Aggregator
Fortifying Finance: A Fireside Chat on Cyber Resilience in the AI Era
2 months ago
LockBit Crackdown Fragmented Russian Cybercrime Groups
2 months ago
Onslought Also Paved Way for Rise of English-Speaking Hackers
An international law enforcement crackdown on the LockBit ransomware group caused fragmentation and distrust among Russian-speaking cybercrime groups, paving the way for English-speaking hacking groups to gain prominence, experts said Tuesday during a London conference.
An international law enforcement crackdown on the LockBit ransomware group caused fragmentation and distrust among Russian-speaking cybercrime groups, paving the way for English-speaking hacking groups to gain prominence, experts said Tuesday during a London conference.
Police Seize Carder Site BidenCash
2 months ago
BidenCash Was Notorious for Posting Free Tranches of Stolen Card Data
An online carder marketplace with a flair for publicity is now offline following a U.S. and Dutch law enforcement seizure. The site, BidenCash, began operations in March 2022, growing to 117,000 customers who facilitated the trafficking of more than 15 million payment card numbers.
An online carder marketplace with a flair for publicity is now offline following a U.S. and Dutch law enforcement seizure. The site, BidenCash, began operations in March 2022, growing to 117,000 customers who facilitated the trafficking of more than 15 million payment card numbers.
US Commerce Secretary Defends Export Controls Crackdown
2 months ago
Top Trump Official Touts Enforcement Wins as Firms Warn China Is Gaining Ground
Despite pushback from tech leaders like Nvidia, Commerce Secretary Howard Lutnick told Congress that expanded export controls, seizures and arrests are safeguarding U.S. innovation, as the Trump administration scraps Biden-era AI policies and targets Chinese access to chips.
Despite pushback from tech leaders like Nvidia, Commerce Secretary Howard Lutnick told Congress that expanded export controls, seizures and arrests are safeguarding U.S. innovation, as the Trump administration scraps Biden-era AI policies and targets Chinese access to chips.
UAE Central Bank Tells FIs to Drop SMS, OTP Authentication
2 months ago
Banking Sector Faces Challenges in Meeting March 2026 Compliance Deadline
The Central Bank of UAE has issued a directive asking financial institutions to eliminate weak authentication methods including SMS and email OTPs. Banks are also expected to implement real-time fraud monitoring and suspend sessions when malicious activity is detected.
The Central Bank of UAE has issued a directive asking financial institutions to eliminate weak authentication methods including SMS and email OTPs. Banks are also expected to implement real-time fraud monitoring and suspend sessions when malicious activity is detected.
FTC chair implores Congress to strengthen children’s online privacy protection law
2 months ago
The FTC's Andrew Ferguson called on Congress to update federal law to get rid of exceptions for tech firms that handle children's data.
CVE-2024-23899 | Git Server Plugin on Jenkins command path traversal (EUVD-2024-0438)
2 months ago
A vulnerability was found in Git Server Plugin on Jenkins. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument command leads to path traversal.
The identification of this vulnerability is CVE-2024-23899. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-27298 | Philips Interventional Workspot os command injection (icsma-21-019-01 / EUVD-2020-19811)
2 months ago
A vulnerability has been found in Philips Interventional Workspot, Coronary Tools, Dynamic Coronary Roadmap, Stentboost Live and ViewForum and classified as critical. This vulnerability affects unknown code. The manipulation leads to os command injection.
This vulnerability was named CVE-2020-27298. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2025-48947 | auth0 nextjs-auth0 up to 4.6.0 Header Cache-Control web browser cache containing sensitive information (EUVD-2025-16914)
2 months ago
A vulnerability was found in auth0 nextjs-auth0 up to 4.6.0 and classified as critical. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument Cache-Control leads to use of web browser cache containing sensitive information.
This vulnerability is handled as CVE-2025-48947. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-7897 | MantisBT up to 2.3.1 My View my_view_page.php $_SERVER[PHP_SELF'] cross site scripting (EUVD-2017-16868 / ID 1038278)
2 months ago
A vulnerability has been found in MantisBT up to 2.3.1 and classified as problematic. This vulnerability affects unknown code of the file my_view_page.php of the component My View. The manipulation of the argument $_SERVER[PHP_SELF'] leads to cross site scripting.
This vulnerability was named CVE-2017-7897. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7096 | WSO2 Open Banking IAM SOAP Admin Services authorization (EUVD-2024-54612)
2 months ago
A vulnerability, which was classified as problematic, was found in WSO2 Open Banking IAM, Open Banking AM, API Manager, Enterprise Mobility Manager, Identity Server, Identity Server as Key Manager and Open Banking KM. This affects an unknown part of the component SOAP Admin Services. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2024-7096. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
银狐最新免杀对抗型攻击样本分析
2 months ago
银狐最新免杀对抗型攻击样本分析
sh4d0wup: Signing-key abuse and update exploitation framework
2 months ago
sh4d0wup Have you ever wondered if the update you downloaded is the same one everybody else gets or did you get a different one that was made just for you? Shadow updates are updates that...
The post sh4d0wup: Signing-key abuse and update exploitation framework appeared first on Penetration Testing Tools.
ddos
又出手了!这次抓到一群坏蛋
2 months ago
当虚拟的世界陷入危机时,现实的灯火也将熄灭。
Weekly Report: IPAが「2024年度中小企業における情報セキュリティ対策に関する実態調査報告書」を公表
2 months ago
独立行政法人情報処理推進機構(IPA)は「2024年度中小企業における情報セキュリティ対策に関する実態調査報告書」を公表しました。本報告書は、中小企業などにおけるサイバーセキュリティ対策の実態および課題などを明らかにし、中小企業などにおける規模・業種などに応じた効果の高いサイバーセキュリティ対策の分析・整理されています。
ChatGPT 推「AI 转录」整理功能;Manus 推出文生视频功能;小鹏、华为合作今日揭晓 | 极客早知道
2 months ago
马斯克:SpaceX 今年收入将达 155 亿美元;Windsurf 称 Anthropic 限制其直接访问 Claude 模型;斥资五亿,迅雷完成收购虎扑
SadGuard: Dynamic Code Analysis + Supply Chain Detection Attack
2 months ago
An AI-powered, self-hosted GitHub bot designed to detect and mitigate supply chain attacks in pull requests. SadGuard combines intelligent code analysis with executable behavior monitoring to secure your software pipeline. SadGuard was inspired by...
The post SadGuard: Dynamic Code Analysis + Supply Chain Detection Attack appeared first on Penetration Testing Tools.
ddos
独家披露:起底台“资通电军”APT组织技术底牌及网络攻击阴谋
2 months ago
曝光“资通电军”核心人物!360揪出台APT组织背后操盘手
【二十四节气】芒种 | 渌沼莲花放,炎风暑雨晴。
2 months ago