Aggregator
【资料】美国陆军步兵杂志2025年春季、夏季刊
【资料】全球每日动态已增至40个国家/地区
绿盟虚拟汽车靶场(六):汽车CAN总线的Fuzz
绿盟虚拟汽车靶场(六):汽车CAN总线的Fuzz
Real-world numbers for estimating security audit costs
At the end of Star Wars: A New Hope, Luke Skywalker races through the Death Star trench, hearing the ghostly voice of Obi-Wan Kenobi telling him to trust him. Luke places blind trust in an intangible energy that surrounds him, he defeats Darth Vader and blows up the dreaded Death Star. While this story works for science fiction, real-world customers can no longer afford to place blind trust in their vendors – they need documented … More →
The post Real-world numbers for estimating security audit costs appeared first on Help Net Security.
CVE-2022-31764 | Apache ShardingSphere ElasticJob-UI up to 3.0.1 JDBC dynamically-managed code resources
CVE-2024-45654 | IBM Security ReaQta 3.12 reliance on untrusted inputs in a security decision
CVE-2024-41742 | IBM TXSeries for Multiplatforms 10.1 allocation of resources
CVE-2024-41743 | IBM TXSeries for Multiplatforms 10.1 Persistent Connection allocation of resources
CVE-2025-0730 | TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304 HTTP GET Request /usr_account_set.cgi username/password get request method with sensitive query strings
CVE-2025-49676 | Microsoft Windows Server 2008 R2 SP1 up to Server 2022 23H2 Routing/Remote Access Service heap-based overflow (EUVD-2025-20640)
CVE-2025-49681 | Microsoft Windows Server 2008 R2 SP1 up to Server 2022 23H2 Routing/Remote Access Service out-of-bounds (EUVD-2025-20569)
Думали, VPN защищает приватность? Поздравляем — теперь это самый дорогой способ попасть на штраф
JVN: 複数のHitachi Energy製品における複数の脆弱性
JVN: ABB製RMC-100における複数の脆弱性
JVN: 複数のLITEON製品におけるパスワードの平文保存の脆弱性
OpenAI избавила нас от промптов — теперь искусство создаётся в один клик
Falco: Open-source cloud-native runtime security tool for Linux
Falco is an open-source runtime security tool for Linux systems, built for cloud-native environments. It monitors the system in real time to spot unusual activity and possible security threats. Falco is a graduated project from the Cloud Native Computing Foundation (CNCF) and is used in production by many organizations. The tool works by watching system events such as syscalls, using custom rules. It can also add context from container runtimes and Kubernetes. The events it … More →
The post Falco: Open-source cloud-native runtime security tool for Linux appeared first on Help Net Security.
North Korean Hackers Weaponized 67 Malicious npm Packages to Deliver XORIndex Malware
North Korean threat actors have escalated their software supply chain attacks with the deployment of 67 malicious npm packages that collectively garnered over 17,000 downloads before detection. This latest campaign represents a significant expansion of the ongoing “Contagious Interview” operation, introducing a previously unreported malware loader dubbed XORIndex alongside the existing HexEval Loader infrastructure. The […]
The post North Korean Hackers Weaponized 67 Malicious npm Packages to Deliver XORIndex Malware appeared first on Cyber Security News.