Aggregator
The true (and surprising) cost of forgotten passwords
Washington's Cybersecurity Storm of Complacency
债务减免公司遭遇数据泄露 150 万客户信息遭泄露
CISA 在 KEV 目录中增加了五个被积极利用的漏洞
AI 只能完成高等数学新测试问题的不到 2%
Malware Spotlight: A Deep-Dive Analysis of WezRat
Key Findings: Introduction On October 30th, the FBI, the US Department of Treasury, and the Israeli National Cybersecurity Directorate (INCD) released a joint Cybersecurity Advisory regarding recent activities of the Iranian cyber group Emennet Pasargad. The group recently operated under the name Aria Sepehr Ayandehsazan (ASA) and is affiliated with the Iranian Islamic Revolutionary Guard Corps (IRGC). […]
The post Malware Spotlight: A Deep-Dive Analysis of WezRat appeared first on Check Point Research.
OvrC 平台漏洞使物联网设备面临远程攻击和代码执行风险
ModeLeak漏洞:研究人员在Google Vertex AI中发现权限提升和模型泄露威胁
CVE-2023-4458 | Linux Kernel ksmbd smb2_open out-of-bounds
CVE-2024-7474 | lunary-ai lunary up to 1.3.3 id access control
CVE-2024-7010 | mudler localai up to 2.20 information disclosure
CVE-2024-11207 | Apereo CAS 6.6 /login redirect_uri
CVE-2024-11209 | Apereo CAS 6.6 2FA /login?service improper authentication
CVE-2024-10962 | WPvivid Plugin up to 0.9.107 on WordPress code injection
CVE-2024-7730 | QEMU virtio-snd Device virtio_snd_pcm_in_cb heap-based overflow (Nessus ID 210736)
CVE-2024-3447 | QEMU sdhci_write_dataport heap-based overflow (Nessus ID 209571)
NIST is chipping away at NVD backlog
The National Institute of Standards and Technology (NIST) is clearing the backlog of unprocessed CVE-numbered vulnerabilities in the National Vulnerability Database (NVD), but has admitted that their initial estimate of when they would finish the job was “optimistic”. About the NVD The National Vulnerability Database is a public repository of vulnerabilities that have been published on MITRE’s CVE List. “NVD staff are tasked with enrichment of CVEs by aggregating data points from the description, references … More →
The post NIST is chipping away at NVD backlog appeared first on Help Net Security.