Aggregator
CVE-2025-58294 | Huawei HarmonyOS 5.0.1/5.1.0/6.0.0 Print access control
CVE-2025-64312 | Huawei HarmonyOS 5.0.1/5.1.0/6.0.0 File Management information disclosure (EUVD-2025-199855)
CVE-2025-58311 | Huawei HarmonyOS/EMUI USB Driver use after free (EUVD-2025-199856)
CVE-2025-58308 | Huawei HarmonyOS 5.0.1/5.1.0/6.0.0 Call security check (EUVD-2025-199857)
CVE-2025-58305 | Huawei HarmonyOS 5.0.1 Gallery app improper authentication (EUVD-2025-199858)
CVE-2025-58304 | Huawei HarmonyOS 5.0.1/5.1.0/6.0.0 File Management information management (EUVD-2025-199859)
CVE-2025-58302 | Huawei HarmonyOS/EMUI Settings access control (EUVD-2025-199860)
CVE-2025-66361 | Logpoint SIEM up to 7.6.x special elements used in a template engine (EUVD-2025-199836)
CVE-2025-66360 | Logpoint SIEM up to 7.6.x Access Control Policy authorization (EUVD-2025-199837)
CVE-2025-66371 | Iteras Peppol-py up to 1.1.0 XML Parser xml external entity reference (EUVD-2025-199852)
CVE-2025-66359 | Logpoint SIEM up to 7.6.x cross site scripting (EUVD-2025-199835)
New observational auditing framework takes aim at machine learning privacy leaks
Machine learning (ML) privacy concerns continue to surface, as audits show that models can reveal parts of the labels (the user’s choice, expressed preference, or the result of an action) used during training. A new research paper explores a different way to measure this risk, and the authors present findings that may change how companies test their models for leaks. Why standard audits have been hard to use Older privacy audits often relied on altering … More →
The post New observational auditing framework takes aim at machine learning privacy leaks appeared first on Help Net Security.
现代家猫起源于北非野猫
Weekly Threat Landscape Digest – Week 48
This week’s threat landscape (Week 48) reveals a surge in newly reported vulnerabilities, enhanced malware capabilities, and increasingly refined social-engineering […]
The post Weekly Threat Landscape Digest – Week 48 appeared first on HawkEye.
Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets
The Shai Hulud 2.0 worm, first detected on November 24, 2025, has compromised nearly 1,200 organizations, including major banks, government bodies, and Fortune 500 technology firms. While initial reports described it as a simple npm supply chain attack that flooded GitHub with spam repositories, new analysis reveals a far more sophisticated operation. Entro Security researchers […]
The post Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets appeared first on Cyber Security News.
朝日集团确认约 200 万客户及员工数据遭黑客窃取
朝日集团确认约 200 万客户及员工数据遭黑客窃取
Ransomware Reshaping Cyber as National Security Priority
Ongoing, high-profile ransomware attacks against Britain and the United States have transformed cybersecurity into a national security priority, Anne Neuberger, the former White House deputy national security adviser for cyber, said at a Wednesday event in London.