Aggregator
.NET 实战:通过 Patch 内存绕过 AMSI
3 months 3 weeks ago
从 UUID 伪装到 Shellcode 执行,通过 UUID 编码绕过本地安全防护
3 months 3 weeks ago
Weekly Report: Ivanti Endpoint Manager Mobileに複数の脆弱性
3 months 3 weeks ago
Ivanti製Ivanti Endpoint Manager Mobileには、認証バイパスの脆弱性(CVE-2025-4427)と任意のコード実行の脆弱性(CVE-2025-4428)があります。Ivantiは、当該脆弱性を悪用した攻撃を確認しているとのことです。この問題は、当該製品にパッチを適用することで解決します。詳細は、開発者が提供する情報を参照してください。
Account Takeover Scams Are Bypassing Fraud Defenses
3 months 3 weeks ago
FIs Must Invest in AI-Fueled Behavioral Biometrics to Go Beyond Static Credentials
Scammers are increasingly turning to account takeover fraud, as financial institutions ramp up their defenses. Instead of luring victims into making authorized transactions, cybercriminals are bypassing them altogether, hijacking their digital identities and draining accounts from within.
Scammers are increasingly turning to account takeover fraud, as financial institutions ramp up their defenses. Instead of luring victims into making authorized transactions, cybercriminals are bypassing them altogether, hijacking their digital identities and draining accounts from within.
US Senate Democrats Push Noem on Cybersecurity Spending Cuts
3 months 3 weeks ago
Homeland Security Secretary Says Trump Budget Strengthens Cybersecurity
Senate Democrats Tuesday pushed Homeland Security Secretary Kristi Noem on the Trump administration's cuts to the cybersecurity component of the U.S. federal department she leads. Noem told senators the U.S. Cybersecurity and Infrastructure Agency will "continue to fulfill" its statutory obligations.
Senate Democrats Tuesday pushed Homeland Security Secretary Kristi Noem on the Trump administration's cuts to the cybersecurity component of the U.S. federal department she leads. Noem told senators the U.S. Cybersecurity and Infrastructure Agency will "continue to fulfill" its statutory obligations.
M&S Reportedly Hacked Using Third-Party Credentials
3 months 3 weeks ago
Scattered Spider Stole Tata Consulting Services Employee Login Details for Hack
British retailer Marks & Spencer was reportedly compromised by cybercrime group Scattered Spider using stolen employee credentials from a third-party IT company. Citing an unidentified source, Reuters reported hackers used the M&S login credentials of two Tata Consulting Services employees.
British retailer Marks & Spencer was reportedly compromised by cybercrime group Scattered Spider using stolen employee credentials from a third-party IT company. Citing an unidentified source, Reuters reported hackers used the M&S login credentials of two Tata Consulting Services employees.
Judge Lets Delta Lawsuit Over CrowdStrike Outage Proceed
3 months 3 weeks ago
Georgia Court Allows Claims of Fraud, Trespass Over Falcon Software Update
Delta can proceed with its lawsuit against CrowdStrike over a July 2024 update that allegedly bypassed Microsoft safeguards and crashed thousands of systems. The judge found that Delta sufficiently alleged fraud, computer trespass and gross negligence, allowing key claims to move forward.
Delta can proceed with its lawsuit against CrowdStrike over a July 2024 update that allegedly bypassed Microsoft safeguards and crashed thousands of systems. The judge found that Delta sufficiently alleged fraud, computer trespass and gross negligence, allowing key claims to move forward.
[remote] Remote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)
3 months 3 weeks ago
Remote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)
我国科技企业遭境外黑客攻击,透视APT攻击反制策略
3 months 3 weeks ago
境外黑客组织针对我国关键领域的网络攻击频率激增!
CVE-2025-21872 | Linux Kernel up to 5.10.234/6.6.82/6.12.17/6.13.5 mm/early_ioremap.c early_memmap iteration (Nessus ID 236983)
3 months 3 weeks ago
A vulnerability classified as problematic has been found in Linux Kernel up to 5.10.234/6.6.82/6.12.17/6.13.5. Affected is the function early_memmap of the file mm/early_ioremap.c. The manipulation leads to excessive iteration.
This vulnerability is traded as CVE-2025-21872. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21863 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 io_uring privilege escalation (Nessus ID 236983)
3 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3. It has been classified as problematic. Affected is an unknown function of the component io_uring. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2025-21863. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-58088 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 bpf_local_storage_map_free deadlock (Nessus ID 236983)
3 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 and classified as critical. This issue affects the function bpf_local_storage_map_free. The manipulation leads to deadlock.
The identification of this vulnerability is CVE-2024-58088. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21851 | Linux Kernel up to 6.12.16/6.13.4/6.14-rc3 arena_map_free memory corruption (Nessus ID 236983)
3 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.12.16/6.13.4/6.14-rc3. It has been rated as critical. Affected by this issue is the function arena_map_free. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2025-21851. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21869 | Linux Kernel up to 6.12.16/6.13.4 Kernel Memory copy_to_kernel_nofault stack-based overflow (Nessus ID 236983)
3 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.16/6.13.4. Affected by this issue is the function copy_to_kernel_nofault of the component Kernel Memory Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2025-21869. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21773 | Linux Kernel up to 6.6.78/6.12.15/6.13.3/6.14-rc2 etas_es58x null pointer dereference (Nessus ID 236983)
3 months 3 weeks ago
A vulnerability has been found in Linux Kernel up to 6.6.78/6.12.15/6.13.3/6.14-rc2 and classified as critical. This vulnerability affects unknown code of the component etas_es58x. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2025-21773. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21836 | Linux Kernel up to 6.6.78/6.12.15/6.13.3/6.14-rc2 io_uring io_buffer_list allocation of resources (Nessus ID 236983)
3 months 3 weeks ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.6.78/6.12.15/6.13.3/6.14-rc2. Affected by this vulnerability is the function io_buffer_list of the component io_uring. The manipulation leads to allocation of resources.
This vulnerability is known as CVE-2025-21836. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21793 | Linux Kernel up to 6.6.78/6.12.15/6.13.3/6.14-rc2 sn-f-ospi divide by zero (Nessus ID 236983)
3 months 3 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.78/6.12.15/6.13.3/6.14-rc2 and classified as critical. Affected by this issue is some unknown functionality of the component sn-f-ospi. The manipulation leads to divide by zero.
This vulnerability is handled as CVE-2025-21793. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21854 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 psock_update_sk_prot null pointer dereference (Nessus ID 236983)
3 months 3 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3. This affects the function vsock_proto::psock_update_sk_prot. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-21854. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
PowerSchool hacker pleads guilty to student data extortion scheme
3 months 3 weeks ago
A 19-year-old college student from Worcester, Massachusetts, has agreed to plead guilty to a massive cyberattack on PowerSchool that extorted millions of dollars in exchange for not leaking the personal data of millions of students and teachers. [...]
Lawrence Abrams