Aggregator
俄军士兵作战规划APP被植入后门,专门窃取通信、位置等信息
1 year 1 month ago
通信聊天、实时位置等敏感信息均会遭到窃取
Grafana 高危漏洞可致关键业务数据泄露,官方补丁及时发布化解危机
1 year 1 month ago
安全客
Хакерская франшиза: DragonForce запускает криминальный DIY
1 year 1 month ago
Теперь жертву накажет не только вирус, но и закон.
Ransomware Attacks Fall Sharply in March
1 year 1 month ago
NCC Group found that ransomware attacks fell by 32% in March compared to February, but described this finding as a “red herring”
用户使用 AI 的需求发生了改变
1 year 1 month ago
根据数据分析师 Marc Zao-Sanders 的分析,在 2024-2025 年 AI 使用场景前 30 名榜单中,“获取专业或个人支持”已成为 2025 年 AI 应用的最常见场景,“疗愈和陪伴”超越 2024 年排名第 1 的“创意生成”功能,首次进入榜单的新需求“整理生活”与“寻找人生方向”紧随其后。传统热门用途“具体搜索”和“创意生成”等需求的热度有所下降。其中 2024 年排名第 3 的“具体搜索”则在今年跌出前 10。分析指出,这可能与生成式AI被集成至主流搜索引擎(如 Gemini 被整合进 Google)有关,用户已不再单纯依赖 AI 进行查询,而更多将其作为认知辅助工具使用。
WhatsApp introduces Advanced Chat Privacy to protect sensitive communications
1 year 1 month ago
WhatsApp adds Advanced Chat Privacy feature that allows users to block others from sharing chat content outside the app. WhatsApp announced the availability of a new feature called “Advanced Chat Privacy” for both individual and group chats that enhances content protection. The feature blocks chat exports, auto-media downloads, and the use of messages in AI […]
Pierluigi Paganini
Capture, Replicate, Deploy: Image Service Upgrades Now Available
1 year 1 month ago
Maddie Presland
Defensie heeft technische startups keihard nodig
1 year 1 month ago
Staatssecretaris Gijs Tuinman zwengelt de samenwerking met innovatieve bedrijven zoveel mogelijk aan. Want Defensie heeft hun kennis keihard nodig. Voor dat doel was hij vandaag bij YES!Delft. Dit is een van de broedplaatsen voor technische startups. Defensie en Economische Zaken willen in Zuid-Holland een regionaal innovatieknooppunt creëren, net als elders in Nederland.
CVE-2024-6235:Citrix NetScaler Console 会话劫持漏洞可致权限完全失控
1 year 1 month ago
安全客
【原创0day】金蝶天燕应用服务器IIOP反序列化远程代码执行漏洞(NVDB-CITIVD-2025865374)
1 year 1 month ago
检测业务是否受到此漏洞影响,请联系长亭应急服务团队!
【原创0day】金蝶天燕应用服务器IIOP反序列化远程代码执行漏洞(NVDB-CITIVD-2025865374)
1 year 1 month ago
检测业务是否受到此漏洞影响,请联系长亭应急服务团队!
CVE-2025-3162 | InternLM LMDeploy up to 0.7.1 PT File utils.py load_weight_ckpt deserialization (Issue 3255)
1 year 1 month ago
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2025-3162. Attacking locally is a requirement. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3374 | PCMan FTP Server 2.0.7 CCC Command buffer overflow
1 year 1 month ago
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2025-3374. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3378 | PCMan FTP Server 2.0.7 EPRT Command buffer overflow
1 year 1 month ago
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component EPRT Command Handler. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2025-3378. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Linux 6.15 чуть не убил производительность: спасли в последний час
1 year 1 month ago
Nginx, PostgreSQL, Memcached — все замедлились из-за одного бага.
CentreStack & Triofox 反序列化漏洞(CVE-2025-30406)
1 year 1 month ago
CentreStack & Triofox 反序列化漏洞(CVE-2025-30406)
NVIDIA NeMo 框架三大高危漏洞危及 AI 开发,数据篡改与远程代码执行风险剧增
1 year 1 month ago
安全客
Critical Commvault Command Center Flaw Enables Attackers to Execute Code Remotely
1 year 1 month ago
A critical security flaw has been disclosed in the Commvault Command Center that could allow arbitrary code execution on affected installations.
The vulnerability, tracked as CVE-2025-34028, carries a CVSS score of 9.0 out of a maximum of 10.0.
"A critical security vulnerability has been identified in the Command Center installation, allowing remote attackers to execute arbitrary code without
The Hacker News
告警!勒索毒王Weaxor家族利用AI攻击,国内多家公司受灾
1 year 1 month ago
Weaxor勒索病毒变种爆发,360上演“猎杀时刻”