Aggregator
"十五五"开局立法新风向,网安相关要点有哪些?
1 month 1 week ago
Phishing-as-a-Service (PhaaS): Inside a Telegram Phishing Bot
1 month 1 week ago
How It Works, What It Steals & How to Stay SafePress enter or click to view image in full sizeSummar
APT41 Targeting Pharmaceutical Sector: Log4Shell to Domain Compromise
1 month 1 week ago
Threat Intelligence Report | Operation DragonRxPress enter or click to view image in full sizeClassi
Checkmarx Fails Again: TeamPCP Hijacks Jenkins Plugin to Harvest Developer Credentials
1 month 1 week ago
Unidentified adversaries have subverted the Checkmarx plugin for Jenkins, embedding deleterious code designed for credential exfiltration. This incursion
The post Checkmarx Fails Again: TeamPCP Hijacks Jenkins Plugin to Harvest Developer Credentials appeared first on Penetration Testing Tools.
ddos
Microsoft Fixes 17 Critical Flaws in May Patch Tuesday
1 month 1 week ago
Microsoft has patched 120 vulnerabilities in this month’s security update round
GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
1 month 1 week ago
Software Supply Chain / Data ExfiltrationCybersecurity researchers are calling attention to a new
GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data
1 month 1 week ago
Cybersecurity researchers are calling attention to a new campaign dubbed GemStuffer that has targeted the RubyGems repository with more than 150 gems that use the registry as a data exfiltration channel rather than for malware distribution.
"The packages do not appear designed for mass developer compromise," Socket said. "Many have little or no download activity, and the payloads are repetitive,
The Hacker News
王牌A计划|三月月度奖励
1 month 1 week ago
感谢各位安全专家长期关注阿里巴巴集团安全,帮助阿里云先知提高阿里巴巴集团和客户安全水平,保障数亿用户的安全!
坦白了:一个普通网页,到底能知道你多少信息?
1 month 1 week ago
欧盟的浏览器选择屏为 Firefox 增加了数百万用户
1 month 1 week ago
欧盟的 Digital Markets Act(DMA)强制要求苹果和 Google 向消费者提供浏览器选择屏,允许消费者选择非默认浏览器如 Safari 或 Chrome。Mozilla 估计,浏览器选择屏为它带来了大约 600 万用户,其中 iOS 平台上的用户数增长了 113%,而 Android 只增加 12%。这一差异可能与苹果和 Google 实现浏览器选择屏的方式有关:苹果用户在首次打开 Safari 时看到浏览器选择屏,而 Android 设备则是在首次启动或恢复出厂设置后。Mozilla 称,用户留存率比 DMA 实施前提高了五倍。浏览器开发商 Aloha、Brave、Opera 和 Vivaldi 此前也披露 DMA 强制实施后的最初几天和几周内,用户数量都出现了显著增长。Mozilla 希望 DMA 也应适用于桌面操作系统,指责微软使用欺骗性的设计策略推广其 Edge 浏览器。
欧盟的浏览器选择屏为 Firefox 增加了数百万用户
1 month 1 week ago
欧盟的 Digital Markets Act(DMA)强制要求苹果和 Google 向消费者提供浏览器选择屏,允许消费者选择非默认浏览器如 Safari 或 Chrome。Mozilla
CVE-2016-8882 | Jasper up to 1.900.7 libjasper/jpc/jpc_dec.c jpc_dec_tilefini null pointer dereference (ID 30 / Nessus ID 95664)
1 month 1 week ago
A vulnerability, which was classified as problematic, was found in Jasper up to 1.900.7. This affects the function jpc_dec_tilefini of the file libjasper/jpc/jpc_dec.c. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2016-8882. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2016-8883 | Jasper up to 1.900.7 jpc_dec.c jpc_dec_tiledecode resource management (RHSA-2017:1208 / Nessus ID 95664)
1 month 1 week ago
A vulnerability has been found in Jasper up to 1.900.7 and classified as problematic. This vulnerability affects the function jpc_dec_tiledecode of the file jpc_dec.c. This manipulation causes improper resource management.
The identification of this vulnerability is CVE-2016-8883. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2016-9107 | Gajim OTR Plugin information disclosure (ID 145 / BID-94099)
1 month 1 week ago
A vulnerability was found in Gajim and classified as problematic. This issue affects some unknown processing of the component OTR Plugin. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2016-9107. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2016-9310 | ntpd up to 4.2.8p8 Control Mode resource consumption (FEDORA-2016-e8a8561ee7 / VU#633847)
1 month 1 week ago
A vulnerability was found in ntpd up to 4.2.8p8. It has been classified as critical. Impacted is an unknown function of the component Control Mode. Performing a manipulation results in resource consumption.
This vulnerability is identified as CVE-2016-9310. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2016-9311 | ntpd up to 4.2.8p8 null pointer dereference (FEDORA-2016-e8a8561ee7 / VU#633847)
1 month 1 week ago
A vulnerability was found in ntpd up to 4.2.8p8. It has been declared as problematic. The affected element is an unknown function. Executing a manipulation can lead to null pointer dereference.
This vulnerability is tracked as CVE-2016-9311. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2016-9312 | ntpd up to 4.2.8p8 on Windows UDP Packet resource management (VU#633847 / Nessus ID 95575)
1 month 1 week ago
A vulnerability was found in ntpd up to 4.2.8p8 on Windows. It has been rated as problematic. The impacted element is an unknown function of the component UDP Packet Handler. The manipulation leads to improper resource management.
This vulnerability is listed as CVE-2016-9312. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2016-9807 | GStreamer up to 1.10.1 FLIC File gst/flx/gstflxdec.c flx_decode_chunks out-of-bounds (RHSA-2016:2975 / Nessus ID 96067)
1 month 1 week ago
A vulnerability categorized as problematic has been discovered in GStreamer up to 1.10.1. This affects the function flx_decode_chunks of the file gst/flx/gstflxdec.c of the component FLIC File Handler. The manipulation results in out-of-bounds read.
This vulnerability is cataloged as CVE-2016-9807. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2016-9808 | GStreamer up to 1.10.1 FLIC Decoder out-of-bounds write (RHSA-2016:2975 / Nessus ID 96067)
1 month 1 week ago
A vulnerability identified as problematic has been detected in GStreamer up to 1.10.1. This impacts an unknown function of the component FLIC Decoder. This manipulation causes out-of-bounds write.
This vulnerability is registered as CVE-2016-9808. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com