Aggregator
网络犯罪分子利用 Darcula PhaaS v3 在几分钟内克隆任何品牌的网站
因政府要求加密后门,苹果在英取消 iCloud 高级数据保护功能
创纪录的 14.6 亿美元加密货币盗窃案为复杂冷钱包攻击所致
Windows应急分析工具-HawkEye v2(GUI)
Windows应急分析工具-HawkEye v2(GUI)
Windows应急分析工具-HawkEye v2(GUI)
Windows应急分析工具-HawkEye v2(GUI)
Windows应急分析工具-HawkEye v2(GUI)
Thailand Targets Cyber Sweatshops to Free 1,000s of Captives
Cybersecurity Weekly Update – 24 February 2025
Welcome to this week's edition of our cybersecurity news roundup, bringing you the latest developments and insights from the UK and beyond.
Home Office Contractor's Data Collection Sparks Privacy ConcernsThe Home Office faces scrutiny after revelations that its contractor, Equifax, collected data on British citizens while conducting financial checks on migrants applying for fee waivers. A report mistakenly sent to the Refugee and Migrant Forum of Essex and London (Ramfel) contained information on 260 individuals dating back to 1986, raising significant privacy issues. The Home Office has ceased using Equifax for visa fee waiver processing pending an investigation into the potential data breach. Read more
Apple Withdraws Advanced Data Protection in the UK Amid Government DisputeApple has removed its Advanced Data Protection (ADP) feature for UK users following a dispute with the British government. The government demanded access to encrypted material on Apple's iCloud under new evidence-collection powers. Apple, opposing the creation of a "back door" to its encryption service, opted to discontinue ADP in the UK. This decision highlights ongoing tensions between tech companies and governments over privacy and security regulations. Learn more
Sellafield Nuclear Site Improves Physical Security but Cyber Concerns PersistThe UK's Office for Nuclear Regulation (ONR) has removed Sellafield nuclear site from special measures concerning physical security, citing significant improvements. However, concerns over cybersecurity remain. Sellafield has been under scrutiny due to previous safety issues and cybersecurity deficiencies. Collaborative efforts are ongoing to address these challenges as the site continues to manage the nation's nuclear waste. Full story
UK Government Introduces AI Cybersecurity StandardsThe UK government has unveiled a new Code of Practice aimed at protecting AI systems from cyber-attacks. This initiative seeks to provide businesses and public services with guidelines to secure AI technologies, thereby safeguarding the digital economy. The voluntary code is expected to form the basis of a global standard for AI security, reinforcing the UK's position as a leader in safe technological innovation. Details here
Cyberattacks Cost UK Businesses Over £40 Billion in Five YearsRecent findings reveal that cyberattacks have cost British businesses approximately £40 billion in lost revenue over the past five years. More than half of private sector companies have experienced at least one attack, with compromised emails and data theft being the most common threats. Despite the increasing risks, many businesses lack adequate cybersecurity measures, often due to high costs and limited IT resources. Read the report
Stay tuned for more updates and insights in our next weekly roundup.
The post Cybersecurity Weekly Update – 24 February 2025 appeared first on Security Boulevard.
CVE-2024-44309 | Apple iOS/iPadOS on Intel Cookie cross site scripting (Nessus ID 211691)
CVE-2018-9365 | Google Andrioid 6/6.0.1/7/8/8.1 smp_l2c.cc smp_data_received out-of-bounds
CVE-2018-9433 | Google Android 6/6.0.1/7 builtins-array.cc ArrayConcatVisitor type confusion
CVE-2024-52763 | Ganglia-web 3.73/3.74/3.75 /graph_all_periods.php g cross site scripting (Issue 382)
CVE-2024-44309 | Apple visionOS on Intel Cookie cross site scripting (Nessus ID 211691)
CVE-2024-52762 | Ganglia-web 3.73/3.74/3.75 /master/header.php tz cross site scripting (Issue 382)
CVE-2018-9411 | Google Android 8/8.1/9 ClearKeyCasPlugin.cpp decrypt out-of-bounds write
SucoshScanny: automated Source Code vulnerability scanner and assessment framework
Sucosh Scanny “Sucosh” is an automated Source Code vulnerability scanner(SAST) and assessment framework for Python(Flask-Django) & NodeJs capable of performing code review in Web Application Developing or Source Code Analysis processes. It can detect...
The post SucoshScanny: automated Source Code vulnerability scanner and assessment framework appeared first on Penetration Testing Tools.
avred: AntiVirus REDucer for AntiVirus REDteaming
avred AntiVirus REDucer for AntiVirus REDteaming. Avred is being used to identify which parts of a file are identified by an Antivirus and tries to show as much possible information and context about each...
The post avred: AntiVirus REDucer for AntiVirus REDteaming appeared first on Penetration Testing Tools.