Aggregator
国家网络安全通报中心:重点防范境外恶意网址和恶意IP
新型AI攻击借助图像植入恶意提示词窃取用户数据
New framework aims to outsmart malware evasion tricks
Attackers have learned how to trick machine learning malware detectors with small but clever code changes, and researchers say they may finally have an answer. In a new paper, academics from Inria and the CISPA Helmholtz Center for Information Security describe a framework that can withstand these kinds of evasion attempts. Their work focuses on adversarial examples in malware detection, where attackers alter software in ways that preserve its function but confuse the model into … More →
The post New framework aims to outsmart malware evasion tricks appeared first on Help Net Security.
Submit #636506: itsourcecode Apartment Management System V1.0 SQL injection [Accepted]
Submit #636372: itsourcecode Apartment Management System V1.0 SQL injection [Accepted]
Submit #636371: itsourcecode Apartment Management System V1.0 SQL injection [Accepted]
CVE-2025-7719 | GE Vernova CIMPLICITY prior 2024 SIM 4 uncontrolled search path (icsa-25-240-06)
CVE-2025-7405 | Mitsubishi Electric MELSEC iQ-F FX5U-32MT-ES Modbus TCP missing authentication (icsa-25-240-01)
CVE-2025-7731 | Mitsubishi Electric MELSEC iQ-F FX5U-32MT-ES 3.1/7.5 SLMP Messages cleartext transmission (icsa-25-240-02)
Hackers Exploit Microsoft Teams, Posing as IT Help Desk for Screen Sharing and Remote Access
A sophisticated phishing campaign has been identified, where threat actors impersonate IT helpdesk personnel through Teams’ external communication features, exploiting the platform’s default configuration to bypass traditional email security measures and gain unauthorized screen-sharing and remote-control capabilities. The attacks leverage Teams’ external collaboration features, which are enabled by default in Microsoft 365 tenants, allowing attackers […]
The post Hackers Exploit Microsoft Teams, Posing as IT Help Desk for Screen Sharing and Remote Access appeared first on Cyber Security News.
CVE-2025-9217 | Slider Revolution Plugin up to 6.7.36 on WordPress used_svg/used_images path traversal (EUVD-2025-26172)
CVE-2024-13342 | Booster for WooCommerce Plugin up to 7.2.4 on WordPress Double Extension add_files_to_order unrestricted upload (EUVD-2024-54930)
CVE-2024-54568 | Apple macOS up to 15.1 File memory corruption
CVE-2024-54554 | Apple macOS up to 15.0 App symlink
CVE-2024-44271 | Apple macOS up to 15.1 Screen Recording information disclosure (WID-SEC-2024-3692)
CVE-2025-58323 | NAVER MYBOX Explorer prior 3.0.8.133 on Windows privileges assignment
Help Wanted: Dark Web Job Recruitment is Up
Cybercriminal forums are experiencing a recruitment boom, with dark-web job postings for hackers, AI experts, and social engineers doubling year over year. Research from Reliaquest highlights growing demand for English-speaking social engineering, IoT compromise, AI-driven attacks, and deepfake capabilities — signaling how adversaries are scaling organized cybercrime operations.
The post Help Wanted: Dark Web Job Recruitment is Up appeared first on Security Boulevard.