Aggregator
IBM security advisory (AV25-557)
3 months 2 weeks ago
Canadian Centre for Cyber Security
行业首推!360大模型安全能力斩获权威认证
3 months 2 weeks ago
安全客
Everest
3 months 2 weeks ago
You must login to view this content
cohenido
再添数字政府新名片!深圳“深治慧”平台入选2025数博会创新案例
3 months 2 weeks ago
安全客
Qualcomm security advisory – September 2025 monthly rollup (AV25-556)
3 months 2 weeks ago
Canadian Centre for Cyber Security
IOC Alert: NetSupport Manager RAT Payload Delivery – wood-simple[.]com/drip.sym
3 months 2 weeks ago
IOC Alert: NetSupport Manager RAT Payload Delivery – wood-simple[.]com/drip.sym
Dark Web Informer
HashiCorp security advisory (AV25-555)
3 months 2 weeks ago
Canadian Centre for Cyber Security
CVE-2020-24363 | TP-LINK TL-WA855RE V5 20200415-rel37464 Access Control POST Request missing authentication (EDB-49092)
3 months 2 weeks ago
A vulnerability described as critical has been identified in TP-LINK TL-WA855RE V5 20200415-rel37464. Affected by this issue is some unknown functionality of the component Access Control. Executing manipulation as part of POST Request can lead to missing authentication.
This vulnerability is registered as CVE-2020-24363. The attack requires access to the local network. Furthermore, an exploit is available.
vuldb.com
CVE-2025-55177 | Facebook WhatsApp Desktop for Mac Synchronization Message authorization (EUVD-2025-26214)
3 months 2 weeks ago
A vulnerability marked as problematic has been reported in Facebook WhatsApp Desktop for Mac, WhatsApp Business for iOS and WhatsApp for iOS. Affected by this issue is some unknown functionality of the component Synchronization Message Handler. Performing manipulation results in incorrect authorization.
This vulnerability is reported as CVE-2025-55177. The attacker must have access to the local network to execute the attack. Moreover, an exploit is present.
It is suggested to upgrade the affected component.
vuldb.com
Так сможет ли робот написать симфонию, создать шедевр? 3 млн фанатов говорят “да”
3 months 2 weeks ago
Вчера был дизайнером, сегодня — звездой стриминга: ИИ сократил путь к славе до нуля.
联合国报告称深圳-香港-广州是全球第一大创新集群
3 months 2 weeks ago
世界知识产权组织(WIPO)发布《2025年全球创新指数》,“深圳-香港-广州”创新集群首次超越日本“东京-横滨”,成为全球第一大创新集群。WIPO 此前制定全球创新指数主要参考 PCT 国际专利申请量、科学引文索引拓展版(SCIE)论文量两大指标,今年增加了风险资金投资交易量的新指标。WIPO 表示,风险投资活动有助于了解科技知识如何转化为初创企业,以及最终转化为市场上的新商品和服务。WIPO 称,深圳-香港-广州和东京-横滨合计占全球专利申请总数的近五分之一。
Palo Alto Networks, Zscaler and PagerDuty Hit in Salesforce Linked Data Breaches
3 months 2 weeks ago
Hackers exploited the Salesloft Drift app to steal OAuth tokens and access Salesforce data, exposing customer details at…
Deeba Ahmed
CVE-2024-42067 | Linux Kernel up to 6.6.36/6.6.37/6.9.7 bpf set_memory_rox return value (Nessus ID 210060 / WID-SEC-2024-1722)
3 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.6.36/6.6.37/6.9.7. It has been rated as problematic. The impacted element is the function set_memory_rox of the component bpf. The manipulation leads to unchecked return value.
This vulnerability is documented as CVE-2024-42067. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-42065 | Linux Kernel up to 6.9.7 xe xe_ttm_stolen_mgr_init null pointer dereference (cc796a77985d/a6eff8f9c7e8 / Nessus ID 210060)
3 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.9.7. The impacted element is the function xe_ttm_stolen_mgr_init of the component xe. Performing manipulation results in null pointer dereference.
This vulnerability was named CVE-2024-42065. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-42064 | Linux Kernel up to 6.9.7 AMD Display denial of service (27df59c60714/af114efe8d24 / Nessus ID 210060)
3 months 2 weeks ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.9.7. This vulnerability affects unknown code of the component AMD Display. The manipulation results in denial of service.
This vulnerability was named CVE-2024-42064. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-42066 | Linux Kernel up to 6.9.7 xe integer overflow (79d54ddf0e29/4f4fcafde343 / Nessus ID 210060)
3 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.9.7. This issue affects some unknown processing of the component xe. This manipulation causes integer overflow.
The identification of this vulnerability is CVE-2024-42066. The attack needs to be done within the local network. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-42063 | Linux Kernel up to 6.1.96/6.6.36/6.9.7 kernel/bpf/devmap.c kmsan_unpoison_memory initialization (Nessus ID 210060 / WID-SEC-2024-1722)
3 months 2 weeks ago
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.1.96/6.6.36/6.9.7. Affected is the function kmsan_unpoison_memory of the file kernel/bpf/devmap.c. Such manipulation leads to improper initialization.
This vulnerability is traded as CVE-2024-42063. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2024-41098 | Linux Kernel up to 6.6.36/6.9.7 libata-core ata_port_alloc null pointer dereference (119c97ace2a9/8a8ff7e3b736/5d92c7c566dc / Nessus ID 208099)
3 months 2 weeks ago
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.36/6.9.7. Affected by this vulnerability is the function ata_port_alloc of the component libata-core. Such manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2024-41098. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
Zscaler, Palo Alto Networks, SpyCloud among the affected by Salesloft Drift breach
3 months 2 weeks ago
In the wake of last week’s revelation of a breach at Salesloft by a group tracked by Google as UNC6395, several companies – including Zscaler, Palo Alto Networks, PagerDuty, Tanium, and SpyCloud – have confirmed their Salesforce instances were accessed. The companies noted that attackers had only limited access to Salesforce databases, not to other systems or resources. They warned, however, that the stolen customer data could be used for convincing phishing and social engineering … More →
The post Zscaler, Palo Alto Networks, SpyCloud among the affected by Salesloft Drift breach appeared first on Help Net Security.
Zeljka Zorz