Aggregator
Operese — утилита, которая знает, как выжить после Windows 10
2 months ago
Возможно, ваш старый ноутбук отлично справится с Linux.
【安全圈】数字猎手揭开印度假币帝国:人脸识别与GPS技术如何摧毁2亿美元的黑色产业链
2 months ago
关键词网络犯罪2025年夏,孟买郊外一家数码印刷厂内,工业级喷墨打印机昼夜不停地吞吐着特殊纸张。
【安全圈】电竞外设惊现"傀儡鼠标":黑客借官方驱动植入Xred病毒入侵百万玩家
2 months ago
关键词网络病毒2025年夏,电竞圈爆发一场隐秘的数字瘟疫。
【安全圈】千万保单背后的暗战:全美人寿1.4亿客户数据遭"少年黑客团"攻陷始末
2 months ago
关键词数据泄露2025年7月16日凌晨,明尼阿波利斯市的全美人寿(Allianz Life)数据中心警报骤响。
【安全圈】微软365全球管理后台"停摆危机":企业数字化命脉的72小时断流警报
2 months ago
关键词Microsoft2025年7月24日晨间,当纽约证券交易所的科技股分析师们打开电脑时,一场悄无声息的数
Весь интернет держится на вере в нерешаемую задачку. Решат — и мы снова в каменном веке
2 months ago
Спасти нас могут… только кубиты?
CVE-2025-8266 | yanyutao0402 ChanCMS up to 3.1.2 collect.js getArticle targetUrl deserialization (ICLP61)
2 months ago
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the file app/modules/cms/controller/collect.js. The manipulation of the argument targetUrl leads to deserialization.
This vulnerability is known as CVE-2025-8266. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Iranian-Linked Cyber Group The Returnees Claims Major Attack on Israeli Defense Contractor
2 months ago
You must login to view this content
cohenido
CVE-2025-54597 | LinuxServer.io Heimdall up to 2.7.2 q cross site scripting (EUVD-2025-22806)
2 months ago
A vulnerability, which was classified as problematic, was found in LinuxServer.io Heimdall up to 2.7.2. Affected is an unknown function. The manipulation of the argument q leads to cross site scripting.
This vulnerability is traded as CVE-2025-54597. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6241 | Lakeside SyStrack prior 10.10.0.42 Environment Variable LsiAgent.exe SYSTEM PATH uncontrolled search path (EUVD-2025-22805)
2 months ago
A vulnerability, which was classified as problematic, has been found in Lakeside SyStrack. This issue affects some unknown processing of the file LsiAgent.exe of the component Environment Variable Handler. The manipulation of the argument SYSTEM PATH leads to uncontrolled search path.
The identification of this vulnerability is CVE-2025-6241. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #622170: yanyutao0402 https://gitee.com/yanyutao0402/ChanCMS <3.1.3 Remote Code Execution [Accepted]
2 months ago
Submit #622170 / VDB-317857
ZAST.AI
CVE-2025-5120 | huggingface smolagents up to 1.14.0 local_python_executor.py sandbox (EUVD-2025-22815)
2 months ago
A vulnerability classified as critical was found in huggingface smolagents up to 1.14.0. This vulnerability affects unknown code of the file local_python_executor.py. The manipulation leads to sandbox issue.
This vulnerability was named CVE-2025-5120. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
«Права и лица — заходи, пока не закрыли!» Утечка Tea App стала пиром для 4chan
2 months ago
Сервис для защиты женщин слил их паспорта, селфи и переписки на потеху 4chan.
Наука — это не правда, а поиск. Но общество хочет приговора
2 months ago
Как превратить гения в идиота за 5 минут? Показать его ошибки.
Один email — и миллиардная дроновая империя Турции рухнула за 30 секунд
2 months ago
Как хакеры Patchwork обокрали оборонку через фальшивую конференцию.
WAIC 2025:AI 肯定继续成长,避免变成「终极反派」是人类难题
2 months ago
不是共识的共识。
Stack Exchange 迁移到云端
2 months ago
编程问答平台 Stack Exchange 宣布迁移到云端,放弃使用自己的服务器。Stack Exchange 自 2010 年起就在新泽西州的数据中心托管旗下网站,它使用了大约 50 台服务器。如果服务器出现问题,工程师需要去现场更换或重启硬件。2023 年它的 Stack Overflow for Teams 迁移到了微软的 Azure 云,现在 Stack Overflow 和 Stack Exchange 网络托管在了 Google Cloud 云服务上。Stack Overflow 从此不再拥有任何物理数据中心或办公室,完全在云端远程工作。
Ученые открыли новое квантовое состояние материи для компьютеров будущего
2 months ago
Новая фаза материи может перевернуть представления о проводимости.
Week in review: Microsoft SharePoint servers under attack, landing your first cybersecurity job
2 months ago
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft pins on-prem SharePoint attacks on Chinese threat actors As Microsoft continues to update its customer guidance for protecting on-prem SharePoint servers against the latest in-the-wild attacks, more security firms have begun sharing details about the ones they have detected. How to land your first job in cybersecurity According to LinkedIn, job applications have surged over 45% in the past … More →
The post Week in review: Microsoft SharePoint servers under attack, landing your first cybersecurity job appeared first on Help Net Security.
Help Net Security