Aggregator
767 млн украденных записей, 250 взломов и 27 новых APT-групп. Главное из отчета F6 о кибервойне против России в 2025 году
StrongestLayer: Top ‘Trusted’ Platforms are Key Attack Surfaces
Explore StrongestLayer's threat intelligence report highlighting the rise of email security threats exploiting trusted platforms like DocuSign and Google Calendar. Learn how organizations can adapt to defend against these evolving cyber risks.
The post StrongestLayer: Top ‘Trusted’ Platforms are Key Attack Surfaces appeared first on Security Boulevard.
CVE-2025-15447 | Seeyon Zhiyuan OA Web Application System up to 20251223 assetsService.j%73p unitCode sql injection (EUVD-2026-0924 / CNNVD-202601-804)
CVE-2025-15446 | Seeyon Zhiyuan OA Web Application System up to 20251223 fixedAssetsList.j%73p unitCode sql injection (EUVD-2026-0923 / CNNVD-202601-796)
CVE-2025-15427 | Seeyon Zhiyuan OA Web Application System up to 20251222 carUseDetailList.j%73p CAR_BRAND_NO sql injection
最大动漫盗版网站被关,运营者被捕
Хаос отменяется. Мы научились направлять тепло в одну сторону, чтобы навсегда избавить смартфоны от перегрева
CVE-2023-42336 | Netis WF2409Ev4 1.0.1.705 /etc/shadow.sample Password hard-coded credentials (EUVD-2023-46789)
CVE-2023-42335 | Fl3xx Dispatch/Crew 2.10.37 unrestricted upload (EUVD-2023-46788)
CVE-2023-42331 | EliteCMS 1.01 manage_uploads.php unrestricted upload (EUVD-2023-46784)
CVE-2023-42334 | Fl3xx Dispatch/Crew 2.10.37 User resource injection (EUVD-2023-46787)
CVE-2023-42328 | PeppermintLabs Peppermint up to 0.2.4 Session Cookie information disclosure (EUVD-2023-46781)
CVE-2023-42323 | DouHaocms 3.3 adminAction.class.php cross-site request forgery (EUVD-2023-46776)
Open-source AI pentesting tools are getting uncomfortably good
AI has come a long way in the pentesting world. We are now seeing open-source tools that can genuinely mimic how a human tester works, not just fire off scans. I dug into three of them, BugTrace-AI, Shannon, and CAI, the Cybersecurity AI framework, and put them up against real-world targets in a lab environment. The results were better than I expected. Below is a breakdown of what each tool did well, where they fell … More →
The post Open-source AI pentesting tools are getting uncomfortably good appeared first on Help Net Security.
Where NSA zero trust guidance aligns with enterprise reality
The NSA has published Phase One and Phase Two of its Zero Trust Implementation Guidelines, providing structured guidance for organizations working to implement zero trust cybersecurity practices. The documents are part of a larger series designed to support adoption of zero trust frameworks aligned with the Department of Defense target-level maturity model. Guidelines aim to guide practical implementation Phase One outlines 36 activities focused on establishing conditions that support 30 specific zero trust capabilities at … More →
The post Where NSA zero trust guidance aligns with enterprise reality appeared first on Help Net Security.
CVE-2024-12084
Хватит скроллить, идите спать. Почему ваш мозг умоляет о пощаде (и как ему помочь)
7,5% чистого зла. Исследователи нашли тысячи ИИ-моделей, которые работают только на преступников
Qilin
You must login to view this content