Aggregator
.NET 一款通过API实现的免杀WebShell
1 year 5 months ago
NGINX站点开启HTTP/3 提升网站速度与安全性
1 year 5 months ago
介绍
随着互联网技术的不断发展,用户对于网站加载速度和安全性的需求越来越高。HTTP/3作为最新的网络协议,通过采用QUIC传输层协议,进一步提升了网页传输的效率和安全性。相比HTTP/2,HT...
黑海洋
Cloudflare缓存加速技术,让网站飞起来
1 year 5 months ago
介绍
Cloudflare缓存加速技术主要通过将静态内容存储在其全球分布的CDN(内容分发网络)节点上,从而提高网站的加载速度和性能。以下是一些主要特性和优势:
全球CDN:Cloudflar...
黑海洋
Militairen zien af bij de Saramacca voor jungletraining
1 year 5 months ago
Hitte, dichte begroeiing, extreme hoge luchtvochtigheid en levensgevaarlijke planten en dieren. Voor militairen is geen gebied ter wereld zo uitdagend als de jungle. Daarom volgen militairen van de Luchtmobiele Brigade en het Korps Mariniers de loodzware Jungle Warfare Course. Want, als je het Surinaamse oerwoud aankunt, kun je alles aan.
Колумбус в заложниках у хакеров: горожане требуют правды, чиновники тянут время
1 year 5 months ago
Власти города уже три месяца не могут справиться с последствиями кибератаки.
SEC fined 4 companies for misleading disclosures about the impact of the SolarWinds attack
1 year 5 months ago
The SEC fined Unisys, Avaya, Check Point, and Mimecast for misleading disclosures about the impact of the SolarWinds Orion hack. The US Securities and Exchange Commission (SEC) charged four companies, Unisys, Avaya, Check Point, and Mimecast for misleading public disclosures related to the supply chain attack on SolarWinds. The SEC fined the four companies for […]
Pierluigi Paganini
CVE-2018-12463 | Fortify Software Security Center 17.1/17.2/18.1 XML Data XML Request xml external entity reference (EDB-45027 / ID 1041286)
1 year 5 months ago
A vulnerability classified as critical was found in Fortify Software Security Center 17.1/17.2/18.1. Affected by this vulnerability is an unknown functionality of the component XML Data Handler. The manipulation as part of XML Request leads to xml external entity reference.
This vulnerability is known as CVE-2018-12463. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
TLS нового поколения: почему AWS и Google инвестируют в Rustls?
1 year 5 months ago
Новая библиотека бросает вызов языку C.
制造巨头海量数据被勒索公开!看威努特如何有效防治
1 year 5 months ago
勒索攻击形势严峻,数据泄露触目惊心,安全防御刻不容缓!
Stream.Security raises $30 million to boost cloud security
1 year 5 months ago
Stream.Security closed a $30 million Series B funding round led by U.S. Venture Partners, with participation from new investors, Citi Ventures, and existing investors, Energy Impact Partners (EIP), Cervin Ventures, TLV Partners, and Glilot Capital Partners VC. This new round of funding brings the total investment in Stream.Security to $55 million. Stream.Security’s Cloud Twin technology provides SecOps teams with real-time cloud threat and exposure modeling to accelerate response. As a result, SecOps teams can trust … More →
The post Stream.Security raises $30 million to boost cloud security appeared first on Help Net Security.
Industry News
Grafana认证后DuckDB-SQL注入漏洞(CVE-2024-9264)
1 year 5 months ago
Grafana认证后DuckDB-SQL注入漏洞(CVE-2024-9264)
US Energy Sector Vulnerable to Supply Chain Attacks
1 year 5 months ago
45% of security breaches in the energy sector in the past year were third-party related, according to a report by Security Scorecard and KPMG
CVE-2024-10293 | ZZCMS 2023 functions.php Ebak_SetGotoPak file unrestricted upload
1 year 5 months ago
A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/class/functions.php. The manipulation of the argument file leads to unrestricted upload.
This vulnerability is traded as CVE-2024-10293. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10292 | ZZCMS 2023 ChangeTable.php savefilename unrestricted upload
1 year 5 months ago
A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-10292. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10291 | ZZCMS 2023 phome.php Ebak_DoExecSQL/Ebak_DotranExecutSQL phome sql injection
1 year 5 months ago
A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_DoExecSQL/Ebak_DotranExecutSQL of the file 3/Ebak5.1/upload/phome.php. The manipulation of the argument phome leads to sql injection.
This vulnerability was named CVE-2024-10291. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10290 | ZZCMS 2023 inc.php information disclosure
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in ZZCMS 2023. This affects an unknown part of the file 3/qq-connect2.0/API/com/inc.php. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-10290. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
vuldb.com
Submit #427146: zzcms 2023 The file contains [Accepted]
1 year 5 months ago
Submit #427146 / VDB-281562
LVZC
Submit #427136: zzcms 2023 The file contains [Accepted]
1 year 5 months ago
Submit #427136 / VDB-281561
LVZC
Submit #427132: zzcms 2023 COMMAND EXECUTION [Duplicate]
1 year 5 months ago
Submit #427132 / VDB-281560
LVZC