Aggregator
Weekly Update 469
So I had this idea around training a text-to-speech engine with my voice, then using that to speak over the Sonos at home to announce AI-driven events, such as people ringing the doorbell. A few hours' worth of video from these weekly updates fed into ElevenLabs and wammo! Here
CVE-2015-7940 | Oracle PeopleSoft Enterprise HCM Human Resources 9.1/9.2 Install cryptographic issues (EUVD-2018-0502 / Nessus ID 87266)
CVE-2015-7940 | Oracle Mobile Security Suite 3.0.1 BMAX cryptographic issues (EUVD-2018-0502 / Nessus ID 89298)
CVE-2015-7940 | Oracle Communications 12.x Policy Management information disclosure (EUVD-2018-0502 / Nessus ID 89298)
CVE-2015-7940 | Oracle Business Process Management Suite Bouncy Castle Java Package cryptographic issues (EUVD-2018-0502 / Nessus ID 87266)
CVE-2015-7940 | Oracle Managed File Transfer 12.1.3.0.0/12.2.1.1.0/12.2.1.2.0 Bouncy Castle Java Package cryptographic issues (EUVD-2018-0502 / Nessus ID 87266)
CVE-2015-7940 | Oracle WebCenter Portal 11.1.1.9.0/12.2.1.2.0/12.2.1.3.0 Security Framework cryptographic issues (EUVD-2018-0502 / Nessus ID 87266)
CVE-2025-4235 | Palo Alto User-ID Credential Agent up to 11.0.2-132 on Windows Legacy Feature exposure of sensitive system information to an unauthorized control sphere (EUVD-2025-29071)
Жёсткий урок от Голливуда: цифровое пиратство карается строже грабежа и разбойного нападения
CVE-2025-48913 | Apache CXF up to 3.6.7/4.0.8/4.1.2 JMS Configuration input validation (EUVD-2025-23982 / Nessus ID 249322)
CVE-2025-8916 | Bouncy Castle for Java API Module allocation of resources (EUVD-2025-24555 / Nessus ID 260006)
CVE-2025-8885 | Bouncy Castle for Java up to 1.77/2.0.0 API Module allocation of resources (EUVD-2025-24231 / Nessus ID 260029)
CVE-2022-28331 | Apache Portable Runtime up to 1.7.0 on Windows apr_socket_sendv stack-based overflow (WID-SEC-2023-0245)
【培训通知】第15期全国开源情报能力培训班10月广西开班
【情报】非洲针对华人的暴力事件背后的认知战
New Malvertising Campaign Leverages GitHub Repository to Deliver Malware
A sophisticated malvertising campaign has emerged, exploiting GitHub repositories through dangling commits to distribute malware via fake GitHub Desktop clients. This novel attack vector represents a significant evolution in cybercriminal tactics, leveraging the trust and legitimacy associated with GitHub’s platform to deceive unsuspecting users into downloading malicious software. The campaign operates by promoting compromised GitHub […]
The post New Malvertising Campaign Leverages GitHub Repository to Deliver Malware appeared first on Cyber Security News.
CVE-2025-10385 | Mercury KM08-708H GiGA WiFi Wave2 1.1 /goform/mcr_setSysAdm sub_450B2C ChgUserId buffer overflow (EUVD-2025-29104)
Exploring Open Source and Compliance in Vulnerability Management
Discover how to leverage open-source tools for vulnerability management while meeting compliance requirements. Learn best practices for secure and compliant software development.
The post Exploring Open Source and Compliance in Vulnerability Management appeared first on Security Boulevard.