Aggregator
Android malware "FakeCall" now reroutes bank calls to attackers
1 year 8 months ago
A new version of the FakeCall malware for Android hijacks outgoing calls from a user to their bank, redirecting them to the attacker's phone number instead. [...]
Bill Toulas
对话小宇宙 Kyth:AI 时代,如何重新理解播客的价值
1 year 8 months ago
谈谈 NotebookLM 等 AI 播客产品、播客破圈、与时代的「心灵避难所」。
CVE-2017-2473 | Apple iOS up to 10.2 Kernel memory corruption (HT207617 / EDB-41792)
1 year 8 months ago
A vulnerability was found in Apple iOS up to 10.2. It has been classified as critical. Affected is an unknown function of the component Kernel. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2017-2473. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-31621 | MariaDB up to 10.6 ds_xbstream.cc xbstream_open denial of service (MDEV-26574)
1 year 8 months ago
A vulnerability classified as problematic has been found in MariaDB up to 10.6. Affected is the function xbstream_open of the file extra/mariabackup/ds_xbstream.cc. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2022-31621. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-41716 | Google Go on Windows Environment Variable os/exec.Cmd syscall.StartProcess null byte or nul character
1 year 8 months ago
A vulnerability has been found in Google Go on Windows and classified as critical. This vulnerability affects the function syscall.StartProcess of the file os/exec.Cmd of the component Environment Variable Handler. The manipulation leads to improper neutralization of null byte or nul character.
This vulnerability was named CVE-2022-41716. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-46902 | Vocera Report Server/Voice Server up to 5.8 Unzip path traversal
1 year 8 months ago
A vulnerability was found in Vocera Report Server and Voice Server up to 5.8. It has been classified as critical. Affected is an unknown function of the component Unzip Handler. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2022-46902. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2022-48623 | Cpanel::JSON::XS up to 4.32 on Perl denial of service (Issue 208)
1 year 8 months ago
A vulnerability was found in Cpanel::JSON::XS up to 4.32 on Perl and classified as problematic. This issue affects some unknown processing. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2022-48623. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-45169 | Livebox Collaboration vDesk up to 031 Push Notification createnotification redirect
1 year 8 months ago
A vulnerability was found in Livebox Collaboration vDesk up to 031. It has been classified as problematic. This affects an unknown part of the file /api/v1/notification/createnotification of the component Push Notification Handler. The manipulation leads to open redirect.
This vulnerability is uniquely identified as CVE-2022-45169. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-28020 | Hitachi Energy FOXMAN-UN/UNEM incorrect user management
1 year 8 months ago
A vulnerability was found in Hitachi Energy FOXMAN-UN and UNEM. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to incorrect user management.
This vulnerability is handled as CVE-2024-28020. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-28022 | Hitachi Energy FOXMAN-UN/UNEM excessive authentication
1 year 8 months ago
A vulnerability classified as problematic has been found in Hitachi Energy FOXMAN-UN and UNEM. This affects an unknown part. The manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability is uniquely identified as CVE-2024-28022. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-6130 | 10Web Form Maker Plugin up to 1.15.25 on WordPress Setting cross site scripting
1 year 8 months ago
A vulnerability was found in 10Web Form Maker Plugin up to 1.15.25 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-6130. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6780 | TECNO Mobile Application 33 User Information permission
1 year 8 months ago
A vulnerability, which was classified as critical, was found in TECNO Mobile Application 33. Affected is an unknown function of the component User Information Handler. The manipulation leads to permission issues.
This vulnerability is traded as CVE-2024-6780. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
National Cyber Threat Assessment 2025-2026
1 year 8 months ago
The National Cyber Threat Assessment 2025-2026 highlights the cyber threats facing individuals and organizations in Canada and how they will evolve in the coming years.
Canadian Centre for Cyber Security
网络安全信息与动态周报2024年第43期(10月21日-10月27日)
1 year 8 months ago
本周,互联网网络安全态势整体评价为良。
PSAUX 勒索软件正在利用 CyberPanel 中的两个最大严重性漏洞 (CVE-2024-51567、CVE-2024-51568)
1 year 8 months ago
安全客
XM Cyber Vulnerability Risk Management boosts prioritization with actual impact analysis
1 year 8 months ago
XM Cyber launched its innovative Vulnerability Risk Management (VRM) solution, extending its Continuous Exposure Management Platform. This new approach to vulnerability management empowers organizations to see through the fog of false positives left behind by legacy vulnerability assessment tools and confidently embrace an innovative new security methodology. XM Cyber’s Vulnerability Risk Management provides an approach to discover, quantify, and reduce the risk presented by common vulnerabilities. By correlating CVE-related risk attributes with real-world attack techniques … More →
The post XM Cyber Vulnerability Risk Management boosts prioritization with actual impact analysis appeared first on Help Net Security.
Industry News
OpenAI 与博通和台积电合作设计 AI 芯片
1 year 8 months ago
为减少对英伟达 AI 芯片的依赖,OpenAI 正与博通和台积电合作设计自己的首款 AI 芯片,同时辅以 AMD 芯片作为补充。OpenAI 的首款芯片专注于推理,它组建了一支由大约 20 人的团队,由曾在 Google 开发 Tensor Processing Units(TPUs)的工程师领导,其中包括了 Thomas Norrie 和 Richard Ho。知情人士表示,OpenAI 的目标是在 2026 年制造芯片,但时间表可能会改变。英伟达的芯片占据了 AI 芯片市场的八成以上份额,但供不应求以及日益高涨的价格正迫使微软、Meta 和 OpenAI 等客户探索内部或外部替代方案。
CVE-2005-4285 | Dick Copits pdestore 1.8 Search Module pdestore.cgi module cross site scripting (EDB-26852 / BID-15898)
1 year 8 months ago
A vulnerability has been found in Dick Copits pdestore 1.8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file pdestore.cgi of the component Search Module. The manipulation of the argument module leads to basic cross site scripting.
This vulnerability is known as CVE-2005-4285. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
卫星互联网产业化提速
1 year 8 months ago
盛邦安全