Aggregator
专家分析韩国坠机未必与鸟击有关
8 months 1 week ago
美国和英国情报部门正准备对俄罗斯在叙利亚的基地发动恐怖袭击
8 months 1 week ago
2024 常用产品
8 months 1 week ago
列举一些 2024 年我常用的小东西。
2024 常用产品
8 months 1 week ago
列举一些 2024 年我常用的小东西。手机有俩:- Samsung S24 Ultra。这是今年安卓机里我最喜欢的,用过其他几款比如 Pixel 9 Pro Fold、Nothing 2a 等,各有缺
SECURITY AFFAIRS MALWARE NEWSLETTER – ROUND 26
8 months 1 week ago
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape. Now You See Me, Now You Don’t: Using LLMs to Obfuscate Malicious JavaScript Analyzing Malicious Intent in Python Code: A Case Study DigiEver Fix That IoT Thing! Botnets Continue to Target Aging D-Link Vulnerabilities OtterCookie, […]
Pierluigi Paganini
SECURITY AFFAIRS MALWARE NEWSLETTER – ROUND 26
8 months 1 week ago
SECURITY AFFAIRS MALWARE NEWSLETTE
大众 80 万电动汽车车主的行踪短暂暴露在互联网上
8 months 1 week ago
本周举行的混沌计算机俱乐部 38C3 会议披露了大众汽车收集的 80 万电动汽车车主行踪信息暴露在互联网上数个月之久。这些信息保存在亚马逊 AWS 服务中,但安全性很差,信息暴露了车主汽车
大众 80 万电动汽车车主的行踪短暂暴露在互联网上
8 months 1 week ago
本周举行的混沌计算机俱乐部 38C3 会议披露了大众汽车收集的 80 万电动汽车车主行踪信息暴露在互联网上数个月之久。这些信息保存在亚马逊 AWS 服务中,但安全性很差,信息暴露了车主汽车精确的 GPS 位置、电池状态和习惯(用报告者的话是汽车是否曾在妓院前停留都一目了然)。受影响的车主包括了德国政客、企业家、汉堡警方,甚至可能还有情报部门的间谍。软件 bug 是在 2024 年夏天引入的,一位匿名告密者发现了问题,报告给了混沌计算机俱乐部,混沌计算机俱乐部立即报告给了德国政府以及大众旗下的软件开发商 Cariad。Cariad 迅速修复了问题,堵上了对其客户数据未经授权的访问漏洞。
威胁情报周报(12.23~12.29)
8 months 1 week ago
一周情报速览~
威胁情报周报(12.23~12.29)
8 months 1 week ago
一周情报速览~
威胁情报周报(12.23~12.29)
8 months 1 week ago
一周情报速览~
Computer Forensics Masters Programs in California
8 months 1 week ago
CVE-2011-5195 | Public Knowledge Project Open Conference Systems up to 2.1.1-1 cross-site request forgery (EDB-18266 / SA47330)
8 months 1 week ago
A vulnerability was found in Public Knowledge Project Open Conference Systems up to 2.1.1-1 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is handled as CVE-2011-5195. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-3078 | Linux Kernel 2.6.16.9 xfs_ioc_fsgetxattr resource management (Bug 630804 / Nessus ID 50807)
8 months 1 week ago
A vulnerability classified as problematic was found in Linux Kernel 2.6.16.9. Affected by this vulnerability is the function xfs_ioc_fsgetxattr. The manipulation leads to improper resource management.
This vulnerability is known as CVE-2010-3078. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2010-2667 | VMware Studio 2.0 privileges management (Nessus ID 52013 / XFDB-60350)
8 months 1 week ago
A vulnerability classified as critical has been found in VMware Studio 2.0. Affected is an unknown function. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2010-2667. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2010-2914 | nessus Web Server plugin 1.2.4 cross site scripting (Nessus ID 47833 / SBV-26633)
8 months 1 week ago
A vulnerability was found in nessus Web Server plugin 1.2.4. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2010-2914. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2010-2798 | Linux Kernel 2.6.16.9 gfs2_rename numeric error (USN-1000-1 / Nessus ID 50925)
8 months 1 week ago
A vulnerability classified as critical has been found in Linux Kernel 2.6.16.9. This affects the function gfs2_rename. The manipulation leads to numeric error.
This vulnerability is uniquely identified as CVE-2010-2798. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2010-2521 | Linux Kernel 2.6.23 memory corruption (RHSA-2010:0907 / Nessus ID 63960)
8 months 1 week ago
A vulnerability was found in Linux Kernel 2.6.23. It has been rated as very critical. This issue affects some unknown processing. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2010-2521. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2010-2599 | RIM Blackberry Software up to 4.7.0 denial of service (XFDB-64622 / SBV-29209)
8 months 1 week ago
A vulnerability was found in RIM Blackberry Software up to 4.7.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2010-2599. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com