Aggregator
CVE-2025-49663 | Microsoft Windows Server 2008 R2 SP1 up to Server 2022 23H2 Routing/Remote Access Service heap-based overflow (EUVD-2025-20581)
/r/ReverseEngineering's Weekly Questions Thread
Happy Birthday Linux! 34 Years of Open-Source Power
August 25, 2025, marks the 34th anniversary of Linux, a project that began as a modest hobby and has grown into the bedrock of modern digital infrastructure. On this day in 1991, 21-year-old Finnish student Linus Torvalds posted to the comp.os.minix newsgroup: “I’m doing a (free) operating system (just a hobby, won’t be big and […]
The post Happy Birthday Linux! 34 Years of Open-Source Power appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2003-0078 | OpenSSL up to 0.9.7 Block Cipher Padding s3_pkt.c ssl3_get_record missing encryption (EDB-22264 / Nessus ID 13783)
CVE-2003-0083 | Apache HTTP Server up to 1.3.24/2.0.45 Escape Character privileges management (EDB-9887 / Nessus ID 11408)
CVE-2003-0084 | Red Hat Linux 2.1 mod_auth_any privileges management (Nessus ID 12383 / ID 86684)
Hackers Steal Windows Secrets and Credentials Undetected by EDR Detection
A cybersecurity researcher has unveiled a sophisticated new method for extracting Windows credentials and secrets that successfully evades detection by most Endpoint Detection and Response (EDR) solutions currently deployed in enterprise environments. The technique, dubbed “Silent Harvest,” leverages obscure Windows APIs to access sensitive registry data without triggering common security alerts. The breakthrough represents a […]
The post Hackers Steal Windows Secrets and Credentials Undetected by EDR Detection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Миллиарды устройств сядут на световую диету. Батарейки больше не нужны?
NIST Releases Lightweight Cryptography Standard for IoT Security
The National Institute of Standards and Technology (NIST) has formally published Special Publication 800-232, “Ascon-Based Lightweight Cryptography Standards for Constrained Devices,” establishing the first U.S. government benchmark for efficient cryptographic algorithms tailored to resource-constrained environments such as the Internet of Things (IoT), embedded systems, and low-power sensors. In February 2023, NIST selected the Ascon family […]
The post NIST Releases Lightweight Cryptography Standard for IoT Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
多领域获认可|梆梆安全入选《2025年中国网络安全市场全景图》
多领域获认可|梆梆安全入选《2025年中国网络安全市场全景图》
近日,国内网络安全研究机构数说安全正式发布《2025年中国网络安全市场全景图》。梆梆安全凭借扎实的技术积累、持续的研发创新以及显著的行业影响力,成功入选6大类共8项细分领域。该成果标志着业界对梆梆安全综合技术实力及其在数字安全领域持续贡献的高度认可。
本期全景图,数说安全采用较为严格的录入标准,在完成对基础资质与市场活跃度的核验后,同时引入对企业经营稳健性与可持续发展能力的多项评估,力求收录已经过实际场景检验、具备一定市场份额,并能保持持续研发投入与自主创新动力的品牌,为网络安全主管部门、行业从业者、产品与服务使用及采购单位,以及资本机构提供更可信、更具参考价值的结构化信息。
梆梆安全入选详情
移动安全
物联网安全
数据安全
应用安全
开发安全
解决方案
在当前数字化与智能化不断深入业务核心的背景下,网络安全行业呈现出“成熟领域精益运营、新兴方向加速验证”的并行发展态势。一方面,数据要素流通机制逐步健全,AI大模型凭借“增量试用+存量改造”的双轨模式,在多种业务场景中持续释放价值;另一方面,鸿蒙应用跨行业终端规模化落地,不断拓展端边协同防护与高可信终端生态的新边界。在这一进程中,网络安全的定位正经历根本性转变——从传统意义上的辅助支撑角色,演进为保障业务连续性、驱动运营效率、并护航数字化转型的核心基础设施与战略性保障体系。
梆梆安全作为长期深耕网络安全领域的专业厂商,已在行业中积累了深厚的技术底蕴与工程实践经验,在移动安全、物联网安全、业务安全、API安全、数据安全、开发安全及信创安全等多个关键领域展现出全面且扎实的技术实力,这不仅体现了综合性的产品与解决方案覆盖能力,更意味着可为客户提供覆盖移动应用全生命周期的系统性安全建设支持。
从应用安全保护、安全与合规检测,到运行阶段的安全监测与响应,梆梆安全均能提供专业化、定制化的安全产品与服务,切实保障客户业务安全稳定运行。
梆梆安全将持续深耕核心技术,加速安全创新,以更可靠的数字安全保障能力,护航数字中国建设,一如既往地为国家关键信息基础设施与企业核心数据资产筑牢安全屏障,赋能数字经济安全、稳定、高质量发展。
CVE-2025-9407 | mtons mblog up to 3.5.0 /settings/profile signature cross site scripting (ICPML3 / EUVD-2025-25662)
CVE-2025-36042 | IBM QRadar SIEM 7.5.0 Web UI cross site scripting (WID-SEC-2025-1888)
CVE-2025-33120 | IBM QRadar SIEM up to 7.5.0 UP13 cronjob unnecessary privileges (EUVD-2025-25525 / WID-SEC-2025-1888)
CVE-2025-43300 | Apple macOS Image File out-of-bounds write (EUVD-2025-25409 / WID-SEC-2025-1876)
CVE-2024-38999 | jrburke requirejs 2.3.6 s.contexts._.configure prototype pollution (Nessus ID 209968 / WID-SEC-2025-1887)
CVE-2025-38742 | Dell iDRAC Service Module up to 6.0.3.0 permission assignment (dsa-2025-311 / EUVD-2025-25485)
CVE-2025-38743 | Dell iDRAC Service Module up to 6.0.3.0 buffer access with incorrect length value (dsa-2025-311 / EUVD-2025-25483)
Microsoft Copilot Agent Policy Flaw Lets Any User Access AI Agents
Microsoft has disclosed a critical flaw in its Copilot agents’ governance framework that allows any authenticated user to access and interact with AI agents within an organization—bypassing intended policy controls and exposing sensitive operations to unauthorized actors. At the core of the issue is the way Copilot Agent Policies are enforced—or, more accurately, not enforced—when […]
The post Microsoft Copilot Agent Policy Flaw Lets Any User Access AI Agents appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.