Aggregator
CVE-2023-1370 | Json-smart Array recursion (Nessus ID 235062)
CVE-2024-23652 | moby buildkit up to 0.12.4 path traversal (GHSA-4v98-7qmw-rqr8 / Nessus ID 235068)
CVE-2024-23651 | moby buildkit up to 0.12.4 race condition (GHSA-m3r6-h7wv-7xxv / Nessus ID 235068)
CVE-2023-28842 | Moby unprotected alternate channel (GHSA-gvm4-2qqg-m333 / Nessus ID 235068)
CVE-2024-8946 | MicroPython 1.23.0 VFS Unmount extmod/vfs.c mp_vfs_umount heap-based overflow (Issue 13006 / Nessus ID 235069)
CVE-2024-8947 | MicroPython 1.22.2 py/objarray.c use after free (Issue 13283 / Nessus ID 235069)
CVE-2023-52843 | Linux Kernel up to 6.6.1 llc net/llc/llc_station.c eth_hdr memory corruption (Nessus ID 235071)
CVE-2023-52867 | Linux Kernel up to 6.6.1 radeon afmt_status buffer overflow (Nessus ID 235071)
CVE-2023-52845 | Linux Kernel up to 6.6.1 tipc lib/string.c strstr buffer overflow (Nessus ID 235071)
CVE-2023-3567 | Linux Kernel vc_screen.c vcs_read use after free (Nessus ID 235071)
CVE-2023-4421 | Mozilla Network Security Services PKCS 11 timing discrepancy (Nessus ID 235073)
Half of red flags in third-party deals never reach compliance teams
Third-party risk management (TPRM) is compromised in many organizations because those holding the relationship with the third-party (relationship owners) don’t escalate red flags to compliance teams reliably, according to Gartner.
The post Half of red flags in third-party deals never reach compliance teams appeared first on Help Net Security.
伪装成DeepL翻译网站安装Gh0st木马
伪装成DeepL翻译网站安装Gh0st木马
Infosec products of the month: April 2025
Here’s a look at the most interesting products from the past month, featuring releases from: 1touch.io, Abnormal AI, AppViewX, Arctic Wolf Networks, Bitdefender, BitSight, Bugcrowd, Cato Networks, CyberQP, Cyware, Entrust, Exabeam, Flashpoint, Forescout, Index Engines, Jit, LastPass, PlexTrac, PowerDMARC, RunSafe Security, Saviynt, Seal Security, Seemplicity, Skyhawk Security, Stellar Cyber, Swimlane, Varonis, and Veracode. Email authentication simplified: How PowerDMARC makes DMARC effortless With PowerDMARC, users can generate and publish DMARC, SPF, and DKIM records with a … More →
The post Infosec products of the month: April 2025 appeared first on Help Net Security.
CSCG 2025
Date: March 1, 2025, 5 p.m. — 01 May 2025, 16:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://play.cscg.live/
Rating weight: 0
Event organizers: NFITS
Live Masterclass | Enterprise Data Sanitization & Disposition: What 2,000 Global Leaders Reveal About 2025 Trends
The Myth of the Perfect CISO: A Multitalented Master of All
There were never many 'do everything' CISOs. Today there are even fewer. But with a specialist area, strong overview and ability to channel expertise, CISOs can align with business goals, embrace the business enabler role, demonstrate quick wins, and ensure their organization makes better risk decisions.
Ascension Notifying Patients About Rash of Third-Party Hacks
Catholic hospital chain Ascension Health is notifying hundreds of thousands of individuals across several states of at least four hacking incidents in recent months involving third-parties. Ascension reported one of the breaches this week, another in mid-April and the others in March and February.