Aggregator
安全警钟敲响:黑客宣称从 Oracle Cloud 服务器窃取 600 万条记录
CVE-2025-2706 | Digiwin ERP 5.0.1 UploadAjaxAPI.ashx File unrestricted upload
CVE-2025-2705 | Digiwin ERP 5.1 /Api/FileUploadApi.ashx DoUpload/DoWebUpload File unrestricted upload
Submit #517030: zhijiantianya ruoyi-vue-pro 2.4.1 File Path Traversal Backend [Accepted]
Submit #517029: zhijiantianya ruoyi-vue-pro 2.4.1 File Path Traversal Front-end [Accepted]
Attackers can bypass middleware auth checks by exploiting critical Next.js flaw
Submit #516293: www.digiwin.com digiwin ERP system v5.0.1 Improper Sanitization of Filename to result [Accepted]
Submit #516292: www.digiwin.com digiwin ERP system v5.1.3 Unauthenticated File Upload Leading to Remote Code Execution [Duplicate]
Submit #516291: www.digiwin.com digiwin ERP system v5.1 Unrigorous file uploading results in RCE [Accepted]
Evaluating AI for Security Operations
SOCs without AI aren't just behind the curve — they're fundamentally outmatched in the asymmetric battle against sophisticated threat actors.
The post Evaluating AI for Security Operations appeared first on Security Boulevard.
实力认证!360入选国家工业信息安全漏洞库技术组成员单位
VSCode Marketplace Removes Two Extensions Deploying Early-Stage Ransomware
30 глаз для Луны: проект AeSI позволит заглянуть в души далёких звёзд
【安全圈】Coinbase 最初成为 GitHub Actions 供应链攻击的目标;218 个存储库的 CI/CD 机密被曝光
【安全圈】微软可信签名服务被滥用为恶意软件签名
【安全圈】JumpServer漏洞使攻击者可绕过认证并获取完全控制权
【安全圈】研究人员揭露macOS漏洞,或导致系统密码泄露
How to Balance Password Security Against User Experience
Critical Chrome Vulnerability Allows Attackers to Execute Arbitrary Code
Google has recently rolled out a critical security update for its Chrome browser, addressing vulnerabilities that could potentially allow attackers to execute arbitrary code. This update is part of a broader effort to ensure user safety in an increasingly threat-ridden digital landscape. The latest version, 134.0.6998.117/.118, is being rolled out across Windows, Mac, and Linux […]
The post Critical Chrome Vulnerability Allows Attackers to Execute Arbitrary Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.