Aggregator
朝鲜黑客成功窃取DMM Bitcoin价值3.08亿美元比特币
8 months 2 weeks ago
01日本和美国确认朝鲜黑客为盗窃幕后黑手2024年5月,朝鲜黑客从日本加密货币公司DMM Bitcoin窃取了价值3.08亿美元的比特币。日本和美国当局已确认此次盗窃与TraderTraitor威胁活
“顶流”带货是真是假?美亚内容鉴真平台帮你守住钱袋子!
8 months 2 weeks ago
企业资讯
Submit #462387: OVERTEK OT-E801G - OTE801G65.1.1.0 V1.1.0 Remote Code Execution [Accepted]
8 months 2 weeks ago
Submit #462387 / VDB-289378
c4ng4c3ir0
От фишинговых писем до разрушения IT-систем: Paper Werewolf атакует
8 months 2 weeks ago
Эксперты фиксируют новый всплеск активности известного кластера.
CVE-2024-12984 | Amcrest IP2M-841B up to 20241211 Web Interface /web_caps/webCapsConfig information disclosure
8 months 2 weeks ago
A vulnerability classified as problematic has been found in Amcrest IP2M-841B, IP2M-841W, IPC-IP2M-841B, IPC-IP3M-943B, IPC-IP3M-943S, IPC-IP3M-HX2B and IPC-IPM-721S up to 20241211. This affects an unknown part of the file /web_caps/webCapsConfig of the component Web Interface. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-12984. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
It is recommended to apply restrictive firewalling.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
一周网安优质PDF资源推荐丨FreeBuf知识大陆
8 months 2 weeks ago
我们精选了本周知识大陆公开发布的10条优质资源,让我们一起看看吧。
Личное в публичное: как простой вызов такси оборачивается потерей данных
8 months 2 weeks ago
Человеческий фактор снова стал причиной цифрового коллапса.
Submit #461109: Amcrest IP2M-841W, IPC-IP3M-HX2B, IPC-IP2M-841B, IPC-IPM-721S, IPC-IP3M-943B, IPC-IP3M-943S, IP2M-841B N/A Information Disclosure [Accepted]
8 months 2 weeks ago
Submit #461109 / VDB-289377
netsecfish
国投智能(美亚柏科)在第五届中国人工智能大赛斩获三个赛道A级证书
8 months 2 weeks ago
企业资讯
国投智能(美亚柏科)在第五届中国人工智能大赛斩获三个赛道A级证书
8 months 2 weeks ago
12月20日,第五届中国人工智能大赛成果发布会在厦召开,国投智能股份董事长滕达应邀出席。公司人工智能团队表现突出,在“大模型安全攻防赛”“AIGC视频检测赛”“人工智能赋能政府服务场景能力验证赛”三个赛道中荣获最高等级A级证书(金奖)。
滕达董事长与获奖团队代表合影
美亚柏科智慧安防事业部总经理黄仝宇博士在下午举行的“人工智能赋能行业应用创新论坛”上作《AI助力打造公共安全新质生产力》主题演讲。他表示,AI大模型出现和落地给安防行业带来了新的发展机遇,它将引领智慧安防的新未来。AI大模型赋能安防,使安防系统具备强大的理解和分析能力,大幅提升现有安防系统的智能化水平和效率,并拓展安防应用的深度和广度,为发展安防新质生产力赋能。
今年9月,在国家互联网信息办公室、公安部指导下,厦门市人民政府主办的第五届中国人工智能大赛正式启动,围绕人工智能安全治理和创新发展两大主线设置了赛题。作为网络空间安全与社会治理领域国家队,国投智能2017年成立AI研发中心,为了应对利用人工智能技术可能带来的安全问题,2019年针对深度合成技术又特别成立专项研究团队,2024年,公司提出“All in AI”战略,整合各产品线的人工智能研发力量,新组建人工智能研究院,突出围绕公共安全大数据和电子数据取证业务需求开展人工智能大模型技术研究,支撑公司产品和技术向人工智能大模型的转型升级,构建公共安全领域的新质生产力。
基于公司在人工智能技术和公共安全业务领域长期和深度的业务知识积累,研发发布了国内首个公共安全领域大模型产品-美亚“天擎”公共安全系列大模型产品,入选 “2023中国大模型TOP70榜单”。
此次获奖是对国投智能在人工智能领域技术实力的高度认可。未来,国投智能将聚焦大模型技术应用、生成式人工智能和人工智能安全三个核心方向,踔厉奋发,持续发力,不断打磨推出更为安全、可信、可靠的人工智能技术产品,为打击利用人工智能的新型涉网犯罪,提供有力的技术武器,为维护和保障人工智能的健康发展和规范应用贡献力量!企业资讯
CVE-2024-56527 | tecnick tcpdf up to 6.7.x Error Message cross site scripting
8 months 2 weeks ago
A vulnerability was found in tecnick tcpdf up to 6.7.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Error Message Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-56527. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56522 | tecnick tcpdf up to 6.7.x Tag Hash unserializeTCPDFtag comparison
8 months 2 weeks ago
A vulnerability was found in tecnick tcpdf up to 6.7.x. It has been declared as problematic. Affected by this vulnerability is the function unserializeTCPDFtag of the component Tag Hash Handler. The manipulation leads to incorrect comparison.
This vulnerability is known as CVE-2024-56522. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56521 | tecnick tcpdf up to 6.7.x certificate validation
8 months 2 weeks ago
A vulnerability was found in tecnick tcpdf up to 6.7.x. It has been classified as problematic. Affected is an unknown function. The manipulation leads to improper certificate validation.
This vulnerability is traded as CVE-2024-56521. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56519 | tecnick tcpdf up to 6.7.x SVG setSVGStyles font-family Privilege Escalation
8 months 2 weeks ago
A vulnerability was found in tecnick tcpdf up to 6.7.x and classified as problematic. This issue affects the function setSVGStyles of the component SVG Handler. The manipulation of the argument font-family leads to Privilege Escalation.
The identification of this vulnerability is CVE-2024-56519. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11921 | GiveWP Plugin up to 3.18.x on WordPress cross site scripting
8 months 2 weeks ago
A vulnerability has been found in GiveWP Plugin up to 3.18.x on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-11921. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11645 | Float Block Plugin up to 1.7 on WordPress Setting cross site scripting
8 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Float Block Plugin up to 1.7 on WordPress. This affects an unknown part of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-11645. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11644 | WP-SVG Plugin up to 0.9 on WordPress Shortcode Attribute cross site scripting
8 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in WP-SVG Plugin up to 0.9 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-11644. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11842 | Weight DN Shipping for WooCommerce Plugin up to 1.1 on WordPress Setting cross-site request forgery
8 months 2 weeks ago
A vulnerability classified as problematic was found in Weight DN Shipping for WooCommerce Plugin up to 1.1 on WordPress. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-11842. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56520 | tecnick tcpdf up to 6.7.x tc-lib-pdf-font Privilege Escalation
8 months 2 weeks ago
A vulnerability classified as problematic has been found in tecnick tcpdf up to 6.7.x. Affected is an unknown function of the component tc-lib-pdf-font. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2024-56520. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com