Aggregator
免费AI Logo生成器:Slea AI
免费AI Logo生成器:Slea AI
CVE-2008-2292 | Net-SNMP 5.1.4/5.2.4/5.4.1 __snprint_value memory corruption (EDB-7100 / Nessus ID 33142)
Evilginx: Open-source man-in-the-middle attack framework
Evilginx is an open-source man-in-the-middle attack framework designed to phish login credentials and session cookies, enabling attackers to bypass 2FA safeguards. “Back in 2017, I was experimenting with extracting cookies from one browser and importing them into another. I realized this technique could effectively take over accounts, bypassing the need for credentials or even MFA authorization. This discovery led me to consider the possibility of executing such an attack remotely by proxying HTTP traffic between … More →
The post Evilginx: Open-source man-in-the-middle attack framework appeared first on Help Net Security.
IBM云计算平台为开源项目提供永久免费服务器 提供2核心8GB内存100GB硬盘
CVE-2011-4132 | Linux Kernel 2.6 cleanup_journal_tail input validation (Bug 753341 / Nessus ID 69585)
CVE-2012-1311 | Cisco IOS XE up to 3.3.0s RSVP Feature resource management (Nessus ID 58571 / ID 43229)
CVE-2011-4188 | Novell iManager up to 2.7.4 Web Interface jclient Create Attribute EnteredAttrName memory corruption (Nessus ID 802852 / XFDB-74669)
CVE-2017-0192 | Microsoft Windows Vista SP2 up to Server 2016 Adobe Type Manager Font Driver ATMFD.dll information disclosure (EDB-41894 / Nessus ID 99285)
CVE-2017-0189 | Microsoft Windows Vista SP2 up to Server 2012 R2 access control (Nessus ID 99286 / ID 91355)
CVE-2017-0188 | Microsoft Windows Vista SP2 up to Server 2012 R2 Win32k information disclosure (EDB-41894 / Nessus ID 99285)
CVE-2017-0191 | Microsoft Windows Vista SP2 up to Server 2012 R2 Win32k access control (EDB-41894 / Nessus ID 99285)
CVE-2017-0185 | Microsoft Hyper-V up to 2016 input validation (EDB-41894 / Nessus ID 99285)
CVE-2017-0184 | Microsoft Hyper-V input validation (EDB-41894 / Nessus ID 99285)
CVE-2017-0186 | Microsoft Hyper-V Network Switch input validation (EDB-41894 / Nessus ID 99285)
谷歌为Chrome开发基于H.265/HEVC编码器API 提高通过浏览器录制视频效率
账号和密钥明文存储,AI平台1.29T数据库裸奔
账号和密钥明文存储,AI平台1.29T数据库裸奔
Maximizing the impact of cybercrime intelligence on business resilience
In this Help Net Security interview, Jason Passwaters, CEO of Intel 471, discusses how integrating cybercrime intelligence into an organization’s security strategy enables proactive threat management and how measuring intelligence efforts can help mitigate risks before they escalate. Passwaters also shares best practices for building a robust intelligence program, focusing on data sources, adversary identification, and collaboration between the private sector and law enforcement.
The post Maximizing the impact of cybercrime intelligence on business resilience appeared first on Help Net Security.