Aggregator
议题征集|“智效融合,安全护航”第七期「度安讲」 技术沙龙议题报名!
1 year 4 months ago
【内含福利】第七期「度安讲」技术沙龙议题征集!
Confucius组织利用ADS隐藏技术的攻击活动分析
1 year 4 months ago
Confucius组织在本次攻击行动中使用了ADS(Alternate Data Streams)特性来隐藏恶意文件,这种技术在之前该组织的攻击活动中未出现过。鉴于此,我们将重点披露该组织使用ADS加载恶意组件的整个流程
苹果悬赏百万美元查找“苹果智能”安全漏洞
1 year 4 months ago
开源情报显威!利用社交APP实时跟踪美俄法等国总统行踪
1 year 4 months ago
官方称不存在风险
QNAP patches second zero-day exploited at Pwn2Own to get root
1 year 4 months ago
QNAP has fixed a second zero-day vulnerability exploited at the Pwn2Own Ireland 2024 hacking contest to gain a root shell and take over a TS-464 NAS device. [...]
Sergiu Gatlan
资料下载 | 江西“数据要素×”、自治区数据要素市场化配置改革、网络安全产业分析报告、车路云一体化...
1 year 4 months ago
·政策
《江西省“数据要素×”三年行动实施方案(2024-2026年)》
《自治区数据要素市场化配置改革实施意见(征求意见稿)》
·报告
《中国网络安全产业分析报告(2024年)》
《车路云一体化系统建设与应用指南》
会议观察:“可观测性+应用安全”正在加速融合
1 year 4 months ago
从可观测性与应用安全技术研讨会上了解基调听云最新技术实践。
CVE-2004-1540 | ZyXEL ZyNOS 3.40/Is.3/Is.5 Configuration File rpfwupload.html denial of service (EDB-24760 / Nessus ID 15781)
1 year 4 months ago
A vulnerability was found in ZyXEL ZyNOS 3.40/Is.3/Is.5. It has been declared as problematic. This vulnerability affects unknown code of the file rpfwupload.html of the component Configuration File. The manipulation leads to denial of service.
This vulnerability was named CVE-2004-1540. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
A Threat Actor Allegedly Leaked Databases of KVacDoor
1 year 4 months ago
A Threat Actor Allegedly Leaked Databases of KVacDoor
Dark Web Informer
Тест Толкина против Тьюринга: Может ли ИИ создать свой Средиземье?
1 year 4 months ago
Почему технология не может конкурировать с человеческим творчеством.
《政务大模型安全治理框架》: 揭示七大安全风险、提供治理路径
1 year 4 months ago
奇安信集团发布首个《政务大模型安全治理框架》
LiteSpeed Cache Plugin Vulnerability Poses Admin Access Risk
1 year 4 months ago
The LiteSpeed Cache vulnerability allows administrator-level access, risking security for over 6 million WordPress sites
News alert: Cybersecurity, AI priorities for 2025 highlighted at ATPC Cyber Forum in Atlanta
1 year 4 months ago
Atlanta, GA, Oct. 30, 2024, CyberNewswire — The American Transaction Processors Coalition (ATPC) Cyber Council will convene “The Tie that Binds: A 21st Century Cybersecurity Dialogue,” on October 31, 2024, at the Bank of America Financial Center Tower’s Convention Hall … (more…)
The post News alert: Cybersecurity, AI priorities for 2025 highlighted at ATPC Cyber Forum in Atlanta first appeared on The Last Watchdog.
The post News alert: Cybersecurity, AI priorities for 2025 highlighted at ATPC Cyber Forum in Atlanta appeared first on Security Boulevard.
cybernewswire
Стрела времени течёт в обе стороны: 50 000 квантовых уровней раскрыли тайну реальности
1 year 4 months ago
Уникальные модели раскрывают, как параллельные миры образуют стабильные структуры.
A Threat Actor is Allegedly Selling Admin Access of an Unidentified Shop in Australia
1 year 4 months ago
A Threat Actor is Allegedly Selling Admin Access of an Unidentified Shop in Australia
Dark Web Informer
ASCIRES Has Been Claimed a Victim to Dragon Ransomware
1 year 4 months ago
ASCIRES Has Been Claimed a Victim to Dragon Ransomware
Dark Web Informer
论文解读:《将LLM用于网络犯罪论坛的威胁情报》
1 year 4 months ago
随着大语言模型(LLM)的发展,研究显示其在网络威胁情报(CTI)提取中具备高效性和准确性。蒙特利尔大学等机构的研究用GPT-3.5-turbo模型从网络犯罪论坛提取关键信息,取得98%的准确率,为CTI自动化分析提供了新方向。
Cybersecurity Training Resources Often Limited to Developers
1 year 4 months ago
With a lack of cybersecurity awareness training resources for all employees, organizations are more susceptible to being breached or falling short when it comes to preventing threats.
Dark Reading Staff
CVE-2024-51258 | DrayTek Vigor 3900 1.5.1.3 mainfunction.cgi doSSLTunnel command injection
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in DrayTek Vigor 3900 1.5.1.3. This issue affects the function doSSLTunnel of the file mainfunction.cgi. The manipulation leads to command injection.
The identification of this vulnerability is CVE-2024-51258. The attack may be initiated remotely. There is no exploit available.
vuldb.com