Aggregator
RansomHub Claims Theft of Montana Planned Parenthood Data
Planned Parenthood of Montana, which provides patients with reproductive healthcare services including birth control and abortion, is responding to a hack and a threat by cybercriminal group RansomHub to leak 93 gigabytes of data allegedly stolen from the organization.
Effective Communication in Difficult Conversations: 6 Rules to Follow
CVE-2002-0886 | Cisco CBOS up to 2.4.4 TCP/IP Stack memory allocation (EDB-21472 / XFDB-9151)
Apache fixes critical OFBiz remote code execution vulnerability
SSHamble:一款针对SSH技术安全的研究与分析工具
Palo Alto宣布完成对IBM QRadar的收购,原用户将被迁移至新平台;第二届网络空间安全(天津)论坛成功举办 | 牛览
CVE-2007-2142 | AjPortal2Php includes/footer.inc.php PagePrefix Remote Code Execution (EDB-3752 / XFDB-33703)
商用密码方案研究 | 智慧医疗商用密码应用安全体系建设
Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution
Efficient API Interaction And Consumption With Laravel: A Beginner's Guide
CVE-2009-1872 | Adobe ColdFusion up to 8.1 searchlog.cfm startRow cross site scripting (EDB-33169 / Nessus ID 42340)
如何使用VeilTransfer评估和提升组织的数据安全态势
Technical debt of C:\Windows\System path
September 2024 Patch Tuesday forecast: Downgrade is the new exploit
I asked for a calm August 2024 Patch Tuesday in last month’s forecast article and that came to pass. The updates released were limited to the regular operating systems and all forms of Office applications. Six zero-day vulnerabilities were announced, with five in the operating systems and one in the Office applications. There were 63 CVEs addressed in the Windows 10 operating systems and associated servers and 55 CVEs addressed in Windows 11. Overall, it … More →
The post September 2024 Patch Tuesday forecast: Downgrade is the new exploit appeared first on Help Net Security.
CVE-2024-44948 | Linux Kernel up to 6.10.4 mtrr_save_state state issue
CVE-2024-44953 | Linux Kernel up to 6.10.4 scsi kworker/0 ufshcd_rpm_get_sync deadlock (f13f1858a28c/3911af778f20)
CVE-2024-44954 | Linux Kernel up to 6.10.4 line6 Privilege Escalation
Microsoft removes revenge porn from Bing search using new tool
Human firewalls are essential to keeping SaaS environments safe
Businesses run on SaaS solutions: nearly every business function relies on multiple cloud-based tech platforms and collaborative work tools like Slack, Google Workspace apps, Jira, Zendesk and others. We recently surveyed security leaders and CISOs on top data security priorities and challenges. We discovered that over 70% work in organizations using 50 or more SaaS solutions, and nearly a third of the respondents reported their organization’s SaaS environments include 200 or more apps. With so … More →
The post Human firewalls are essential to keeping SaaS environments safe appeared first on Help Net Security.