Aggregator
腾讯安全市占率领跑!艾瑞咨询最新威胁情报市场报告出炉
1 year 3 months ago
Chinese Cyber Espionage Jumps 150%, CrowdStrike Finds
1 year 3 months ago
In its 2025 Global Threat Report, CrowdStrike observed a significant escalation in Chinese cyber espionage activities
新型Linux后门病毒Auto-color瞄准美国和亚洲系统
1 year 3 months ago
新型Linux后门病毒Auto-color利用隐身技术,针对北美和亚洲教育及政府机构进行攻击,操纵系统功能并隐藏网络活动,构成重大威胁。
FreeBuf早报 | Bybit 遭黑客攻击事件溯源;微软合作伙伴中心存在高危漏洞
1 year 3 months ago
攻击源自 Safe{Wallet} 的 AWS 基础设施,Bybit 自身基础设施未被攻击。
Authorities Arrested Hackers Behind 90 Data Leaks Worldwide
1 year 3 months ago
Authorities arrested a prolific hacker responsible for over 90 data breaches across 65 organizations in the Asia-Pacific region and 25 additional global targets. The cybercriminal, operating under aliases ALTDOS, DESORDEN, GHOSTR, and 0mid16B, exfiltrated 13 terabytes of sensitive data between 2020 and February 2025, targeting industries ranging from healthcare to finance. The operation marks a […]
The post Authorities Arrested Hackers Behind 90 Data Leaks Worldwide appeared first on Cyber Security News.
Kaaviya
CVE-2015-1379 | Socat up to 1.7.2/2.0.0-b7 Signal input validation (Nessus ID 216897 / BID-72321)
1 year 3 months ago
A vulnerability was found in Socat up to 1.7.2/2.0.0-b7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Signal Handler. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2015-1379. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1390 | OpenAnolis Anolis OS 2.73;0 Group Name pam_cap.so access control (Nessus ID 216893)
1 year 3 months ago
A vulnerability classified as critical has been found in OpenAnolis Anolis OS 2.73;0. This affects an unknown part of the file pam_cap.so of the component Group Name Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-1390. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-26599 | Red Hat Enterprise Linux 6/7/8/9 X.org X11 Server/TigerVNC compCheckRedirect uninitialized pointer (Nessus ID 216902)
1 year 3 months ago
A vulnerability was found in Red Hat Enterprise Linux 6/7/8/9. It has been rated as critical. This issue affects the function compCheckRedirect of the component X.org X11 Server/TigerVNC. The manipulation leads to uninitialized pointer.
The identification of this vulnerability is CVE-2025-26599. It is possible to launch the attack on the local host. There is no exploit available.
vuldb.com
CVE-2011-1866 | HP OpenView Storage Data Protector up to 6.10 omniinet.exe memory corruption (EDB-17461 / Nessus ID 55551)
1 year 3 months ago
A vulnerability was found in HP OpenView Storage Data Protector up to 6.10. It has been classified as very critical. Affected is an unknown function of the file omniinet.exe of the component HP OpenView. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2011-1866. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-26596 | Red Hat Enterprise Linux 6/7/8/9 X.org X11 Server/TigerVNC XkbSizeKeySyms heap-based overflow (Nessus ID 216902)
1 year 3 months ago
A vulnerability was found in Red Hat Enterprise Linux 6/7/8/9 and classified as critical. Affected by this issue is the function XkbSizeKeySyms of the component X.org X11 Server/TigerVNC. The manipulation leads to heap-based buffer overflow.
This vulnerability is handled as CVE-2025-26596. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-26594 | Red Hat Enterprise Linux 6/7/8/9 X.org X11 Server/TigerVNC use after free (Nessus ID 216902)
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in Red Hat Enterprise Linux 6/7/8/9. This issue affects some unknown processing of the component X.org X11 Server/TigerVNC. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2025-26594. Attacking locally is a requirement. There is no exploit available.
vuldb.com
NVIDIA针对Jetson AGX Orin和IGX Orin发布安全更新,以修复UEFI漏洞(CVE-2024-0148)
1 year 3 months ago
安全客
CVE-2024-49507 | Adobe InDesign Desktop up to 18.5.3/19.5 heap-based overflow (apsb24-88 / Nessus ID 211462)
1 year 3 months ago
A vulnerability was found in Adobe InDesign Desktop up to 18.5.3/19.5. It has been classified as critical. Affected is an unknown function. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-49507. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
GrassCall: фейковые работодатели опустошили кошельки соискателей
1 year 3 months ago
Поиск работы превратился в игру на деньги.
【安全圈】CVE-2025-20029:F5 BIG-IP系统发现命令注入漏洞,概念验证已发布
1 year 3 months ago
【安全圈】DISA 透露,2024 年的数据泄露影响了超过 330 万人
1 year 3 months ago
【安全圈】瑞典要求加密通信应用部署后门,Signal强烈反对
1 year 3 months ago
【安全圈】央视揭露电诈新手段:“手机口”成诈骗分子的“隐形传声筒”
1 year 3 months ago
Bybit遭窃事件:Safe{Wallet}漏洞被利用,14亿美元以太坊被盗
1 year 3 months ago
安全客