / Nessus ID 215406)
CVE-2023-40548 | rhboot shim on 32-bit verify_sbat_section heap-based overflow (EUVD-2023-45119 / Nessus ID 215974)
CVE-2025-10725 | Red Hat OpenShift AI ClusterRole permission (EUVD-2025-31761)
CVE-2023-40551 | shim 3.8.15/8 MZ Binary Format out-of-bounds (EUVD-2023-45122 / Nessus ID 232680)
CVE-2023-40549 | rhboot shim shim.c verify_buffer_authenticode out-of-bounds (EUVD-2023-45120 / Nessus ID 215357)
CVE-2023-40550 | rhboot shim verify_buffer_sbat out-of-bounds (EUVD-2023-45121 / Nessus ID 215335)
CVE-2025-57852 | Red Hat OpenShift AI /etc/passwd default permission (EUVD-2025-31743)
Red Hat Openshift AI Service Vulnerability Allow Attackers to Take Control of the Infrastructure
Red Hat published security advisory CVE-2025-10725, detailing an Important severity flaw in the OpenShift AI Service that could enable low-privileged attackers to elevate their permissions to full cluster administrator and compromise the entire platform. With a CVSS v3 base score of 9.9, this vulnerability poses a critical risk for organizations leveraging Red Hat OpenShift AI […]
The post Red Hat Openshift AI Service Vulnerability Allow Attackers to Take Control of the Infrastructure appeared first on Cyber Security News.
New Battering RAM Attack Bypasses Latest Defenses on Intel and AMD Cloud Processors
Confidential computing promised to protect sensitive workloads in the public cloud. Yet a new low-cost hardware attack, Battering RAM, demonstrates that even up-to-date memory-encryption schemes on Intel and AMD processors can be defeated with a simple interposer costing under 50 dollars. Modern servers use DDR4 DRAM with hardware-backed encryption, such as Intel SGX’s Total Memory Encryption (TME) […]
The post New Battering RAM Attack Bypasses Latest Defenses on Intel and AMD Cloud Processors appeared first on Cyber Security News.