Aggregator
JVN: リコー製Web Image Monitorを実装している複数のレーザープリンタおよび複合機(MFP)におけるスタックベースのバッファオーバーフローの脆弱性
Procolored 官方打印机驱动被发现含有恶意程序
AI hallucinations and their risk to cybersecurity operations
AI systems can sometimes produce outputs that are incorrect or misleading, a phenomenon known as hallucinations. These errors can range from minor inaccuracies to misrepresentations that can misguide decision-making processes. Real world implications “If a company’s AI agent leverages outdated or inaccurate data, AI hallucinations might fabricate non-existent vulnerabilities or misinterpret threat intelligence, leading to unnecessary alerts or overlooked risks. Such errors can divert resources from genuine threats, creating new vulnerabilities and wasting already-constrained SecOps … More →
The post AI hallucinations and their risk to cybersecurity operations appeared first on Help Net Security.
Stormous
You must login to view this content
重磅课程 | 6月 • PPES-201 现代智能手机防窃听
Why EU encryption policy needs technical and civil society input
In this Help Net Security interview, Bart Preneel, Full Professor at University of Leuven, unpacks the European Commission’s encryption agenda, urging a balanced, technically informed approach to lawful access that safeguards privacy, security, and fundamental rights across the EU. Given the European Commission’s aim to enable lawful access to encrypted data, how can we reconcile this with the technical consensus that introducing such access points inherently weakens encryption? While “lawful access to encrypted data based … More →
The post Why EU encryption policy needs technical and civil society input appeared first on Help Net Security.
CVE-2022-3643 | Xen on Linux NIC Interface denial of service (DLA 3244-1 / Nessus ID 236642)
CVE-2022-3707 | Linux Kernel up to 6.1-rc2 Intel GVT-g Graphics Driver intel_gvt_dma_map_guest_page double free (Nessus ID 236642)
CVE-2022-4095 | Linux Kernel up to 5.19.1 rtl8712_cmd.c cmd_hdl_filter use after free (Nessus ID 236642)
CVE-2022-3523 | Linux Kernel Driver mm/memory.c use after free (Nessus ID 236642)
CVE-2020-25654 | Pacemaker up to 1.1.23/2.0.5-rc1 ACL access control (Nessus ID 236643)
CVE-2022-1184 | Linux Kernel EXT4 Filesystem fs/ext4/namei.c dx_insert_block use after free (Nessus ID 236642)
CVE-2022-2196 | Linux Kernel KVM insecure default initialization of resource (Nessus ID 236642)
CVE-2019-3885 | Pacemaker 2.0.1 System Log use after free (RHSA-2019:1278 / Nessus ID 236643)
CVE-2021-20179 | Valid pki-core Key authorization (Nessus ID 236644)
CVE-2019-20330 | Oracle Global Lifecycle Management OPatch up to 11.2.0.3.22/12.2.0.1.18/13.9.4.2.2 Patch Installer deserialization (Nessus ID 236644)
山东大学 | MiniCAT:了解和检测小程序中的跨页面请求伪造漏洞
Hanko: Open-source authentication and user management
Hanko is an open-source, API-first authentication solution purpose-built for the passwordless era. “We focus on helping developers and organizations modernize their authentication flows by migrating users towards passkeys, while still supporting all common authentication methods like email/password, MFA, OAuth, as well as SAML SSO,” Felix Magedanz, CEO at Hanko, told Help Net Security. “What truly sets us apart is our commitment to developer experience,” explained Magedanz. Hanko is fully open source and licensed under AGPL … More →
The post Hanko: Open-source authentication and user management appeared first on Help Net Security.