Aggregator
CVE-2025-62222 | Microsoft Visual Studio Code CoPilot Chat Extension Agentic AI command injection (EUVD-2025-93395)
CVE-2025-62449 | Microsoft Visual Studio Code CoPilot Chat Extension path traversal (EUVD-2025-93394)
CVE-2025-62453 | Microsoft Visual Studio Code protection mechanism (EUVD-2025-93392)
CVE-2025-30398 | Microsoft Nuance PowerScribe 360 information disclosure (EUVD-2025-93391)
CVE-2025-62206 | Microsoft Dynamics 365 information disclosure (EUVD-2025-93431)
New Quantum Route Redirect Tool Lets Attackers Launch One-Click Phishing Attacks on Microsoft 365 Users
A sophisticated phishing campaign is targeting Microsoft 365 users worldwide through a newly discovered tool called Quantum Route Redirect. This advanced automation platform transforms complex phishing operations into simple one-click attacks that evade traditional security measures. The campaign has already affected victims across 90 countries, with the United States accounting for 76% of the targets. […]
The post New Quantum Route Redirect Tool Lets Attackers Launch One-Click Phishing Attacks on Microsoft 365 Users appeared first on Cyber Security News.
光棍节开放注册四小时共注册26414人,没有激活的同学请尽快激活啦,发帖前请认真阅读注册须知和总版规,防止违规封号注销。 刚加入的同学请经常登录并保持活跃(注意:签到不算活跃,只有发帖或回帖才算,这句话很重要),避免没活跃被清理,参与到论坛交流中来,对于给予帮助你的人加热心和论坛币,做一个热心受欢迎的人。 错过的同学可以“星标”公众号等待下次开放注册通知。
信息安全漏洞周报(2025年第45期)
Linux Crypto Speeds Up: New Patches Deliver 53% Faster HCTR2 Mode
Google engineer Eric Biggers has once again turned his attention to enhancing the performance of Linux’s cryptographic subsystem.
The post Linux Crypto Speeds Up: New Patches Deliver 53% Faster HCTR2 Mode appeared first on Penetration Testing Tools.
Ditch the Terminal: How to Get a Beginner-Friendly App Store on Linux (KDE Discover)
For many Linux users, software management still evokes associations with console commands, tangled dependency chains, and the constant
The post Ditch the Terminal: How to Get a Beginner-Friendly App Store on Linux (KDE Discover) appeared first on Penetration Testing Tools.
Windows 11 Version 26H1 is Coming—But Only for New Snapdragon X2 ARM Chips
Microsoft has confirmed that it is preparing a new Windows 11 build labeled 26H1, though the release is
The post Windows 11 Version 26H1 is Coming—But Only for New Snapdragon X2 ARM Chips appeared first on Penetration Testing Tools.
CVE-2023-26846 | OpenCATS 0.9.7 index.php?m=candidates city cross site scripting (EUVD-2023-30638)
CVE-2023-26845 | OpenCATS 0.9.7 Web Request cross-site request forgery (EUVD-2023-30637)
CVE-2023-26843 | ChurchCRM 4.5.3 NoteEditor.php cross site scripting (EUVD-2023-30635)
VPN Boom & Ban Threat: Subscriptions Soar 1,400% as US/UK Eye Restrictions
Hundreds of millions of smartphone users have found themselves facing blocks on adult websites and mandatory age verification
The post VPN Boom & Ban Threat: Subscriptions Soar 1,400% as US/UK Eye Restrictions appeared first on Penetration Testing Tools.
Windows 11 Tests Haptic Feedback: Get a ‘Buzz’ When Snapping Windows
Microsoft continues to experiment with new interface features in Windows 11, and this time the spotlight has fallen
The post Windows 11 Tests Haptic Feedback: Get a ‘Buzz’ When Snapping Windows appeared first on Penetration Testing Tools.
2025年网络安全“金帽子”年度评选活动投票通道正式开启!
在智能技术深度融合的当下,网络安全已不仅仅是纯粹的技术议题,更是支撑社会运转的重要基石。伴随生成式人工智能、隐私计算等新一代信息技术的快速迭代,整个安全格局正在经历一场静默而深刻的重塑。此背景下,既催生出防护能力的全新可能,也带来了数据治理、模型可信与合规等前所未有的挑战。在这个技术边界不断流动的时代,众多网络安全企业正扮演者着务实而开放的探索者角色,他们用扎实的代码与可持续的方案,守护着每一次连接背后的信任。
为见证那些优秀企业一年来付出的努力与成果,“金帽子”年度评选活动始终愿意成为这样一片土壤:不设门槛,不贴标签,只关注那些真正推动行业前进的实践与思考,致力于推动网络安全事业不断前进。
目前,2025年网络安全“金帽子”年度评选活动经过全行业的公开报名与基础审核,现已开启投票通道,对征集到的优秀企业、团队和多款安全产品、方案等奖项展开线上投票评选。投票截止时间为11月28日中午12:00,获奖榜单最终将于12月8日在全行业进行公布。欢迎大家参与投票活动,选出您心中的网络安全优质项目。
本届评选奖项:
1、年度优秀安全产品
2、年度优秀行业解决方案
3、年度优秀AI安全创新应用
4、年度行业影响力
5、年度优秀团队品牌
6、年度优秀典型案例
7、年度杰出安全服务商
评选投票规则
本届网络安全“金帽子”年度评选活动,由大众投票占比40%,专家投票占比60%进行综合考量。
同时评选系统对恶意刷票行为制定了预防机制,评选过程公开、客观、公正。大众可通过PC端、手机端等多渠道参与,每天每人每项有1票的投票数量。
投票方式
1、网站投票方式
PC端或手机端登录嘶吼官网点击首页专题栏,进入2025年”网络安全金帽子年度评选”页面,下拉至「评选奖项」再点击喜欢企业下方的“投票”按钮即可投票。
网站投票入口:https://www.4hou.com/golden-hat-2025
2、微信投票方式
扫描下方二维码,即可进入投票页面进行投票,同时也可了解各奖项的投票情况。
助力海报
企业助力海报获取方式:
用PC端或手机端进入“2025网络安全金帽子年度评选”专题页面,进入你要投票的企业,点击企业下方的“助力海报”自动生成投票海报,分享至好友或朋友圈,对方可直接进入企业页面进行投票。
防不正当竞争说明
网络安全“金帽子”奖旨在推动网络安全行业良性发展,禁止参选企业与个人,通过刷票等不公平的方式获得奖项。
如在投票阶段发现参选企业或个人使用不限于自动化程序的方式刷票,嘶吼有权直接在统计过程中去除相关数据且无需进行说明;如发现参选企业或个人持续进行不限于自动化程序的方式进行刷票,嘶吼有权暂停该参选企业或个人继续参与本次投票活动。
投票通道现已启动!嘶吼再次号召大家积极参与到2025年网络安全“金帽子”年度评选投票之中,为网络安全事业贡献自己的力量,共同构建一个更加安全、可靠的网络环境。在此,也预祝各参选企业在本次评选中荣获佳绩!
OnDemand | Analyst Insights: Building Cyber Resilience Through Proactive Recovery Strategies
Nacha Revises Fraud Monitoring Rules for FIs
Nacha's 2026 rule amendments pivot from "commercially reasonable" to "reasonably intended" fraud detection standards. Nacha's Devon Marsh explains what this shift means for RDFIs and ODFIs and how banks and financial institutions can define and demonstrate reasonable practices.