Aggregator
.NET 内网攻防实战电子报刊
1 week 1 day ago
01.NET内网安全攻防报刊小报童电子报刊【.NET内网安全攻防】也正式上线了,引入小报童也是为了弥补知识星球
红队视角:.NET Web.config 漏洞实战挖掘与利用
1 week 1 day ago
Протозвезда HOPS-315 показала, как из пыли растёт новая Солнечная система
1 week 1 day ago
Удивительное открытие раскрывает начало космической эволюции.
Bolthole: New ClickOnce Payload Offers Red Teams Stealthy Initial Access
1 week 1 day ago
Bolthole A proof-of-concept ClickOnce payload for Red Teams to establish initial access in authorized penetration tests. Overview Bolthole provides operators with: Reverse SSH tunnel into the target environment CMD shell access as the executing...
The post Bolthole: New ClickOnce Payload Offers Red Teams Stealthy Initial Access appeared first on Penetration Testing Tools.
ddos
CVE-2024-50136 | Linux Kernel up to 6.1.114/6.6.58/6.11.5 mlx5 eswitch_vport_event information disclosure (Nessus ID 213470 / WID-SEC-2024-3339)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 6.1.114/6.6.58/6.11.5. It has been classified as problematic. Affected is the function eswitch_vport_event of the component mlx5. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-50136. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-48956 | Linux Kernel up to 6.0.12 include/net/ip6_fib.h ip6_fragment use after free (Nessus ID 210933 / WID-SEC-2024-3251)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 6.0.12. It has been rated as critical. This issue affects the function ip6_fragment in the library include/net/ip6_fib.h. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2022-48956. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50123 | Linux Kernel up to 6.11.5 bpf bpf_link_show_fdinfo out-of-bounds (6d79f12c0ce2/c2f803052bc7 / Nessus ID 216493)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 6.11.5. It has been declared as problematic. This vulnerability affects the function bpf_link_show_fdinfo of the component bpf. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2024-50123. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50120 | Linux Kernel up to 6.6.58/6.11.5 SMB Client smb3_reconfigure allocation of resources (35dbac8c328d/35488799b0ab/9a5dd6115139 / Nessus ID 216493)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 6.6.58/6.11.5. It has been classified as problematic. This affects the function smb3_reconfigure of the component SMB Client. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-50120. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50116 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 submit_bh_wbc buffer overflow (Nessus ID 212931 / WID-SEC-2024-3339)
1 week 1 day ago
A vulnerability classified as critical has been found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. This affects the function submit_bh_wbc. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-50116. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50117 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 AMD Display show_regs null pointer dereference (Nessus ID 212872 / WID-SEC-2024-3339)
1 week 1 day ago
A vulnerability classified as critical was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. This vulnerability affects the function show_regs of the component AMD Display. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-50117. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50113 | Linux Kernel up to 6.11.5 firewire information disclosure (90753a38bc3d/f6a6780e0b9b / Nessus ID 216493)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 6.11.5. It has been rated as problematic. This issue affects some unknown processing of the component firewire. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-50113. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50114 | Linux Kernel up to 6.11.5 KVM __kvm_vgic_vcpu_destroy use after free (6bcc2890b883/ae8f8b376102 / Nessus ID 216493)
1 week 1 day ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.11.5. Affected is the function __kvm_vgic_vcpu_destroy of the component KVM. The manipulation leads to use after free.
This vulnerability is traded as CVE-2024-50114. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50115 | Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5 nSVM out-of-bounds (Nessus ID 212929 / WID-SEC-2024-3339)
1 week 1 day ago
A vulnerability classified as problematic was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. Affected by this vulnerability is an unknown functionality of the component nSVM. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2024-50115. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50112 | Linux Kernel up to 6.6.58/6.11.5 privilege escalation (60a5ba560f29/690599066488/3267cb6d3a17 / Nessus ID 216493)
1 week 1 day ago
A vulnerability was found in Linux Kernel up to 6.6.58/6.11.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to privilege escalation.
This vulnerability was named CVE-2024-50112. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Securing Tomorrow: An Interview with Trend Micro VP of Product Management Michael Habibi
1 week 1 day ago
Proactive security in a rapidly evolving threat landscape
美团开源OIBench与CoreCodeBench:揭示大模型编程能力的真实水平
1 week 1 day ago
Meituan-M17 团队联合上海交大等机构,分别推出了 OIBench(聚焦高区分度算法题评测)与 CoreCodeBench(聚焦多场景工程级代码基准)两大数据集,旨在揭示大模型编程能力真实水平,这两大数据集已分别在GitHub和Huggingface上进行开源。
美团技术团队
Flaw in Signal App Clone Could Leak Passwords — GreyNoise Identifies Active Reconnaissance and Exploit Attempts
1 week 1 day ago
A vulnerability disclosed in May 2025, CVE-2025-48927, affects certain deployments of TeleMessageTM SGNL. If exposed, this endpoint can return a full snapshot of heap memory which may include plaintext usernames, passwords, and other sensitive data.
浅析流行银狐样本
1 week 1 day ago
威努特助力制药企业“网络+计算+安全”一体化建设
1 week 1 day ago
一站式解决方案确保药品生产和办公业务稳定可靠。