Aggregator
НеSOCрушимая безопасность: «Газинформсервис» прокачал GSOC и показал новый BAS
New Russia-affiliated actor Void Blizzard targets critical sectors for espionage
Microsoft Threat Intelligence has discovered a cluster of worldwide cloud abuse activity conducted by a threat actor we track as Void Blizzard, who we assess with high confidence is Russia-affiliated and has been active since at least April 2024. Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to Russia, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America.
The post New Russia-affiliated actor Void Blizzard targets critical sectors for espionage appeared first on Microsoft Security Blog.
CVE-2025-5218 | FreeFloat FTP Server 1.0.0 LITERAL Command buffer overflow
CVE-2025-5219 | FreeFloat FTP Server 1.0.0 ASCII Command buffer overflow
CVE-2025-5220 | FreeFloat FTP Server 1.0.0 GET Command buffer overflow
CVE-2025-33079 | IBM Controller/Cognos Controller 11.0.0/11.0.1/11.1.0 credentials storage
CVE-2025-48744 | SIGB PMB prior 8.0.1.2 path traversal
CVE-2025-23393 | SUSE Manager Server Module 4.3 cross site scripting
CVE-2025-2407 | Mobatime AMX MTAPI/AMXGT-100 Web API missing authentication
CVE-2025-4683 | MStore API Plugin up to 4.17.5 on WordPress create_blog authorization
CVE-2025-4682 | Essential Blocks Plugin up to 5.4.0 on WordPress Slider Widget/Post Carousel Widget cross site scripting
XSS的高级利用
CVE-2025-5215 | D-Link DCS-5020L 1.01_B2 /rame/ptdc.cgi websReadEvent Authorization stack-based overflow
CVE-2025-5216 | PHPGurukul Student Record System 3.20 /login.php ID sql injection
CVE-2025-5217 | FreeFloat FTP Server 1.0.0 RMDIR Command buffer overflow
数世咨询:《中国数据安全50强(2025)》发布
Windows Server emergency update fixes Hyper-V VM freezes, restart issues
Everest Ransomware Leaks Coca-Cola Employee Data Online
中国电信蝉联中国公有云DDoS防护市场份额第一!
5月26日,国际权威咨询机构IDC发布《IDC MarketShare:中国公有云抗DDoS市场份额,2024》调研报告,中国电信凭借运营商独有的云网资源禀赋、卓越的安全服务、突破性的创新技术,以29.0%的份额在中国公有云DDoS防护市场中占比第一,连续两年蝉联榜首,持续领跑网络与通信安全-DDoS防护领域。
图片来源:IDC
2024年,中国电信云堤·抗D产品收入稳步增长,在国内公有云抗DDoS市场中,连续两年保持市场份额领先。
2024年,云堤·抗D为政务、金融、企事业单位以及互联网行业客户提供近百次重保服务,累计防御网络攻击达60余万次,保障了我国网络安全的同时挽回了大量的经济损失,是国资委《央企科技创新成果产品(2023年)手册》唯一入选的DDoS防护产品。
·在科技创新方面,电信安全承接工信部网安局“网络安全科技创新揭榜挂帅”行业亟需方向的面向短时高频DDoS攻击的快速处置响应攻关任务,积极探究新形势下DDoS攻击防护技术的创新应用;
·在前沿探索方面,电信安全依托深度测绘僵尸网络,提取僵尸网络发起源控制端被控主机及访问行为等信息,结合通过对恶意样本的捕获、逆向分析和研判等技术手段,生成攻击发起者的恶意攻击行为画像数据,为告警研判提供依据;
·在防护能力方面,云堤·抗D推出快速研判、精准识别的秒级检测功能,结合见微大模型智能风险辅助分析与研判,通过骨干、城域、端侧防护资源多级联动,对DDoS攻击流量实现高、中、低全方位的近源与近目的清洗、封堵及秒级压制等处置措施。
随着数字化转型的持续推进,将出现更多的业务上云、安全出海以及新型应用拓展,同时DDoS攻击的频率和规模不断扩大,企业对公有云抗DDoS服务的需求将持续增加,中国电信安全公司将继续秉持“传承红色基因,守护安全中国”的使命,为保障客户网络的安全畅通与业务的连续可用保驾护航。