Aggregator
Now BlueSky hit with crypto scams as it crosses 20 million users
4 days 1 hour ago
As many more users are flocking to BlueSky from social media platforms like X/Twitter, so ar
Arcus Media
4 days 1 hour ago
cohenido
Threat actor sells data of over 750,000 patients from a French hospital
4 days 1 hour ago
Threat actor sells data of over 750,000 patients from a French hospital
聚焦乌镇 | 《中国互联网发展报告2024》和《世界互联网发展报告2024》蓝皮书发布
4 days 2 hours ago
扫码订阅《中国信息安全》邮发代号 2-786征订热线:010-8234106311月21日,由中国网络空间研究院编写、国内互联网领域高端智库和研究机构支持参与的《中国互联网发展报告2024》和《世界
前沿 | 《密码法》颁布五周年:法治成效、实施难点与未来走向
4 days 2 hours ago
扫码订阅《中国信息安全》邮发代号 2-786征订热线:010-82341063文 | 公安部第三研究所研究员 黄道丽;西安交通大学教授 马民虎2024年10月26日是《密码法》颁布五周年纪念日。作为
聚焦乌镇 | 打造大模型安全标杆!360安全大模型在世界互联网大会连获两项殊荣
4 days 2 hours ago
扫码订阅《中国信息安全》邮发代号 2-786征订热线:010-82341063近日,2024年世界互联网大会乌镇峰会在浙江乌镇举行。峰会期间,三六零集团(下称“360”)凭借其自主研发的360安全大
通知 | 网安标委发布《网络安全标准实践指南——粤港澳大湾区(内地、香港)个人信息跨境处理保护要求》(附全文)
4 days 2 hours ago
扫码订阅《中国信息安全》邮发代号 2-786征订热线:010-82341063关于发布《网络安全标准实践指南——粤港澳大湾区(内地、香港)个人信息跨境处理保护要求》的通知网安秘字〔2024〕152号
How a Mental Health Nonprofit Secures Endpoints for Compassionate Care
4 days 2 hours ago
Consolidating endpoint management boosts cybersecurity while keeping an Oklahoma-based nonprofit focused on community mental health.
Jennifer Lawinski, Contributing Writer
DataCon2024 | 距竞赛结束还剩1天!明日迎接最后决战
4 days 2 hours ago
DataCon2024 /第九个比赛日转眼,DataCon2024已经进行了九天的激烈比拼,各大战队轮番登榜,排名榜不断刷新的背后,是七百余支战队持续创新、不断突破、勇于攀登的励志精神。明天,Data
Машины тоже хотят домой: маленький робот уговорил собратьев устроить бунт
4 days 2 hours ago
Случай в Китае поднимает новые дискуссии о безопасности технологий.
竟长达10年未发现?Ubuntu系统“needrestart”工具曝5个本地提权漏洞
4 days 2 hours ago
近日,Ubuntu系统中的“needrestart”实用程序被曝出存在5个本地权限提升(LPE)漏洞,这些安全缺陷已潜伏10年之久未被发现。这些漏洞由安全公司Qualys发现,并被分配了CVE编号,从
Hack.lu 2024 Getting into Shape 解析
4 days 2 hours ago
1.本篇文章详细讨论wasm逆向,针对wasm2c wasm2js (wasm2wat 更是没法看)量大 代码多 且市面上没有出色wasm反编译引擎(JEB 也无济于事),我们如何海量代码中找到核心逻
惊喜开班!系统0day安全-IOT设备漏洞挖掘
4 days 2 hours ago
数字化时代,物联网(IoT)设备已经渗透到我们生活的方方面面,从智能家居到工业自动化,无一不依赖于这些智能设备。然而,随着IoT设备的普及,安全问题也日益凸显。IoT设备漏洞挖掘成为了保障网络安全的重
Intelligence Insights: November 2024
4 days 2 hours ago
LummaC2 sets the table and gobbles up sensitive information in this month's edition of Intelligence Insights
The Red Canary Team
Explore MITRE ATT&CK Techniques in Real-World Samples with TI Lookup
4 days 2 hours ago
We’re excited to annou
Daniel Stori’s Turnoff.US: ‘My Adorable Useless Code’
4 days 2 hours ago
via the inimitable Daniel Stori at Turnoff.US!
The post Daniel Stori’s Turnoff.US: ‘My Adorable Useless Code’ appeared first on Security Boulevard.
Marc Handelman
CVE-2004-1757 | BEA WebLogic 6.1/7.0/8.1 Administration Server Console config.xml missing encryption (VU#350350 / Nessus ID 12043)
4 days 2 hours ago
A vulnerability classified as critical has been found in BEA WebLogic 6.1/7.0/8.1. This affects an unknown part of the file config.xml of the component Administration Server Console. The manipulation leads to missing encryption of sensitive data.
This vulnerability is uniquely identified as CVE-2004-1757. Access to the local network is required for this attack. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2004-1756 | BEA WebLogic 7.0/8.1 Custom Trust Manager administrator's improper authentication (VU#566390 / ID 87198)
4 days 2 hours ago
A vulnerability classified as critical was found in BEA WebLogic 7.0/8.1. Affected by this vulnerability is an unknown functionality of the file administrator's of the component Custom Trust Manager. The manipulation leads to improper authentication.
This vulnerability is known as CVE-2004-1756. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2004-1755 | BEA WebLogic 7.0 FAT Client Certificate Authentication improper authentication (VU#858990 / XFDB-15826)
4 days 2 hours ago
A vulnerability was found in BEA WebLogic 7.0. It has been classified as critical. Affected is an unknown function of the component FAT Client Certificate Authentication Handler. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2004-1755. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com