Aggregator
【他是破案“魔术师”!】
4 months 2 weeks ago
组建了一支专业教官团队,带出了一批优秀的年轻教官... ...
Operation DevilTiger:APT-Q-12 使用 0day 漏洞技战术披露
4 months 2 weeks ago
攻击者在使用漏洞攻击前往往会进行非常复杂的信息收集,APT-Q-12使用多套复杂的邮件探针,周期性的向目标投递探针邮件以此来收集受害者的使用习惯和行为逻辑,包括常用的邮件平台、品牌,在针对不同office产品又会进行区别处理。
派早报:专家回应网号、网证热点问题
4 months 2 weeks ago
你可能错过的新鲜事专家回应网号、网证热点问题据新华社报道,近期,公安部、国家网信办等研究起草《国家网络身份认证公共服务管理办法(征求意见稿)》,向社会公开征求意见,引发广泛关注。新华社记者梳理当前
BlackSuit Ransomware
4 months 2 weeks ago
Key TakeawaysIn December 2023, we observed an intrusion that started with the execution of a Cob
BlackSuit Ransomware
4 months 2 weeks ago
Key Takeaways In December 2023, we observed an intrusion that started with the execution of a Cobalt Strike beacon and ended in the deployment of BlackSuit ransomware. The threat actor … Read More
editor
CVE-2015-5254 | Apache ActiveMQ up to 5.12.x Broker Service input validation (RHSA-2016:0489 / Nessus ID 87410)
4 months 2 weeks ago
A vulnerability was found in Apache ActiveMQ up to 5.12.x. It has been classified as very critical. This affects an unknown part of the component Broker Service. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2015-5254. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
又捕获一起0day!这次是禅道RCE
4 months 2 weeks ago
又一个!
CVE-2013-7389 | D-Link DIR-645 up to Frimware 1.03b08 authentication.cgi password cross site scripting (20130801-dlink-dir645 / EDB-27283)
4 months 2 weeks ago
A vulnerability classified as critical was found in D-Link DIR-645 up to Frimware 1.03b08. This vulnerability affects unknown code of the file authentication.cgi. The manipulation of the argument password as part of POST Request leads to cross site scripting.
This vulnerability was named CVE-2013-7389. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
「黑悟空」崩溃内幕:网络攻击暴增2万倍;微软AI码农平均薪酬高达270万;卡戴珊版Beats耳机开卖|极客早知道
4 months 2 weeks ago
周鸿祎再回应 360 儿童手表问答争议,惩罚产品经理去接一个月客服电话;
英伟达将公布 Blackwell 架构细节;
特斯拉 Model Y 焕新版伪装车现身美国湾区,换用贯穿式尾灯带;
美团 CEO 王兴发布内部邮件宣布公司最新架构调整
.NET内网实战:通过回调函数执行Shellcode
4 months 2 weeks ago
2024hvv | 32套.NET系统漏洞威胁情报(08.26更新)
4 months 2 weeks ago
.NET 一款通过白名单程序执行命令的工具
4 months 2 weeks ago
CVE-2014-5618 | fingersoft Cartoon Camera 1.2.2 X.509 Certificate cryptographic issues (VU#582497)
4 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in fingersoft Cartoon Camera 1.2.2. Affected by this issue is some unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-5618. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2005-0420 | Microsoft Exchange 2003 Outlook Web Access owalogon.asp information disclosure (EDB-25084 / Nessus ID 17636)
4 months 2 weeks ago
A vulnerability classified as problematic has been found in Microsoft Exchange 2003. Affected is an unknown function of the file owalogon.asp of the component Outlook Web Access. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2005-0420. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
网安行业的产品高质量道路
4 months 2 weeks ago
CVE-2007-1372 | PostGuestbook 0.6.1 header.php tpl_pgb_moddir file inclusion (EDB-3423 / XFDB-32866)
4 months 2 weeks ago
A vulnerability classified as very critical was found in PostGuestbook 0.6.1. This vulnerability affects unknown code of the file styles/internal/header.php. The manipulation of the argument tpl_pgb_moddir leads to file inclusion.
This vulnerability was named CVE-2007-1372. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Agentless Password Auditing for Linux White Paper
4 months 2 weeks ago
We have released a white paper on our powerful agentless password auditor for Linux. We discuss the
CVE-2014-5617 | Exsoul-browser Exsoul Web Browser 3.3.3 X.509 Certificate cryptographic issues (VU#582497)
4 months 2 weeks ago
A vulnerability classified as critical was found in Exsoul-browser Exsoul Web Browser 3.3.3. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-5617. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2014-5616 | Litter Penguin Web Browser! Explorer 2.0.7 X.509 Certificate cryptographic issues (VU#582497)
4 months 2 weeks ago
A vulnerability classified as critical has been found in Litter Penguin Web Browser! Explorer 2.0.7. Affected is an unknown function of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2014-5616. The attack needs to be done within the local network. There is no exploit available.
vuldb.com