Aggregator
研究发现 X 算法偏爱共和党和马斯克
$25,5 млн снова на базе: как криптоплатформа Thala вернула похищенные средства?
Major security audit of critical FreeBSD components now available
The FreeBSD Foundation, in partnership with the Alpha-Omega Project, has released the results of an extensive security audit of two critical FreeBSD components: the bhyve hypervisor and the Capsicum sandboxing framework. The audit, conducted by the offensive security firm Synacktiv, provides insights into potential vulnerabilities and highlights the importance of proactive security measures in open-source software. The security audit, carried out in June and July 2024, aimed to identify vulnerabilities in these subsystems’ user-mode and … More →
The post Major security audit of critical FreeBSD components now available appeared first on Help Net Security.
CVE-2006-0115 | OnePlug CMS press/details.asp Product_ID sql injection (EDB-27034 / BID-16155)
CVE-2024-50317 | Ivanti Avalanche up to 6.4.5 null pointer dereference
CVE-2024-50318 | Ivanti Avalanche up to 6.4.5 null pointer dereference
CVE-2024-47905 | Ivanti Connect Secure/Policy Secure up to 22.7R2.2 stack-based overflow (Nessus ID 211467)
CVE-2024-50319 | Ivanti Avalanche up to 6.4.5 infinite loop
CVE-2024-50320 | Ivanti Avalanche up to 6.4.5 infinite loop
CVE-2024-50321 | Ivanti Avalanche up to 6.4.5 infinite loop
CVE-2024-47907 | Ivanti Connect Secure up to 22.7R2.2 stack-based overflow
CVE-2024-10531 | Kognetiks Chatbot Plugin up to 2.1.7 on WordPress Assistant Update authorization
CVE-2024-10684 | Kognetiks Chatbot Plugin up to 2.1.7 on WordPress dir cross site scripting
CVE-2024-11143 | Kognetiks Chatbot Plugin up to 2.1.8 on WordPress update_assistant cross-site request forgery
CVE-2024-47909 | Ivanti Connect Secure/Policy Secure up to 22.7R2.2 stack-based overflow (Nessus ID 211467)
CVE-2024-11007 | Ivanti Connect Secure/Policy Secure up to 22.7R2.0 os command injection (Nessus ID 211455)
Smarter AppSec: How ADR, Secure by Design and ‘Shift Smart’ are Redefining Cybersecurity | Application Security Podcast Takeaways | Contrast Security
If there’s one thing Jeff Williams learned from years and years of doing pen testing and threat modeling, it’s this: They're highly time-pressured.
The post Smarter AppSec: How ADR, Secure by Design and ‘Shift Smart’ are Redefining Cybersecurity | Application Security Podcast Takeaways | Contrast Security appeared first on Security Boulevard.