Aggregator
第107篇:国*攻防比赛中一个多层嵌套的java内存马的反混淆解密分析过程
CVE-2008-4662 | LokiCMS 0.3.4 admin.php language path traversal (EDB-6744 / XFDB-45843)
CVE-2008-6186 | RaidenFTPD 2.4 memory corruption (EDB-6742 / BID-31741)
CVE-2008-5626 | Dxmsoft XM Easy Personal FTP Server 5.6.0 -1 resource management (EDB-6741 / BID-31739)
CVE-2008-6180 | NewLife Blogger up to 3.3.1 sql injection (EDB-6739 / XFDB-45821)
CVE-2008-6183 | Myphpindexer My PHP Indexer 1.0 index.php path traversal (EDB-6740 / XFDB-45830)
1 - 1 = 2
L1:第二关:玩转书生「多模态对话」和「AI搜索」产品
CVE-2024-39722 | Ollama up to 0.1.45 API Push Route path traversal (Nessus ID 210502)
CVE-2023-6681 | jwcrypto up to 1.5.0 PBKDF2 denial of service (Nessus ID 210497)
CVE-2023-38264 | IBM JDK Object Request Broker denial of service (Nessus ID 210508)
CVE-2024-37298 | gorilla schema up to 1.4.0 session_id allocation of resources (GHSA-3669-72x9-r9p3 / Nessus ID 210509)
CVE-2023-40217 | Python up to 3.8.17/3.9.17/3.10.12/3.11.4 TLS Client Authentication initialization (Nessus ID 210518)
CVE-2024-0450 | CPython up to 3.8.18/3.9.18/3.10.13/3.11.8/3.12.2 on zipfile ZIP Bomb amplification (Nessus ID 210518)
CVE-2024-24814 | OpenIDC mod_auth_openidc up to 2.4.15.1 mod_auth_openidc_session_chunks resource consumption (Nessus ID 210515)
CVE-2023-24329 | Python up to 3.10 urllib.parse input validation (Nessus ID 210518)
CVE-2023-6597 | CPython up to 3.8.18/3.9.18/3.10.13/3.11.8/3.12.2 tempfile.TemporaryDirectory symlink (Issue 91133 / Nessus ID 210518)
Highlights from the InCyber Montreal Forum
I had a tremendous time at the InCyber Montreal forum. The speakers, panels, fellow practitioners, and events were outstanding!
I bumped into Dan Lohrmann and Nancy Rainosek before their panel with Sue McCauley on CISO challenges. We had some very interesting discussions throughout the day. Always great to hang out with Dan and Nancy.
Then it was my turn on a panel, led by Nataliya Khylenko, discussing how to strike a balance when protecting data in the age of AI. Fellow panelists Sandra Estok, Tania Tanic, and Brandon Pugh were brilliant in providing diverse and relevant perspectives.
By the end of the day, I was able to spend some quality time with Diane M Janosek, Christophe Foulon, and Evgeniy Kharam.
One of my favorite talks was from the passionate Sumona Banerji, who discussed the evolving risks of child online grooming and victimization.
I also caught glimpses of Alexa Charles who leads the coordination of this massive event and keeps all us speakers happy! She is a true superstar!
The Gala Cocktail was spectacular. A local mariachi band, not what I expected in Montreal Canada, played lively tunes and the discussions were flowing among the cybersecurity professionals!
Last but not least Vincent Riou and Shigeru Kitamura, former National Security Advisor of Japan, announced an expansion of the InCyber events to include San Antonio and Japan for 2025!
I am looking forward to both next year!
The post Highlights from the InCyber Montreal Forum appeared first on Security Boulevard.
Combating Cybercrime: What to Expect From Trump Presidency?
One post-election question pertaining to Donald Trump's upcoming presidency is how his administration will choose to combat cybercrime, and to what extent the White House will continue to take a leadership role in combating ransomware and cybercrime - especially based in Russia.