Aggregator
专家解读 | 国家网络身份认证公共服务筑牢数字安全屏障
2 months 1 week ago
近期,公安部第一研究所于锐研究员关于国家网络身份认证公共服务进行了专题宣讲,以下是文字实录……
关注 | 工信部通报49款侵害用户权益行为的APP(SDK)(附清单)
2 months 1 week ago
工信部部对APP、SDK违法违规收集使用个人信息等问题开展治理。近期,经组织第三方检测机构进行抽查,共发现49款APP及SDK存在侵害用户权益行为,现予以通报。
专题·网安人才评价体系 | 网络安全人才专业能力全面评价体系分析
2 months 1 week ago
随着信息技术的快速发展,网络安全已成为全球竞争的核心领域。近年来,网络安全威胁与日俱增,网络攻击事件频繁发生,国家安全、经济社会发展面临严峻考验。为筑牢网络安全防线,各国都积极加强网络安全人才队伍建设,提升网络安全防护能力。
CVE-2025-5331 | PCMan FTP Server 2.0.7 NLST Command buffer overflow
2 months 1 week ago
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow.
This vulnerability was named CVE-2025-5331. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-5330 | FreeFloat FTP Server 1.0 RETR Command buffer overflow
2 months 1 week ago
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component RETR Command Handler. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-5330. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
还在等快递?这届 618 别人已经收货了
2 months 1 week ago
美团闪购入局,618 变了。
CVE-2024-52588 | Strapi up to 4.25.1 Webhooks URL server-side request forgery (GHSA-v8wj-f5c7-pvxf)
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Strapi up to 4.25.1. Affected by this issue is some unknown functionality of the component Webhooks URL Handler. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2024-52588. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-48388 | freescout-help-desk freescout up to 1.8.177 as format string
2 months 1 week ago
A vulnerability classified as critical was found in freescout-help-desk freescout up to 1.8.177. Affected by this vulnerability is an unknown functionality. The manipulation of the argument as leads to format string.
This vulnerability is known as CVE-2025-48388. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-4687 | Teltonika RMS up to 5.6 Pending Invite privilege escalation
2 months 1 week ago
A vulnerability classified as problematic has been found in Teltonika RMS up to 5.6. Affected is an unknown function of the component Pending Invite Handler. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2025-4687. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-27151 | Redis up to 8.0.1 stack-based overflow (GHSA-5453-q98w-cmvm)
2 months 1 week ago
A vulnerability was found in Redis up to 8.0.1. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-27151. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #585404: PCMan FTP Server 2.0.7 Buffer Overflow [Accepted]
2 months 1 week ago
Submit #585404 / VDB-310504
r3ng4f
Submit #585402: FreeFloat FTP Server 1.0 Buffer Overflow [Accepted]
2 months 1 week ago
Submit #585402 / VDB-310503
r3ng4f
США отрезали Китай от софта для чипов. Но вместо удара по отрасли включили ей турбонаддув
2 months 1 week ago
Трамп играет в долгую, Пекин — в свою. Исход пока не очевиден, но ставки растут.
Fortity SCA 审计规则更新
2 months 1 week ago
Fortity SCA 审计规则更新
'Haozi' Gang Sells Turnkey Phishing Tools to Amateurs
2 months 1 week ago
The phishing operation is using Telegram groups to sell a phishing-as-a-service kit with customer service, a mascot, and infrastructure that requires little technical knowledge to install.
Alexander Culafi, Senior News Writer, Dark Reading
Microsoft: Windows 11 might fail to start after installing KB5058405
2 months 1 week ago
Microsoft has confirmed that some Windows 11 systems might fail to start after installing the KB5058405 security update released during this month's Patch Tuesday. [...]
Sergiu Gatlan
还等什么?30小时入门CTF,速来学
2 months 1 week ago
适合新手入门
外出充电需警惕!ChoiceJacking 攻击来袭,安卓、苹果手机无一幸免
2 months 1 week ago
新型 ChoiceJacking 攻击威胁手机安全
Google CTF 2023 - v8box
2 months 1 week ago
看雪论坛作者ID:flyyyy