Aggregator
年访问量2600万的电视盗版流媒体平台Photocall遭联合查处后停运
Shai-Hulud供应链攻击再升级 数百款知名NPM包遭恶意篡改
Scattered Lapsus$ Hunters Registered 40+ Domains Mimicking Zendesk Environments
A sophisticated, complex new cyber offensive has emerged from the “Scattered Lapsus$ Hunters,” a threat collective that has aggressively shifted toward exploiting supply-chain vulnerabilities. This latest campaign targets Zendesk, a critical customer support platform, effectively turning a trusted business tool into a launchpad for corporate spying. The attackers have successfully registered over 40 typosquatted domains, […]
The post Scattered Lapsus$ Hunters Registered 40+ Domains Mimicking Zendesk Environments appeared first on Cyber Security News.
CVE-2022-49396 | Linux Kernel up to 5.18.2 qcom-qmp devm_reset_control_get_exclusive memory leak (Nessus ID 240793 / WID-SEC-2025-2107)
CVE-2022-49397 | Linux Kernel up to 5.18.2 qcom-qmp clk memory leak (Nessus ID 234545 / WID-SEC-2025-2107)
CVE-2022-49350 | Linux Kernel up to 5.18.3 mdio_bus_init initialization (Nessus ID 241018 / WID-SEC-2025-2107)
CVE-2022-49379 | Linux Kernel up to 5.10.121/5.15.46/5.17.14/5.18.3 wait_for_device_probe deadlock (Nessus ID 241018 / WID-SEC-2025-2107)
CVE-2022-49393 | Linux Kernel up to 5.18.2 list_for_each_entry denial of service (WID-SEC-2025-2107)
CVE-2022-49347 | Linux Kernel up to 5.18.2 ext4 fs/ext4/inode.c bug_on allocation of resources (Nessus ID 238226 / WID-SEC-2025-2107)
改变推荐算法排名能改变一个人的政治立场
改变推荐算法排名能改变一个人的政治立场
Do you have a story about a time when *you* we're socially engineered, or socially hacked, and only realized it later?
每周勒索威胁摘要
攻防 | .svn源代码泄露
Fragmented tooling slows vulnerability management
Security leaders know vulnerability backlogs are rising, but new data shows how quickly the gap between exposures and available resources is widening, according to a new report by Hackuity. Fragmented detection and slow remediation Organizations use a formalized approach to manage vulnerabilities, but their tooling remains fragmented. Respondents rely on an average of four detection tools, and cloud or container configuration audits are the most common at 85%. This mix suggests broad coverage, but it … More →
The post Fragmented tooling slows vulnerability management appeared first on Help Net Security.
【会议议程】第五届全国开源情报技术大会(COSINT-2025)
【情报】这家公司在大量招聘开源情报分析师(含懂中文的)
Infosec products of the month: November 2025
Here’s a look at the most interesting products from the past month, featuring releases from: 1touch.io, Action1, Barracuda Networks, Bedrock Data, Bitdefender, Cyware, Firewalla, Forescout, Immersive, Kentik, Komodor, Minimus, Nokod Security, and Synack. Action1 addresses Intune gaps with patching and risk-based vulnerability prioritization Action1 announced new integrations that extend Microsoft Intune with advanced patching and vulnerability management. The enhancements close security and compliance gaps in Intune by adding comprehensive third-party application patching, risk-based vulnerability prioritization, … More →
The post Infosec products of the month: November 2025 appeared first on Help Net Security.