Aggregator
【安全圈】谷歌修复导致 AI 概览称“现在是 2024 年”的漏洞
【安全圈】OneDrive 文件选择器漏洞让应用程序获取用户整个云盘的访问权限
RSA enhances passwordless identity platform
RSA announced a new Identity Security Posture Management (ISPM) and enhancements to its passwordless identity platform. These innovations will help enterprises proactively find and resolve security risks across hybrid and cloud environments and simplify users’ log-in processes with advanced, phishing-resistant security capabilities. RSA announces new RSA Governance & Lifecycle ISPM capabilities Built into the RSA Governance & Lifecycle identity governance and administration (IGA) solution, the new ISPM features from RSA address critical cybersecurity risks that … More →
The post RSA enhances passwordless identity platform appeared first on Help Net Security.
Future-ready cybersecurity: Lessons from the MITRE CVE crisis
The domino effect of CVE disruption is something all cybersecurity practitioners must be aware of, a Morphisec executive argues.
The post Future-ready cybersecurity: Lessons from the MITRE CVE crisis appeared first on CyberScoop.
Scattered Spider: Understanding Help Desk Scams and How to Defend Your Organization
CVE-2004-1960 | Protector System 1.15b1 blocker_query.php cross site scripting (EDB-24048 / XFDB-15965)
第125篇:蓝队溯源之burpsuite、zap、AWVS、xray扫描器反制方法与复现
CVE-2013-3482 | Hexagon ERDAS ER Viewer up to 11.3 ermapper_u.dll rf_report_error memory corruption (EDB-26708 / ID 121697)
CVE-2000-1113 | Microsoft Windows Media Player 6.4/7.0 ASX File memory corruption (EDB-20427 / XFDB-5574)
隐秘的 npm 供应链攻击:误植域名导致RCE和数据破坏
高通:速修复这三个已遭利用的 Adreno GPU 漏洞
Хотели когда-нибудь перепрограммировать помидор? Потерпите — скоро это будет нормой
Google patches new Chrome zero-day bug exploited in attacks
Sonos Era 300: колонка-предатель качает вредонос, пока вы наслаждаетесь джазом
CVE-2025-4392 | Shared Files Plugin up to 1.7.48 on WordPress sanitize_file cross site scripting (EUVD-2025-16717)
极客公园 @ 你!快来加入我们!
用 AI 读书、学习,大脑会萎缩吗?
SolarWinds Dameware Remote Control Service Vulnerability Allows Privilege Escalation
A significant vulnerability, CVE-2025-26396, affects the SolarWinds Dameware Mini Remote Control Service could allow attackers to escalate privileges on affected systems. Security researcher Alexander Pudwill, working with Trend Micro Zero Day Initiative, responsibly disclosed the flaw to SolarWinds. In a coordinated vulnerability disclosure, SolarWinds has released Dameware version 12.3.2, which addresses a critical security vulnerability. […]
The post SolarWinds Dameware Remote Control Service Vulnerability Allows Privilege Escalation appeared first on Cyber Security News.