Aggregator
Src实战-垂直越权任意添加用户
Windows 11 24H2 Update Disrupts Connection to Veeam Backup Server
Users of the Veeam Backup Server have encountered a significant issue following the Windows 11 24H2 update. Specifically, the update has disrupted the connection between Veeam Recovery Media and the Veeam Backup Server. This problem affects users who have created recovery media from Windows 11 version 24H2 (build 26100.3194) or higher. When attempting to restore […]
The post Windows 11 24H2 Update Disrupts Connection to Veeam Backup Server appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-8690
CVE-2025-27552 | DBIx::Class::EncodedColumn up to 0.00032 Bcrypt.pm rand weak prng
CVE-2025-27551 | DBIx::Class::EncodedColumn up to 0.00032 Digest.pm rand weak prng
CVE-2025-1542 | Infonet Projekt SA OXARI ServiceDesk prior 2.0.324.0 authorization
Microsoft: Recent Windows updates cause Remote Desktop issues
Cloudflare Attributes Service Outage to Faulty Password Rotation
Cloudflare experienced a significant service outage that affected several of its key offerings, including R2 object storage, Cache Reserve, Images, Log Delivery, Stream, and Vectorize. The incident, which lasted 1 hour and 7 minutes, was traced back to a faulty credential rotation process for the R2 Gateway service. Incident Overview The outage began at 21:38 […]
The post Cloudflare Attributes Service Outage to Faulty Password Rotation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
【已复现】Ingress NGINX Controller 远程代码执行漏洞
【已复现】Ingress NGINX Controller 远程代码执行漏洞
【已复现】Ingress NGINX Controller 远程代码执行漏洞
【已复现】Ingress NGINX Controller 远程代码执行漏洞
【已复现】Ingress NGINX Controller 远程代码执行漏洞
【已复现】Ingress NGINX Controller 远程代码执行漏洞
【已复现】Ingress NGINX Controller 远程代码执行漏洞
Grafana глазами Red Team: как мониторинг раскрывает внутренности сети
SplxAI raises $7 million to provide security for agentic AI
SplxAI has closed $7 million in seed funding led by LAUNCHub Ventures with participation from Rain Capital, Inovo, Runtime Ventures, DNV Ventures and South Central Ventures. LAUNCHub General Partner Stan Sirakov is also joining the SplxAI Board of Directors and former Brand Engagement Network CISO Sandy Dunn is joining the company as CISO to spearhead development of SplxAI’s GRC offering. The funding will accelerate the development and adoption of the SplxAI Platform, enabling organizations to … More →
The post SplxAI raises $7 million to provide security for agentic AI appeared first on Help Net Security.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2019-9874 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
- CVE-2019-9875 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.