Aggregator
Твой "умный" телевизор теперь не только показывает рекламу, но и участвует в кибервойне
1 month ago
Серая экономика прокси оставляет владельцев сайтов без эффективных средств защиты.
Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users
1 month ago
Premium Deception campaign uses 250 Android apps to silently sign victims up to paid services
HPE security advisory (AV26-487)
1 month ago
Canadian Centre for Cyber Security
务实,是一种很稀缺的能力
1 month ago
最近和一位金融行业的甲方安全从业人员聊天,挺有感触的,于是想着记录一下。
Google Chrome security advisory (AV26-486)
1 month ago
Canadian Centre for Cyber Security
F5 security advisory (AV26-485)
1 month ago
Canadian Centre for Cyber Security
AI for Security:方法不对,越干越累?
1 month ago
网络安全从业人员使用AI遇到的困境
FreePBX security advisory (AV26-484)
1 month ago
Canadian Centre for Cyber Security
【安全圈】涨幅约 200%:美国流媒体 Plex 终身版将涨价至 749.99 美元
1 month ago
AI 漏洞挖掘开始交付"工程化结果"
从音频解码到工业 CAD,从车端 CAN 帧到企业 Java 中间件——这一次,AI 红队没有靠"灵感"。
【安全圈】消息称微软内部示警:GitHub 面临生存级风险,AI 编程工具削弱托管必要性
1 month ago
AI 漏洞挖掘开始交付"工程化结果"
从音频解码到工业 CAD,从车端 CAN 帧到企业 Java 中间件——这一次,AI 红队没有靠"灵感"。
【安全圈】撞库黑产牟利倒卖十万条账号密码,男子获刑三年六个月
1 month ago
AI 漏洞挖掘开始交付"工程化结果"
从音频解码到工业 CAD,从车端 CAN 帧到企业 Java 中间件——这一次,AI 红队没有靠"灵感"。
Microsoft issues YellowKey mitigation, no patch yet
1 month ago
Microsoft acknowledged the YellowKey BitLocker bypass flaw and released mitigations, urging admins to disable autofstx.exe and enable TPM+PIN. A week after Chaotic Eclipse publicly dropped the YellowKey vulnerability, Microsoft acknowledged it and published a mitigation. Not a patch, a mitigation. The distinction matters, and we will get to why. The flaw, tracked as CVE-2026-45585 (CVSS […]
Pierluigi Paganini
CVE-2023-5807 | TRtek Education Portal prior 3.2023.29 sql injection
1 month ago
A vulnerability described as critical has been identified in TRtek Education Portal. This affects an unknown function. Executing a manipulation can lead to sql injection.
The identification of this vulnerability is CVE-2023-5807. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2023-5921 | DECE Geodi prior 8.0.0.27396 behavioral workflow
1 month ago
A vulnerability has been found in DECE Geodi and classified as problematic. This impacts an unknown function. The manipulation leads to enforcement of behavioral workflow.
This vulnerability is traded as CVE-2023-5921. An attack has to be approached locally. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2023-6011 | DECE Geodi prior 8.0.0.27396 cross site scripting
1 month ago
A vulnerability was found in DECE Geodi and classified as problematic. Affected is an unknown function. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2023-6011. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-5983 | Botanik Pharmacy Automation prior 2.1.133.0 Embedded Sensitive Data information disclosure
1 month ago
A vulnerability identified as problematic has been detected in Botanik Pharmacy Automation. This issue affects some unknown processing of the component Embedded Sensitive Data Handler. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2023-5983. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2023-6118 | Neutron IP Camera prior b1130.1.0.1 path traversal
1 month ago
A vulnerability was found in Neutron IP Camera. It has been rated as problematic. This issue affects some unknown processing. This manipulation causes path traversal: '/../filedir'.
This vulnerability is registered as CVE-2023-6118. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2023-6150 | ESKOM Computer e-municipality module up to 104 privileges management
1 month ago
A vulnerability, which was classified as critical, was found in ESKOM Computer e-municipality module up to 104. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2023-6150. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2023-6151 | ESKOM Computer e-municipality module up to 104 privileges management
1 month ago
A vulnerability has been found in ESKOM Computer e-municipality module up to 104 and classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in improper privilege management.
This vulnerability is identified as CVE-2023-6151. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com