Aggregator
CVE-2024-45258 | req Package up to 3.43.3 on Go URL cleanHost missing initialization
4 months 2 weeks ago
A vulnerability classified as critical was found in req Package up to 3.43.3 on Go. This vulnerability affects the function cleanHost of the component URL Handler. The manipulation leads to missing initialization of a variable.
This vulnerability was named CVE-2024-45258. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8158 | 9front lib9p authorization
4 months 2 weeks ago
A vulnerability classified as critical has been found in 9front. This affects an unknown part of the component lib9p. The manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2024-8158. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
新型投递器PEAKLIGHT Downloader 部署在针对 Windows 的恶意电影下载攻击中
4 months 2 weeks ago
安全客
新恶意软件 Cthulhu Stealer 以 Apple macOS 用户为目标
4 months 2 weeks ago
安全客
谷歌 Chrome 浏览器更新修复了被恶意利用的漏洞(CVE-2024-7971)
4 months 2 weeks ago
安全客
CVE-2024-41996 | Diffie-Hellman Key Agreement Protocol Order D(HE)at resource consumption
4 months 2 weeks ago
A vulnerability was found in Diffie-Hellman Key Agreement Protocol. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Order Handler. The manipulation leads to resource consumption.
This vulnerability is handled as CVE-2024-41996. The attack may be launched remotely. There is no exploit available. This vulnerability has a historic impact due to its background and reception.
vuldb.com
职场黑神话:TA竟让天命打工人秒变苦命猴子
4 months 2 weeks ago
安全客
网络身份证是强制,会影响正常上网?公安部详细回应
4 months 2 weeks ago
网号是由字母和数字组成、不含明文身份信息的网络身份符号;网证是承载网号及自然人非明文身份信息的网络身份认证凭证。
CVE-2014-5623 | penguinchefshop 1.0.1 X.509 Certificate cryptographic issues (VU#582497)
4 months 2 weeks ago
A vulnerability was found in penguinchefshop 1.0.1. It has been classified as critical. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-5623. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2007-1401 | PHP 4.4.6 CrackLib memory corruption (EDB-3431 / XFDB-33032)
4 months 2 weeks ago
A vulnerability has been found in PHP 4.4.6 and classified as critical. This vulnerability affects unknown code of the component CrackLib. The manipulation leads to memory corruption.
This vulnerability was named CVE-2007-1401. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
vuldb.com
COBIT框架下的AI安全治理与优化
4 months 2 weeks ago
在数字时代,人工智能(AI)和机器学习(ML)正在成为创新的基石,企业面临有效治理这些技术的挑战。由ISACA […]
aqniu
《黑神话:悟空》火爆导致Steam崩溃?官方回应:受到DDoS攻击 ;新型安卓恶意软件可利用NFC技术窃取银行卡信息 | 牛览
4 months 2 weeks ago
新闻速览 •应对离地攻击威胁,NSA联合发布一项新的网络安全指南 •美国联邦航空管理局为飞行器通讯安全提出新规 […]
aqniu
FreeBuf 全球网络安全产业投融资观察(7月)
4 months 2 weeks ago
据多方资料不完全统计,2024年7月共记录到全球网络安全行业投融资事件45起,与上月相比增加6起。其中国内4起,国外41起。
CVE-2014-5622 | Mobbtech Follow Mania for Instagram 1.2.1 X.509 Certificate cryptographic issues (VU#582497)
4 months 2 weeks ago
A vulnerability was found in Mobbtech Follow Mania for Instagram 1.2.1 and classified as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-5622. The attack can only be done within the local network. There is no exploit available.
vuldb.com
魔方最新黑科技!全球首个语音指挥 FPS AI 队友 F.A.C.U.L. 亮相科隆|AGI 掘金资讯
4 months 2 weeks ago
酱酱们中午好~今天的 AGI 掘金热点资讯来啦,我们知识库上线了 AI 小助手,欢迎来撩!
抖音集团招聘 | 广告业务2025校招已启动!七大类技术岗热招
4 months 2 weeks ago
澳大利亚工人下班后有权拒绝工作邮件和工作电话
4 months 2 weeks ago
旨在遏制工作邮件和工作电话入侵个人生活的新法律于本周一生效,从现在开始,澳大利亚工人在下班后有权拒绝工作邮件和电话而不会受到惩罚。澳大利亚斯威本科技大学副教授 John Hopkins 表示,在数字技术发明前,工人们都是下班后回家到第二天上班前都不会有联系。但在今天,即使在休假,员工对于收到工作邮件、电话和短信都习以为常了。根据澳大利亚研究所去年的一项调查,2023 年澳大利亚人平均无偿加班 281 小时,调查估计此类无偿劳动的货币价值为 1300 亿澳元。法国最早在 2017 年引入了法律限制下班后的工作邮件和电话。澳大利亚的法律没有限制应对紧急情况和工作时间不规律的工作,此类工作允许雇主联系员工。
CVE-2002-0118 | Infopop Ultimate Bulletin Board 6.2.0 IMG Tag cross site scripting (EDB-21209 / XFDB-7838)
4 months 2 weeks ago
A vulnerability was found in Infopop Ultimate Bulletin Board 6.2.0. It has been classified as problematic. This affects an unknown part of the component IMG Tag Handler. The manipulation leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2002-0118. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Threads 测试允许帖子在 24 小时后消失
4 months 2 weeks ago
Meta 旗下的微博客应用 Threads 正在测试允许用户给帖子设置倒计时如 24 小时的功能,时间截至之后帖子就不再显示。Instagram 负责人 Adam Mosseri 几个月曾透露在测试被称为自动归档的可选功能,允许用户指定一个日期,让他们发布的帖子从信息流中隐藏。新的功能正在一小部分用户中进行测试。批评者认为这项功能容易被滥用去传播虚假信息,减少传播者的责任。