Aggregator
Кодекс хакеров: мир в шаге от исторического соглашения
11 months 1 week ago
Париж становится центром формирования этики кибербезопасности.
В лаборатории зла: как CraxsRAT и NFCGate превратили Android в банкомат
11 months 1 week ago
Число заражённых устройств в России достигло 180 тысяч.
警惕!黑客利用 mu - plugins 目录隐匿 WordPress 恶意软件,网站面临多重风险
11 months 1 week ago
安全客
Switch 2 将于 6 月 5 日上市,起售价 450 美元
11 months 1 week ago
任天堂在 4 月 2 日举行的直面会上宣布其新一代主机 Switch 2 将于 6 月 5 日上市,起售价 449 美元,捆绑《Mario Kart World》的版本售价 499 美元。Switch 2 掌机配备了 7.9 英寸 LCD 显示屏,提供了 1080p 分辨率,支持 HDR 和刷新率 120Hz,内部存储增加到 256GB。主机模式支持 4K/60fps 输出。Switch 2 向后兼容 Switch 一代的游戏,然而如果玩家想要玩高清化的 Switch 2 版本如支持 4K@60 fps 或 1080p@120 fps,需要购买所谓的升级包。在直面会上,FromSoftware 演示了 Switch 2 独占游戏《The Duskbloods》,预计 2026 年上市。
震惊!28.7 亿 Twitter 用户数据疑遭泄露,400GB 信息曝光
11 months 1 week ago
安全客
The Future of Security Operations: Why Next-Gen SIEM is a Necessity
11 months 1 week ago
Transitioning to a modern SIEM model can achieve significant cost savings while enhancing security visibility and operational efficiency.
The post The Future of Security Operations: Why Next-Gen SIEM is a Necessity appeared first on Security Boulevard.
Ajit Sancheti
$74 млн исчезли, а токен растёт — абсурдный взлом UPCX
11 months 1 week ago
Инцидент обнажил парадокс криптомира.
在人工智能驱动的网络威胁形势下,企业备份策略的发展至关重要
11 months 1 week ago
安全客
CVE-2025-21994 | Linux Kernel up to 6.1.131/6.6.84/6.12.20/6.13.8 ksmbd parse_dcal num_aces allocation of resources
11 months 1 week ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.1.131/6.6.84/6.12.20/6.13.8. This vulnerability affects the function parse_dcal of the component ksmbd. The manipulation of the argument num_aces leads to allocation of resources.
This vulnerability was named CVE-2025-21994. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50597 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Component HTTP Server nxd_http_server.c integer underflow (TALOS-2024-2103)
11 months 1 week ago
A vulnerability classified as problematic has been found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. This affects an unknown part of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c of the component NetX Duo Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is uniquely identified as CVE-2024-50597. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50596 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Web Component HTTP Server nx_web_http_server.c integer underflow (TALOS-2024-2103)
11 months 1 week ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c of the component NetX Duo Web Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is handled as CVE-2024-50596. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50595 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Component HTTP Server nxd_http_server.c integer underflow (TALOS-2024-2102)
11 months 1 week ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c of the component NetX Duo Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is known as CVE-2024-50595. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50594 | STMicroelectronics X-CUBE-AZRT-H7RS 1.0.0 NetX Duo Web Component HTTP Server nx_web_http_server.c integer underflow (TALOS-2024-2102)
11 months 1 week ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL 1.0.0. It has been classified as problematic. Affected is an unknown function of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c of the component NetX Duo Web Component HTTP Server. The manipulation leads to integer underflow.
This vulnerability is traded as CVE-2024-50594. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50385 | STMicroelectronics X-CUBE-AZRT-H7RS NetX Component HTTP Server nxd_http_server.c cleanup (TALOS-2024-2097)
11 months 1 week ago
A vulnerability was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL and classified as critical. This issue affects some unknown processing of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.c of the component NetX Component HTTP Server. The manipulation leads to incomplete cleanup.
The identification of this vulnerability is CVE-2024-50385. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50384 | STMicroelectronics X-CUBE-AZRT-H7RS NetX Component HTTP Server nx_web_http_server.c cleanup (TALOS-2024-2097)
11 months 1 week ago
A vulnerability has been found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL and classified as critical. This vulnerability affects unknown code of the file x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.c of the component NetX Component HTTP Server. The manipulation leads to incomplete cleanup.
This vulnerability was named CVE-2024-50384. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-45064 | STMicroelectronics X-CUBE-AZRT-H7RS FileX Internal RAM Interface memory corruption (TALOS-2024-2096)
11 months 1 week ago
A vulnerability, which was classified as critical, was found in STMicroelectronics X-CUBE-AZRT-H7RS, X-CUBE-AZRTOS-F4, X-CUBE-AZRTOS-F7, X-CUBE-AZRTOS-G0, X-CUBE-AZRTOS-G4, X-CUBE-AZRTOS-H7, X-CUBE-AZRTOS-L4, X-CUBE-AZRTOS-L5, X-CUBE-AZRTOS-WB and X-CUBE-AZRTOS-WL. This affects an unknown part of the component FileX Internal RAM Interface. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-45064. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
注意!HijackLoader 新增模块,恶意隐匿与反制分析能力大幅增强
11 months 1 week ago
安全客
CVE-2025-3123 | WonderCMS 3.5.0 Theme Installation/Plugin Installation installUpdateModuleAction unrestricted upload (Issue 330)
11 months 1 week ago
A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleAction of the component Theme Installation/Plugin Installation. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2025-3123. The attack may be launched remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
The vendor explains, that "[t]he philosophy has always been, admin [...] bear responsibility to not install themes/plugins from untrusted sources."
vuldb.com
Police shuts down KidFlix child sexual exploitation platform
11 months 1 week ago
Kidflix, one of the largest platforms used to host, share, and stream child sexual abuse material (CSAM) on the dark web, was shut down on March 11 following a joint action coordinated by German law enforcement. [...]
Sergiu Gatlan