Aggregator
В поезд — по лицу, в самолёт — по голосу. Минтранс начинает испытания биометрии
8 months 3 weeks ago
РЖД начинает проработку технологии, но не торопится отказываться от документов.
WMCTF2025
8 months 3 weeks ago
Name: WMCTF2025 (an WMCTF event.)
Date: Sept. 20, 2025, 2 a.m. — 21 Sept. 2025, 02:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://wmctf.wm-team.cn/
Rating weight: 80.00
Event organizers: W&M
Date: Sept. 20, 2025, 2 a.m. — 21 Sept. 2025, 02:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://wmctf.wm-team.cn/
Rating weight: 80.00
Event organizers: W&M
ATLA Opening Date CTF
8 months 3 weeks ago
Name: ATLA Opening Date CTF (an ATLA Opening Date CTF event.)
Date: Sept. 20, 2025, 5 a.m. — 20 Sept. 2025, 13:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Kyrgyzstan, Bishkek
Offical URL: https://ctf.atlabyte.com/
Rating weight: 0
Event organizers: ATLA CTF
Date: Sept. 20, 2025, 5 a.m. — 20 Sept. 2025, 13:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Kyrgyzstan, Bishkek
Offical URL: https://ctf.atlabyte.com/
Rating weight: 0
Event organizers: ATLA CTF
Holmes CTF 2025
8 months 3 weeks ago
Name: Holmes CTF 2025 (an Hack The Box CTF event.)
Date: Sept. 22, 2025, 1 p.m. — 26 Sept. 2025, 19:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.hackthebox.com/event/details/holmes-ctf-2025-2536
Rating weight: 24.00
Event organizers: Hack The Box
Date: Sept. 22, 2025, 1 p.m. — 26 Sept. 2025, 19:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://ctf.hackthebox.com/event/details/holmes-ctf-2025-2536
Rating weight: 24.00
Event organizers: Hack The Box
InfiniteCTF Qualifiers
8 months 3 weeks ago
Name: InfiniteCTF Qualifiers (an InfiniteCTF event.)
Date: Sept. 27, 2025, 7 p.m. — 28 Sept. 2025, 03:00 UTC [add to calendar]
Format: Attack-Defense
On-line
Offical URL: https://register.redteamassociation.com/
Rating weight: 0.00
Event organizers: Red Team Association
Date: Sept. 27, 2025, 7 p.m. — 28 Sept. 2025, 03:00 UTC [add to calendar]
Format: Attack-Defense
On-line
Offical URL: https://register.redteamassociation.com/
Rating weight: 0.00
Event organizers: Red Team Association
【安全圈】黑客滥用 Milesight 路由器向欧洲用户发送钓鱼短信
8 months 3 weeks ago
关键词违反网络安全法一、上海某跨国公司违规出境用户信息案2025年5月,某国际时尚品牌被曝数据泄露,其中国公司
【安全圈】微软确认 Outlook 桌面版出现严重故障,导致邮件客户端无法启动
8 months 3 weeks ago
关键词违反网络安全法一、上海某跨国公司违规出境用户信息案2025年5月,某国际时尚品牌被曝数据泄露,其中国公司
【安全圈】Red Hat 疑遭重大数据泄露:黑客声称窃取 28,000 私有仓库
8 months 3 weeks ago
关键词违反网络安全法一、上海某跨国公司违规出境用户信息案2025年5月,某国际时尚品牌被曝数据泄露,其中国公司
【安全圈】OpenAI 正在测试敏感话题安全路由机制,或在极端情况下报警
8 months 3 weeks ago
关键词违反网络安全法一、上海某跨国公司违规出境用户信息案2025年5月,某国际时尚品牌被曝数据泄露,其中国公司
How to Close Threat Detection Gaps: Your SOC's Action Plan
8 months 3 weeks ago
Running a SOC often feels like drowning in alerts. Every morning, dashboards light up with thousands of signals; some urgent, many irrelevant. The job is to find the real threats fast enough to keep cases from piling up, prevent analyst burnout, and maintain client or leadership confidence.
The toughest challenges, however, aren’t the alerts that can be dismissed quickly, but the ones that hide
The Hacker News
Android spyware campaigns impersonate Signal and ToTok messengers
8 months 3 weeks ago
Two new spyware campaigns that researchers call ProSpy and ToSpy lured Android users with fake upgrades or plugins for the Signal and ToTok messaging apps to steal sensitive data. [...]
Bill Toulas
cby与scz的一次对话
8 months 3 weeks ago
她甚至不知道我在开心什么
Expired US Cyber Law Puts Data Sharing and Threat Response at Risk
8 months 3 weeks ago
Experts argued that the lapse of the Cybersecurity Information Sharing Act could have far-reaching consequences in US national cyber defenses
Подумал о товаре — увидел рекламу. Глава Instagram объяснил «магию» точного таргетинга
8 months 3 weeks ago
Meta нашла замену микрофону — и это куда страшнее.
Cybercrime group claims to have breached Red Hat ‘s private GitHub repositories
8 months 3 weeks ago
The cybercrime group calling itself the Crimson Collective claimed to have compromised Red Hat ‘s private GitHub repositories. The Crimson Collective claimed it had stolen 570GB from Red Hat ’s private GitHub repositories, including 28,000 projects and approximately 800 Customer Engagement Reports (CERs) with sensitive network data. CERs often contain sensitive info, including infrastructure details, […]
Pierluigi Paganini
CVE-2025-54468 | SUSE Rancher up to 2.9.11/2.10.9/2.11.5/2.12.1 Endpoint /meta/proxy information disclosure (GHSA-mjcp-rj3c-36fr)
8 months 3 weeks ago
A vulnerability was found in SUSE Rancher up to 2.9.11/2.10.9/2.11.5/2.12.1. It has been classified as problematic. Affected by this issue is some unknown functionality of the file /meta/proxy of the component Endpoint. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2025-54468. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-40645 | ViDay HTTP GET Request /api/reserva/web/clients phone information disclosure
8 months 3 weeks ago
A vulnerability was found in ViDay and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /api/reserva/web/clients of the component HTTP GET Request Handler. Executing manipulation of the argument phone can lead to information disclosure.
This vulnerability is tracked as CVE-2025-40645. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-40646 | ViDay information disclosure
8 months 3 weeks ago
A vulnerability has been found in ViDay and classified as problematic. Affected is an unknown function. Performing manipulation results in information disclosure.
This vulnerability is identified as CVE-2025-40646. The attack can only be performed from the local network. There is not any exploit available.
vuldb.com
CVE-2025-46741 | Schweitzer Engineering Laboratories SEL Blueframe OS up to 1.11.x privileges management (EUVD-2025-14293)
8 months 3 weeks ago
A vulnerability identified as critical has been detected in Schweitzer Engineering Laboratories SEL Blueframe OS up to 1.11.x. The impacted element is an unknown function. This manipulation causes improper privilege management.
The identification of this vulnerability is CVE-2025-46741. The attack can only be executed locally. There is no exploit available.
You should upgrade the affected component.
vuldb.com