Aggregator
“Marko Polo”打造全球网络犯罪巨头
1 year 6 months ago
安全客
全球首起通信设备武器化事件!黎巴嫩BP机爆炸致数千人死伤
1 year 6 months ago
安全客
Century-Long Innovation: A Legacy of Outpacing Cyber Threats
1 year 6 months ago
Discover how Komori, a century-old printing giant, is leading the charge in cybersecurity innovation by adapting to internet-connected risks and utilizing advanced solutions like NodeZero to safeguard their legacy.
The post Century-Long Innovation: A Legacy of Outpacing Cyber Threats appeared first on Horizon3.ai.
The post Century-Long Innovation: A Legacy of Outpacing Cyber Threats appeared first on Security Boulevard.
Ashely Griffin
科学家首次观察到夸克量子纠缠
1 year 6 months ago
CERN LHC 物理学家首次观察到夸克量子纠缠。ATLAS 探测器的物理学家分析了约百万对顶夸克和反顶夸克,发现了统计学上压倒性的纠缠证据,研究报告发表在本周的《自然》期刊上。CMS 探测器的物理学家也于今年 6 月在预印本平台 arXiv 报告了纠缠结果。LHC 质子碰撞后产生的顶夸克和反顶夸克对的寿命非常短,仅持续 10^(−25)秒,之后就衰变为寿命更长的粒子。成功观察到顶夸克纠缠有助于提高研究人员对顶夸克物理学的理解,为未来高能纠缠测试铺平道路。
CVE-2021-28799 | QNAP QTS/QuTS Hero/QuTScloud HBS 3 Hybrid Backup Sync improper authorization
1 year 6 months ago
A vulnerability was found in QNAP QTS, QuTS Hero and QuTScloud and classified as critical. This issue affects some unknown processing of the component HBS 3 Hybrid Backup Sync. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2021-28799. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-45382 | D-Link DIR-810L DDNS ncc2 Privilege Escalation (SAP10264)
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in D-Link DIR-810L, DIR-820L, DIR-820LW, DIR-826L, DIR-830L and DIR-836L. This issue affects some unknown processing of the file ncc2 of the component DDNS. The manipulation leads to Privilege Escalation.
The identification of this vulnerability is CVE-2021-45382. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-0543 | Redis on Debian Lua sandbox
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in Redis on Debian. Affected by this issue is some unknown functionality of the component Lua. The manipulation leads to sandbox issue.
This vulnerability is handled as CVE-2022-0543. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-1040 | Sophos Firewall up to 18.5 MR3 User Portal/Webadmin improper authentication (EDB-51006)
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Sophos Firewall up to 18.5 MR3. Affected is an unknown function of the component User Portal/Webadmin. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2022-1040. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-26871 | Trend Micro Apex Central unrestricted upload
1 year 6 months ago
A vulnerability has been found in Trend Micro Apex Central and classified as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2022-26871. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Infostealers Cause Surge in Ransomware Attacks, Just One in Three Recover Data
1 year 6 months ago
Infostealer malware and digital identity exposure behind rise in ransomware, researchers find
Submit #410397: SourceCodester Best house rental management system project in php 4/15 SQL Injection [Duplicate]
1 year 6 months ago
Submit #410397 / VDB-268767
webray.com.cn
CVE-2024-8883 | Red Hat Build of Keycloak Redirect URI redirect
1 year 6 months ago
A vulnerability was found in Red Hat Build of Keycloak, JBoss Enterprise Application Platform and Single Sign-On. It has been classified as problematic. This affects an unknown part of the component Redirect URI Handler. The manipulation leads to open redirect.
This vulnerability is uniquely identified as CVE-2024-8883. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-8698 | Red Hat Build of Keycloak SAML Signature signature verification
1 year 6 months ago
A vulnerability was found in Red Hat Build of Keycloak, JBoss Enterprise Application Platform and Single Sign-On and classified as problematic. Affected by this issue is some unknown functionality of the component SAML Signature Handler. The manipulation leads to improper verification of cryptographic signature.
This vulnerability is handled as CVE-2024-8698. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2021-21973 | VMware vCenter Server/Cloud Foundation vSphere Client server-side request forgery (VMSA-2021-0002)
1 year 6 months ago
A vulnerability was found in VMware vCenter Server and Cloud Foundation. It has been rated as critical. Affected by this issue is some unknown functionality of the component vSphere Client. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2021-21973. Access to the local network is required for this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-26318 | Watchguard Firebox/XTM prior 12.7.2_U2/12.1.3_U8/12.5.9_U2 Remote Code Execution (FBX-22786)
1 year 6 months ago
A vulnerability was found in Watchguard Firebox and XTM and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2022-26318. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-26143 | Mitel MiCollab/MiVoice Business Express
1 year 6 months ago
A vulnerability classified as critical was found in Mitel MiCollab and MiVoice Business Express. This vulnerability affects unknown code. The manipulation leads to an unknown weakness.
This vulnerability was named CVE-2022-26143. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8375 | Google Deepmind Reverb RPC Endpoint deserialization
1 year 6 months ago
A vulnerability has been found in Google Deepmind Reverb and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RPC Endpoint. The manipulation leads to deserialization.
This vulnerability is known as CVE-2024-8375. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-9011 | code-projects Crud Operation System 1.0 updata.php sid sql injection
1 year 6 months ago
A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0. Affected is an unknown function of the file updata.php. The manipulation of the argument sid leads to sql injection.
This vulnerability is traded as CVE-2024-9011. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Отсканировал и остался без денег: как QR-коды разоряют европейских туристов
1 year 6 months ago
От новейших методов мошенников не застрахованы даже опытные пользователи.