Aggregator
CVE-2024-58266 | comex shlex Crate up to 1.2.0 on Rust escape output (GHSA-r7qv-8r2h-pg27)
CVE-2023-53157 | rosenpass Crate up to 0.2.0 on Rust UDP Packet length parameter (GHSA-6ggr-cwv4-g7qg)
CVE-2023-53159 | sfackler openssl Crate up to 0.10.54 on Rust set_host buffer over-read (ID 1965)
CVE-2023-53158 | GitoxideLabs gix-transport Crate up to 0.36.0 on Rust Username os command injection (GHSA-rrjw-j4m2-mf34)
知名保险公司安联人寿泄露140万客户详细信息 疑似员工被钓鱼泄露CRM权限
The legal minefield of hacking back
In this Help Net Security interview, Gonçalo Magalhães, Head of Security at Immunefi, discusses the legal and ethical implications of hacking back in cross-border cyber incidents. He warns that offensive cyber actions risk violating international law, escalating conflicts, and harming innocent third parties. Instead, Magalhães advocates for legally sanctioned frameworks, such as bug bounty programs, to strengthen security without crossing dangerous lines. How do international laws complicate the use of hacking back, especially in cross-border … More →
The post The legal minefield of hacking back appeared first on Help Net Security.
«Поздравляем, вы выиграли 1,275 биткойна!» — говорит Google Forms. Не верьте
CVE-2022-50237 | dalek-cryptography ed25519-dalek Crate up to 1 on Rust exposure of sensitive system information to an unauthorized control sphere (RUSTSEC-2022-0093)
CVE-2005-1633 | JGS-XA JGS-Portal 3.0.2 jgs_portal.php ID sql injection (EDB-25673 / Nessus ID 18289)
CVE-2005-1479 | Jgs-xa JGS-Portal 3.0.1 jgs_portal.php ID sql injection (EDB-25570 / XFDB-20371)
vivo开源由Rust开发的BlueOS蓝河内核 似乎主要是针对物联网设备的
Vulnhuntr: Open-source tool to identify remotely exploitable vulnerabilities
Vulnhuntr is an open-source tool that finds remotely exploitable vulnerabilities. It uses LLMs and static code analysis to trace how data moves through an application, from user input to server output. This helps it spot complex, multi-step vulnerabilities that traditional tools often miss. “Vulnhuntr is basically one of the first LLM agents, before people were even talking about LLM agents. The core challenge is that you can’t just feed an entire codebase to an LLM. … More →
The post Vulnhuntr: Open-source tool to identify remotely exploitable vulnerabilities appeared first on Help Net Security.