Aggregator
The Future of Security Operations: Why Next-Gen SIEM is a Necessity
8 months 2 weeks ago
Transitioning to a modern SIEM model can achieve significant cost savings while enhancing security visibility and operational efficiency.
The post The Future of Security Operations: Why Next-Gen SIEM is a Necessity appeared first on Security Boulevard.
Ajit Sancheti
$74 млн исчезли, а токен растёт — абсурдный взлом UPCX
8 months 2 weeks ago
Инцидент обнажил парадокс криптомира.
在人工智能驱动的网络威胁形势下,企业备份策略的发展至关重要
8 months 2 weeks ago
安全客
CVE-2025-21994 | Linux Kernel up to 6.1.131/6.6.84/6.12.20/6.13.8 ksmbd parse_dcal num_aces allocation of resources
8 months 2 weeks ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.1.131/6.6.84/6.12.20/6.13.8. This vulnerability affects the function parse_dcal of the component ksmbd. The manipulation of the argument num_aces leads to allocation of resources.
This vulnerability was named CVE-2025-21994. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50597 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Component HTTP Server nxd_http_server.c integer underflow (TALOS-2024-2103)
8 months 2 weeks ago
A vulnerability classified as problematic has been found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. This affects an unknown part of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c of the component NetX Duo Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is uniquely identified as CVE-2024-50597. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50596 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Web Component HTTP Server nx_web_http_server.c integer underflow (TALOS-2024-2103)
8 months 2 weeks ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c of the component NetX Duo Web Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is handled as CVE-2024-50596. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50595 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Component HTTP Server nxd_http_server.c integer underflow (TALOS-2024-2102)
8 months 2 weeks ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c of the component NetX Duo Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is known as CVE-2024-50595. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50594 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Web Component HTTP Server nx_web_http_server.c integer underflow (TALOS-2024-2102)
8 months 2 weeks ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. It has been classified as problematic. Affected is an unknown function of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c of the component NetX Duo Web Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is traded as CVE-2024-50594. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50385 | STMicroelectronics X-CUBE-AZRT-H7RS NetX Component HTTP Server nxd_http_server.c cleanup (TALOS-2024-2097)
8 months 2 weeks ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL and classified as critical. This issue affects some unknown processing of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c of the component NetX Component HTTP Server. The manipulation leads to incomplete cleanup.
The identification of this vulnerability is CVE-2024-50385. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50384 | STMicroelectronics X-CUBE-AZRT-H7RS NetX Component HTTP Server nx_web_http_server.c cleanup (TALOS-2024-2097)
8 months 2 weeks ago
A vulnerability has been found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL and classified as critical. This vulnerability affects unknown code of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c of the component NetX Component HTTP Server. The manipulation leads to incomplete cleanup.
This vulnerability was named CVE-2024-50384. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-45064 | STMicroelectronics X-CUBE-AZRT-H7RS FileX Internal RAM Interface memory corruption (TALOS-2024-2096)
8 months 2 weeks ago
A vulnerability, which was classified as critical, was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL. This affects an unknown part of the component FileX Internal RAM Interface. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-45064. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
注意!HijackLoader 新增模块,恶意隐匿与反制分析能力大幅增强
8 months 2 weeks ago
安全客
CVE-2025-3123 | WonderCMS 3.5.0 Theme Installation/Plugin Installation installUpdateModuleAction unrestricted upload (Issue 330)
8 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleAction of the component Theme Installation/Plugin Installation. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2025-3123. The attack may be launched remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
The vendor explains, that "[t]he philosophy has always been, admin [...] bear responsibility to not install themes/plugins from untrusted sources."
vuldb.com
Police shuts down KidFlix child sexual exploitation platform
8 months 2 weeks ago
Kidflix, one of the largest platforms used to host, share, and stream child sexual abuse material (CSAM) on the dark web, was shut down on March 11 following a joint action coordinated by German law enforcement. [...]
Sergiu Gatlan
Akira
8 months 2 weeks ago
cohenido
Akira
8 months 2 weeks ago
cohenido
Submit #525101: WonderCMS 3.5.9 remote code execution [Accepted]
8 months 2 weeks ago
Submit #525101 / VDB-303014
cc1110
The Reality Behind Security Control Failures—And How to Prevent Them
8 months 2 weeks ago
Most orgs only discover their security controls failed after a breach. With OnDefend's continuous validation, you can test, measure, and prove your defenses work—before attackers exploit blind spots. [...]
Sponsored by OnDefend
How an Interdiction Mindset Can Help Win War on Cyberattacks
8 months 2 weeks ago
The US military and law enforcement learned to outthink insurgents. It's time for cybersecurity to learn to outsmart and outmaneuver threat actors with the same framework.
Mike McNerney