Aggregator
CVE-2022-44654 | Trend Micro Apex One/Apex One as a Service /SAFESEH protection mechanism
CVE-2025-3957 | opplus springboot-admin 1.0 SysLogDao.xml order sql injection
CVE-2025-3958 | withstars Books-Management-System 1.0 Book Edit Page /book_edit_do.html Name cross site scripting
CVE-2025-42599 | QUALITIA Active Mail up to 6.60.050085 Request stack-based overflow
云上LLM数据泄露风险研究系列(三):开源大模型应用的攻击面分析
云上LLM数据泄露风险研究系列(三):开源大模型应用的攻击面分析
Kovrr Launches First-Ever CRQ-Powered Cyber Risk Register
Articles related to cyber risk quantification, cyber risk management, and cyber resilience.
The post Kovrr Launches First-Ever CRQ-Powered Cyber Risk Register appeared first on Security Boulevard.
大模型时代,百度智能云迎来最大机会
Finding Minhook in a sideloading attack – and Sweden too
Threat Actors Hacking SAP Critical Zero-Day
Threat actors are exploiting a zero-day flaw in a partially deprecated SAP tool still widely used by governments and businesses. On Friday, SAP's security division, Onapsis, disclosed that CVE-2025-31324 is "actively exploited in the wild."
Employee Benefits Firm Says 4 Million Affected by 2024 Hack
Employee benefits administrator Verisource Services Inc. has told regulators that a hack discovered in February 2024 has affected 4 million individuals, up significantly from initial estimates reported last summer. The company already faces several lawsuits involving its earlier lowball estimates.
ISMG Editors: Day 1 Overview of RSAC Conference 2025
ISMG Editors convened in San Francisco for coverage of RSAC Conference. Panelists shared an overview of opening-day speakers and hot topics, including the growth of AI, uncertainties in the global threat landscape, the Innovation Sandbox contest and Cryptographers' Panel session.
HHS Fines Neurology Practice $25K for Ransomware Attack
Federal regulators fined a New York neurology practice $25,000 following an investigation into a 2020 ransomware breach affecting nearly 7,000 individuals. Comprehensive Neurology failed to conduct an accurate and thorough risk analysis, regulators said.
Google: 97 zero-days exploited in 2024, over 50% in spyware attacks
Phishing 3.0: Trust, Deepfakes, and Why Your Inbox Might Betray You
In his recent post, our CEO, Eyal Benishti, sounded the phishing alarm for all to hear. The message? The traditional foundation of digital business communication, trust, is collapsing under the weight of AI-driven attacks.
The post Phishing 3.0: Trust, Deepfakes, and Why Your Inbox Might Betray You appeared first on Security Boulevard.
Zero-Day Exploitation Figure Surges 19% in Two Years
Vulnerability Exploitation Is Shifting in 2024-25
More From Our Main Blog: Agentic Cyber Defense Defined | The Purple AI Athena Release
Discover how SentinelOne’s Purple AI Athena Release uses agentic AI to revolutionize threat detection, investigation, and automated response.
The post Agentic Cyber Defense Defined | The Purple AI Athena Release appeared first on SentinelOne.