Aggregator
【培训】开源情报分析师实战能力培训班-4月成都开班
5 days 23 hours ago
为进一步推动我国开源情报人才队伍建设,四川警察学院联合成都欧深特信息科技有限公司在成都校区(成都市双流区黄水镇云岭路36号)举办开源情报分析师实战能力培训班,第2期培训班定于2026年4月26日至5月1日举办。
【研究报告】人工智能军事技术在中东的扩散
5 days 23 hours ago
人工智能赋能的军事技术预计将在中东战场上持续扩散,加剧对平民和民用设施的破坏,并恶化人道主义危机。由于缺乏有效的问责机制,中东已成为人工智能赋能军事技术的试验场,这些技术随后被当作经过实战检验的成熟技术推向国际市场。
RAG从元数据Key到RCE:CVE-2026-22738 深度解析Spring AI向量存储中的SpEL表达式注入与逃逸
5 days 23 hours ago
为更好学习交流,建了个技术交流群,大家可以扫描进群。
CVE-2024-44215 | Apple visionOS Image information disclosure (Nessus ID 211697 / WID-SEC-2024-3291)
6 days ago
A vulnerability was found in Apple visionOS and classified as problematic. Affected by this issue is some unknown functionality of the component Image Handler. Executing a manipulation can lead to information disclosure.
This vulnerability appears as CVE-2024-44215. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-44215 | Apple iOS/iPadOS Image information disclosure (Nessus ID 211697 / WID-SEC-2024-3291)
6 days ago
A vulnerability was found in Apple iOS and iPadOS. It has been classified as problematic. This affects an unknown part of the component Image Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-44215. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2024-44215 | Apple tvOS Image information disclosure (Nessus ID 211697 / WID-SEC-2024-3291)
6 days ago
A vulnerability was found in Apple tvOS. It has been declared as problematic. This vulnerability affects unknown code of the component Image Handler. The manipulation results in information disclosure.
This vulnerability is known as CVE-2024-44215. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44215 | Apple watchOS Image information disclosure (Nessus ID 211697 / WID-SEC-2024-3291)
6 days ago
A vulnerability was found in Apple watchOS. It has been rated as problematic. This issue affects some unknown processing of the component Image Handler. This manipulation causes information disclosure.
This vulnerability is handled as CVE-2024-44215. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-44218 | Apple macOS File heap-based overflow (Nessus ID 211697 / WID-SEC-2024-3291)
6 days ago
A vulnerability classified as critical has been found in Apple macOS. Impacted is an unknown function of the component File Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2024-44218. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44218 | Apple iOS/iPadOS File heap-based overflow (Nessus ID 211697 / WID-SEC-2024-3291)
6 days ago
A vulnerability classified as critical was found in Apple iOS and iPadOS. The affected element is an unknown function of the component File Handler. The manipulation results in heap-based buffer overflow.
This vulnerability is identified as CVE-2024-44218. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-44239 | Apple macOS information disclosure (Nessus ID 211697 / WID-SEC-2024-3291)
6 days ago
A vulnerability was found in Apple macOS. It has been classified as problematic. This vulnerability affects unknown code. This manipulation causes information disclosure.
This vulnerability is registered as CVE-2024-44239. The attack needs to be launched locally. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2024-44222 | Apple macOS up to 13.6/14.6 information disclosure (Nessus ID 211697 / WID-SEC-2024-3291)
6 days ago
A vulnerability, which was classified as problematic, was found in Apple macOS up to 13.6/14.6. This impacts an unknown function. Executing a manipulation can lead to information disclosure.
The identification of this vulnerability is CVE-2024-44222. The attack can only be executed locally. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2024-44236 | Apple macOS up to 13.6/14.6 File out-of-bounds (Nessus ID 211697 / WID-SEC-2024-3291)
6 days ago
A vulnerability has been found in Apple macOS up to 13.6/14.6 and classified as problematic. Affected is an unknown function of the component File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2024-44236. The attack can only be performed from a local environment. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2024-44229 | Apple visionOS Browsing History information disclosure (Nessus ID 211696 / WID-SEC-2024-3291)
6 days ago
A vulnerability was found in Apple visionOS. It has been declared as problematic. This affects an unknown function of the component Browsing History Handler. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2024-44229. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44229 | Apple iOS/iPadOS Browsing History information disclosure (Nessus ID 211696 / WID-SEC-2024-3291)
6 days ago
A vulnerability was found in Apple iOS and iPadOS. It has been rated as problematic. This impacts an unknown function of the component Browsing History Handler. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2024-44229. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
Why AI Bot Protection and Control Are Essential for Application Security
6 days ago
AI-driven automation is no longer emerging. It is already integrated and accepted as internet traffic. From AI assistants and crawlers to enterprise automation tools, websites are now routinely accessed by non-human actors operating at scale. Vulnerabilities or weaknesses in your application infrastructure, including risky APIs, are no longer difficult to find, as agentic AI tools, […]
The post Why AI Bot Protection and Control Are Essential for Application Security appeared first on Blog.
The post Why AI Bot Protection and Control Are Essential for Application Security appeared first on Security Boulevard.
Grainne McKeever
CVE-2024-39371 | Linux Kernel up to 6.1.94/6.6.34/6.9.4 io_uring io_file_can_poll null pointer dereference (Nessus ID 213470 / WID-SEC-2024-1451)
6 days ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.94/6.6.34/6.9.4. This issue affects the function io_file_can_poll of the component io_uring. Such manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2024-39371. The attack requires being on the local network. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2024-39362 | Linux Kernel up to 6.1.94/6.6.33/6.9.4 fs/kernfs/dir.c acpi_bind_one stack-based overflow (WID-SEC-2024-1451)
6 days ago
This appears to be a false positive. Please validate the mentioned sources and consider excluding this entry altogether.
vuldb.com
CVE-2024-39296 | Linux Kernel up to 6.6.33/6.9.4 bonding_masters bonding_exit missing initialization (f07224c16678/cf48aee81103/a45835a0bb6e / WID-SEC-2024-1451)
6 days ago
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.33/6.9.4. This vulnerability affects the function bonding_exit of the file /sys/class/net/bonding_masters. This manipulation causes missing initialization of a variable.
This vulnerability is registered as CVE-2024-39296. The attack requires access to the local network. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2024-39301 | Linux Kernel up to 6.9.4 p9_client_rpc initialization (Nessus ID 207738 / WID-SEC-2024-1451)
6 days ago
A vulnerability identified as problematic has been detected in Linux Kernel up to 6.9.4. The affected element is the function p9_client_rpc. Performing a manipulation results in improper initialization.
This vulnerability is cataloged as CVE-2024-39301. The attack must originate from the local network. There is no exploit available.
You should upgrade the affected component.
vuldb.com