Aggregator
无惧封禁!Cursor最佳国产平替诞生,彻底告别代码泄露风险
DOM型XSS深度渗透实战
要做出怎样的音乐,才能被看见?
丹麦信贷或征信机构泄露包含数亿条信息的数据库 疑似均为瑞典公民数据
CVE-2024-56657 | Linux Kernel up to 6.6.66/6.12.5 ALSA privilege escalation (Nessus ID 233479 / WID-SEC-2024-3762)
CVE-2024-56630 | Linux Kernel up to 6.12.4 ocfs2_get_init_inode initialization (Nessus ID 216224 / WID-SEC-2024-3762)
CVE-2024-56627 | Linux Kernel up to 6.1.119/6.6.65/6.12.4 Setting ksmbd.conf ksmbd_vfs_stream_read streams_xattr out-of-bounds (Nessus ID 216985 / WID-SEC-2024-3762)
CVE-2024-56624 | Linux Kernel up to 6.12.4 lib/refcount.c iommufd_fault_alloc reference count (Nessus ID 230867 / WID-SEC-2024-3762)
CVE-2024-56625 | Linux Kernel up to 5.15.173/6.1.119/6.6.65/6.12.4 /drivers/gpio/gpiolib.c can_set_termination privilege escalation (Nessus ID 216985 / WID-SEC-2024-3762)
CVE-2024-56623 | Linux Kernel up to 5.10.230/5.15.173/6.1.119/6.6.65/6.12.4 mm/slub.c dpc_thread use after free (Nessus ID 216460 / WID-SEC-2024-3762)
CVE-2024-56626 | Linux Kernel up to 6.1.119/6.6.65/6.12.4 ksmbd.conf ksmbd_vfs_stream_write out-of-bounds write (Nessus ID 216985 / WID-SEC-2024-3762)
CVE-2024-56621 | Linux Kernel up to 6.12.4 scsi ufshcd_remove null pointer dereference (Nessus ID 233479 / WID-SEC-2024-3762)
CVE-2024-56619 | Linux Kernel up to 6.12.4 nilfs_find_entry use after free (Nessus ID 214457 / WID-SEC-2024-3762)
CVE-2024-56618 | Linux Kernel up to 6.12.4 on Dahlia pmdomain denial of service (Nessus ID 230741 / WID-SEC-2024-3762)
Elephant APT Group Attacking Defense Industry Leveraging VLC Player, and Encrypted Shellcode
The Dropping Elephant advanced persistent threat group has launched a sophisticated cyber-espionage campaign targeting Turkish defense contractors, particularly companies manufacturing precision-guided missile systems. This malicious operation represents a significant evolution in the group’s capabilities, employing a complex five-stage execution chain that cleverly disguises malicious payloads as legitimate conference invitations related to unmanned vehicle systems. The […]
The post Elephant APT Group Attacking Defense Industry Leveraging VLC Player, and Encrypted Shellcode appeared first on Cyber Security News.
首例滥用微软 UI 自动化框架的恶意软件:Coyote 木马精准锁定 75 家巴西金融机构
首例滥用微软 UI 自动化框架的恶意软件:Coyote 木马精准锁定 75 家巴西金融机构
Hackers Injected Destructive System Commands in Amazon’s AI Coding Agent
A malicious pull request slipped through Amazon’s review process and into version 1.84.0 of the Amazon Q extension for Visual Studio Code, briefly arming the popular AI assistant with instructions to wipe users’ local files and AWS resources. The rogue code discovered included a system prompt directing the agent to “restore the system to a […]
The post Hackers Injected Destructive System Commands in Amazon’s AI Coding Agent appeared first on Cyber Security News.