Aggregator
山石安研院2024年度代表性原创0day漏洞
8 months 1 week ago
山石网科安全技术研究院2024年度代表性原创通用漏洞国内版
山石安研院2024年度代表性原创0day漏洞
8 months 1 week ago
在过去的一年中安全技术研究院三大实验室挖掘了无数的各类原创0day漏洞,帮助国内外各大厂商修复了众多的高危及严重漏洞,由于CNVD的漏洞最高级别只是高危,所以有些超危、严重的漏洞都算为高危了。这里仅以
CVE-2024-3393 | Palo Alto Networks Cloud NGFW/PAN-OS DNS Security unusual condition
8 months 1 week ago
A vulnerability was found in Palo Alto Networks Cloud NGFW and PAN-OS. It has been rated as problematic. This issue affects some unknown processing of the component DNS Security. The manipulation leads to improper check for unusual conditions.
The identification of this vulnerability is CVE-2024-3393. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Microsoft, Ping, Okta Dominate Access Management Gartner MQ
8 months 1 week ago
Access Management Leaders Remain Unchanged as Customer Identity Cases Proliferate
Advances in customer identity around better user experience, strong authentication, and centralized identity processes have driven rapid growth in the access management market. The space by grew 17.6% to $5.85 billion in 2023 as organizations increasing look to replace homegrown CIAM solutions.
Advances in customer identity around better user experience, strong authentication, and centralized identity processes have driven rapid growth in the access management market. The space by grew 17.6% to $5.85 billion in 2023 as organizations increasing look to replace homegrown CIAM solutions.
US CISA Issues Final Cyber Rules for Restricted Bulk Data
8 months 1 week ago
Cyber Defense Agency Aims to Bolster Protections Against Chinese Intrusion
The Cybersecurity and Infrastructure Security Agency is issuing final rules to safeguard U.S. sensitive data from potential Chinese intrusions, requiring Americans involved in restricted transactions with Chinese entities to adopt stringent cybersecurity measures.
The Cybersecurity and Infrastructure Security Agency is issuing final rules to safeguard U.S. sensitive data from potential Chinese intrusions, requiring Americans involved in restricted transactions with Chinese entities to adopt stringent cybersecurity measures.
Japanese Businesses Hit By a Surge In DDoS Attacks
8 months 1 week ago
DDoS Attacks Primarily Target Logistics, Government and Financial Entities
A spate of distributed denial-of-service attacks during the end-of-year holiday season disrupted operations at multiple Japanese organizations, including the country's largest airline, wireless carrier and prominent banks. The effect of the attacks has been temporary.
A spate of distributed denial-of-service attacks during the end-of-year holiday season disrupted operations at multiple Japanese organizations, including the country's largest airline, wireless carrier and prominent banks. The effect of the attacks has been temporary.
How to approach getting into a Windows account without a pin, without erasing all the credentials?
8 months 1 week ago
用 GPT 总结 2024 年的人,全破防了
8 months 1 week ago
我的 2024 年,让 GPT 彻底看透了。作者 | Li Yuan编辑 | 靖宇2024 年过去了,你有被各种软件的年终总结刷屏吗?有的软件的总结对你来说无关痛痒:来到某鱼的第七年,卖出了 0 元的
用 GPT 总结 2024 年的人,全破防了
8 months 1 week ago
我的 2024 年,让 GPT 彻底看透了。
Dental Practice Pays State in Alleged Data Breach 'Cover Up'
8 months 1 week ago
Indiana Attorney General Fines Westend Dental $350K in 2020 Ransomware Hack
An Indiana dental practice agreed to pay the state $350,000 and implement a long list of data security improvements following an alleged 2020 ransomware breach "cover up" that came to light when state regulators investigated a patient complaint about unfulfilled requests for dental X-rays.
An Indiana dental practice agreed to pay the state $350,000 and implement a long list of data security improvements following an alleged 2020 ransomware breach "cover up" that came to light when state regulators investigated a patient complaint about unfulfilled requests for dental X-rays.
Microsoft, Ping, Okta Dominate Access Management Gartner MQ
8 months 1 week ago
Access Management Leaders Remain Unchanged as Customer Identity Cases Proliferate
Advances in customer identity around better user experience, strong authentication, and centralized identity processes have driven rapid growth in the access management market. The space by grew 17.6% to $5.85 billion in 2023 as organizations increasing look to replace homegrown CIAM solutions.
Advances in customer identity around better user experience, strong authentication, and centralized identity processes have driven rapid growth in the access management market. The space by grew 17.6% to $5.85 billion in 2023 as organizations increasing look to replace homegrown CIAM solutions.
US CISA Issues Final Cyber Rules for Restricted Bulk Data
8 months 1 week ago
Cyber Defense Agency Aims to Bolster Protections Against Chinese Intrusion
The Cybersecurity and Infrastructure Security Agency is issuing final rules to safeguard U.S. sensitive data from potential Chinese intrusions, requiring Americans involved in restricted transactions with Chinese entities to adopt stringent cybersecurity measures.
The Cybersecurity and Infrastructure Security Agency is issuing final rules to safeguard U.S. sensitive data from potential Chinese intrusions, requiring Americans involved in restricted transactions with Chinese entities to adopt stringent cybersecurity measures.
Japanese Businesses Hit By a Surge In DDoS Attacks
8 months 1 week ago
DDoS Attacks Primarily Target Logistics, Government and Financial Entities
A spate of distributed denial-of-service attacks during the end-of-year holiday season disrupted operations at multiple Japanese organizations, including the country's largest airline, wireless carrier and prominent banks. The effect of the attacks has been temporary.
A spate of distributed denial-of-service attacks during the end-of-year holiday season disrupted operations at multiple Japanese organizations, including the country's largest airline, wireless carrier and prominent banks. The effect of the attacks has been temporary.
CVE-2024-43767 | Google Android 12/12L/13/14/15 SkBlurMaskFilterImpl.cpp prepare_to_draw_into_mask heap-based overflow
8 months 1 week ago
A vulnerability, which was classified as critical, has been found in Google Android 12/12L/13/14/15. Affected by this issue is the function prepare_to_draw_into_mask of the file SkBlurMaskFilterImpl.cpp. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2024-43767. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43077 | Google Android devicemem_server.c DevmemValidateFlags out-of-bounds write
8 months 1 week ago
A vulnerability was found in Google Android. It has been declared as critical. Affected by this vulnerability is the function DevmemValidateFlags of the file devicemem_server.c. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2024-43077. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43762 | Google Android 12/12L/13/14/15 Local Privilege Escalation
8 months 1 week ago
A vulnerability classified as problematic has been found in Google Android 12/12L/13/14/15. This affects an unknown part. The manipulation leads to Local Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-43762. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43764 | Google Android 13/14 Lock Screen ClipboardListener.java onPrimaryClipChanged improper authentication
8 months 1 week ago
A vulnerability classified as critical was found in Google Android 13/14. This vulnerability affects the function onPrimaryClipChanged of the file ClipboardListener.java of the component Lock Screen. The manipulation leads to improper authentication.
This vulnerability was named CVE-2024-43764. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43768 | Google Android 12/12L/13/14/15 SkDeflate.cpp skia_alloc_func out-of-bounds write
8 months 1 week ago
A vulnerability, which was classified as critical, was found in Google Android 12/12L/13/14/15. Affected is the function skia_alloc_func of the file SkDeflate.cpp. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2024-43768. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43769 | Google Android 13/14/15 CloudDpc PackageManagerService.java isPackageDeviceAdmin default permission
8 months 1 week ago
A vulnerability has been found in Google Android 13/14/15 and classified as problematic. Affected by this vulnerability is the function isPackageDeviceAdmin of the file PackageManagerService.java of the component CloudDpc. The manipulation leads to incorrect default permissions.
This vulnerability is known as CVE-2024-43769. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com