Aggregator
Chrome应用商店恶意扩展程序窃取用户敏感数据
Chrome应用商店恶意扩展程序窃取用户敏感数据
OpenAEV: Open-source adversarial exposure validation platform
OpenAEV is an open source platform designed to plan, run, and review cyber adversary simulation campaigns used by security teams. The project focuses on organizing exercises that blend technical actions with operational and human response elements, all managed through a single system. Scenarios as the foundation At the core of OpenAEV is the concept of a scenario. A scenario defines a threat context and turns it into a structured plan made up of events called … More →
The post OpenAEV: Open-source adversarial exposure validation platform appeared first on Help Net Security.
Submit #731433: campcodes Supplier Management System 1.0 SQL Injection [Accepted]
Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data
QNAP has patched multiple security vulnerabilities in its License Center application that could allow attackers to access sensitive information or disrupt services on affected NAS devices. The issues, tracked as CVE-2025-52871 and CVE-2025-53597, were disclosed on January 3, 2026. QNAP rated the flaws as Moderate severity and confirmed that the issues have been resolved in the latest releases. The vulnerabilities affect License Center 2.0.x, a component used to […]
The post Multiple Vulnerabilities in QNAP Tools Let Attackers Obtain Secret Data appeared first on Cyber Security News.
测试显示 Windows 11 的速度在六个 Windows 版本中垫底
测试显示 Windows 11 的速度在六个 Windows 版本中垫底
CVE-2025-66518 | Apache Kyuubi up to 1.10.1 Frontend Protocol file access
CVE-2025-5591 | Kentico Xperience 13.0.167 Form cross site scripting
CVE-2025-62208 | Microsoft Windows up to Server 2025 License Manager log file (EUVD-2025-93402 / Nessus ID 274792)
CVE-2025-62209 | Microsoft Windows up to Server 2025 License Manager log file (EUVD-2025-93401 / Nessus ID 274792)
CVE-2025-60721 | Microsoft Windows 11 24H2/11 25H2 Administrator Protection privilege context switching error (EUVD-2025-93393 / WID-SEC-2025-2564)
CVE-2025-60723 | Microsoft Windows up to Server 2025 DirectX Graphics race condition (EUVD-2025-93410 / WID-SEC-2025-2564)
CVE-2025-60724 | Microsoft Windows up to Server 2025 GDI+ heap-based overflow (EUVD-2025-93409 / Nessus ID 274792)
CVE-2025-60718 | Microsoft Windows 11 24H2/11 25H2 Administrator Protection untrusted search path (EUVD-2025-93412 / WID-SEC-2025-2564)
CVE-2025-60719 | Microsoft Windows up to Server 2025 Ancillary Function Driver for WinSock untrusted pointer dereference (Nessus ID 274792 / WID-SEC-2025-2564)
CVE-2025-60720 | Microsoft Windows up to Server 2025 Transport Driver Interface Translation Driver buffer over-read (EUVD-2025-93411 / Nessus ID 274792)
CVE-2025-60717 | Microsoft Windows up to Server 2025 Broadcast DVR User Service use after free (EUVD-2025-93413 / Nessus ID 274792)
Understanding AI insider risk before it becomes a problem
In this Help Net Security video, Greg Pollock, Head of Research and Insights at UpGuard, discusses AI use inside organizations and the risks tied to insiders. He explains two problems. One involves employees who use AI tools to speed up work but share data with unapproved services. The other involves hostile actors who use AI to gain trusted roles inside companies. Pollock walks through research showing how common unapproved AI use has become, including among … More →
The post Understanding AI insider risk before it becomes a problem appeared first on Help Net Security.