Aggregator
.NET 红队武器库和资源集合 (第34期)
4 months 2 weeks ago
威胁情报周报(8.19~8.25)
4 months 2 weeks ago
一周情报速览~
【AI速读】美国陆军人才、生物、网络、气候、基地、现代化等系列战略报告
4 months 2 weeks ago
今天给大家推送美国陆军《统一网络计划》《数字转型战略》《生物防御战略》《基地战略》《人才战略》《机构战略》《气候战略》《现代化战略》等战略文件的AI解读。
Is AI Making Banking Safer or Just More Complicated?
4 months 2 weeks ago
As Banks Combat Fraud, Customers Feel the Strain of Overly Cautious Measures
In today’s AI-driven world, banks are becoming increasingly vigilant, often freezing accounts or demanding extensive documentation at the slightest hint of suspicious activity. Sending money, once a straightforward task, is now fraught with complexity.
In today’s AI-driven world, banks are becoming increasingly vigilant, often freezing accounts or demanding extensive documentation at the slightest hint of suspicious activity. Sending money, once a straightforward task, is now fraught with complexity.
A Tangled Web We Weave: When Reported M&A Never Materializes
4 months 2 weeks ago
Why Acquisition Reports Emerge in the Media, and What It Means for Those Mentioned
Companies historically responded to M&A reports with milquetoast statements about "not commenting on rumors or speculation," but aggressive clapbacks have become much more common. Increasingly, executives are willing to attract more publicity by publicly - and vocally - denying acquisition reports.
Companies historically responded to M&A reports with milquetoast statements about "not commenting on rumors or speculation," but aggressive clapbacks have become much more common. Increasingly, executives are willing to attract more publicity by publicly - and vocally - denying acquisition reports.
Medibank to Spend AU$126M on Post-Breach Security Upgrade
4 months 2 weeks ago
Australian Insurer Expects Years of Litigation Related to 2022 Hack
Australia's largest provider of private health insurance says it expects to spend a total of AU$126 million, or $84.78 million, over a three-year period to upgrade its IT security. A Russia-based cybercriminal group hacked Medibank in October 2022.
Australia's largest provider of private health insurance says it expects to spend a total of AU$126 million, or $84.78 million, over a three-year period to upgrade its IT security. A Russia-based cybercriminal group hacked Medibank in October 2022.
Banking Lobby Asks Ginnie Mae to Modify Cyber Reporting Rule
4 months 2 weeks ago
Banking and Housing Policy Groups Call New Cyber Reporting Measures 'Impractical'
A group of banking and housing lobbyists are urging Ginnie Mae to redo its latest set of cybersecurity incident reporting requirements for custodians of mortgage-backed securities, calling the new measures "impractical" and potentially burdensome for many organizations.
A group of banking and housing lobbyists are urging Ginnie Mae to redo its latest set of cybersecurity incident reporting requirements for custodians of mortgage-backed securities, calling the new measures "impractical" and potentially burdensome for many organizations.
Feds to Health Sector: Don't Skimp on Physical Security
4 months 2 weeks ago
Cyberattacks Soar, But Guarding PHI From Break-Ins, Natural Disasters Is Critical
Despite the endless barrage of cyberattacks hitting the healthcare sector, HIPAA-regulated entities must not neglect their duty to protect electronic patient information against physical threats, including burglaries and natural disasters, U.S. regulators said.
Despite the endless barrage of cyberattacks hitting the healthcare sector, HIPAA-regulated entities must not neglect their duty to protect electronic patient information against physical threats, including burglaries and natural disasters, U.S. regulators said.
Slack Patches Prompt Injection Flaw in AI Tool Set
4 months 2 weeks ago
Hackers Could Exploit Bug to Manipulate Slack AI's LLM to Steal Data
Chat app Slack patched a vulnerability in its artificial intelligence tool set that hackers could have exploited to manipulate an underlying large language model to phish employees and steal sensitive data. Slack said it was a low-severity bug.
Chat app Slack patched a vulnerability in its artificial intelligence tool set that hackers could have exploited to manipulate an underlying large language model to phish employees and steal sensitive data. Slack said it was a low-severity bug.
[webapps] Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Authentication Bypass
4 months 2 weeks ago
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Authentication Bypass
[webapps] Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Device Config
4 months 2 weeks ago
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x - Device Config
[webapps] Elber Wayber Analog/Digital Audio STL 4.00 - Authentication Bypass
4 months 2 weeks ago
Elber Wayber Analog/Digital Audio STL 4.00 - Authentication Bypass
[webapps] Elber Wayber Analog/Digital Audio STL 4.00 - Device Config Disclosure
4 months 2 weeks ago
Elber Wayber Analog/Digital Audio STL 4.00 - Device Config Disclosure
[webapps] HughesNet HT2000W Satellite Modem - Password Reset
4 months 2 weeks ago
HughesNet HT2000W Satellite Modem - Password Reset
[webapps] Aurba 501 - Authenticated RCE
4 months 2 weeks ago
Aurba 501 - Authenticated RCE
CVE-2024-8142 | SourceCodester Daily Calories Monitoring Tool 1.0 delete-calorie.php calorie cross site scripting
4 months 2 weeks ago
A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/delete-calorie.php. The manipulation of the argument calorie leads to cross site scripting.
This vulnerability was named CVE-2024-8142. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8141 | SourceCodester Daily Calories Monitoring Tool 1.0 add-calorie.php calorie_date/calorie_name cross site scripting
4 months 2 weeks ago
A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-calorie.php. The manipulation of the argument calorie_date/calorie_name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-8141. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8140 | SourceCodester Task Progress Tracker 1.0 update-task.php task_name cross site scripting
4 months 2 weeks ago
A vulnerability was found in SourceCodester Task Progress Tracker 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file update-task.php. The manipulation of the argument task_name leads to cross site scripting.
This vulnerability is handled as CVE-2024-8140. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8139 | itsourcecode E-Commerce Website 1.0 search_list.php user sql injection
4 months 2 weeks ago
A vulnerability has been found in itsourcecode E-Commerce Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file search_list.php. The manipulation of the argument user leads to sql injection.
This vulnerability is known as CVE-2024-8139. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com