Aggregator
Webinar: Learn How to Identify High-Risk Identity Gaps and Slash Security Debt in 2025
9 months 3 weeks ago
In today’s rapidly evolving digital landscape, weak identity security isn’t just a flaw—it’s a major risk that can expose your business to breaches and costly downtime.
Many organizations are overwhelmed by an excess of user identities and aging systems, making them vulnerable to attacks. Without a strategic plan, these security gaps can quickly turn into expensive liabilities.
Join us for "
The Hacker News
紧急!CVE-2024-39327 IDPKI 严重漏洞或致非法滥发证书
9 months 3 weeks ago
安全客
5 - CVE-2025-24989
9 months 3 weeks ago
Currently trending CVE - hypeScore: 5 - An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.
This vulnerability has already been mitigated in the service and all affected cusomters have been noti
4 - CVE-2024-13159
9 months 3 weeks ago
Currently trending CVE - hypeScore: 5 - Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
3 - CVE-2025-21355
9 months 3 weeks ago
Currently trending CVE - hypeScore: 7 - Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network
2 - CVE-2024-12284
9 months 3 weeks ago
Currently trending CVE - hypeScore: 12 - Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
1 - CVE-2025-27090
9 months 3 weeks ago
Currently trending CVE - hypeScore: 19 - Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without
10 - CVE-2025-26466
9 months 3 weeks ago
Currently trending CVE - hypeScore: 1
8 - CVE-2025-26465
9 months 3 weeks ago
Currently trending CVE - hypeScore: 1 - A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying
6 - CVE-2025-0108
9 months 3 weeks ago
Currently trending CVE - hypeScore: 2 - An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While
9 - CVE-2024-12754
9 months 3 weeks ago
Currently trending CVE - hypeScore: 1 - AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to
7 - CVE-2024-53704
9 months 3 weeks ago
Currently trending CVE - hypeScore: 1 - An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
发布 | 2024年工业控制网络安全态势白皮书
9 months 3 weeks ago
安全KER小助手
BlackBasta Ransomware Chatlogs Leaked Online
9 months 3 weeks ago
BlackBasta’s internal chatlogs are “highly useful from a threat intelligence perspective,” said Prodaft, the firm that revealed the leak
CVE-2025-0111 和 CVE-2025-23209:帕洛阿尔托防火墙和 Craft CMS 在野高危漏洞
9 months 3 weeks ago
安全客
马斯克DOGE一获得CISA内部访问权限员工曾“涉黑”;黑客内讧?Black Basta勒索软件团伙聊天记录被泄露 |牛览
9 months 3 weeks ago
新闻速览 •马斯克DOGE一获得CISA内部访问权限员工曾“涉黑” •黑客内讧?Black Basta勒索软件 […]
aqniu
【安全圈】Citrix 发布 NetScaler 控制台权限提升漏洞的安全修复程序
9 months 3 weeks ago
【安全圈】赛门铁克诊断工具漏洞可让攻击者提升权限
9 months 3 weeks ago
【安全圈】CISA 和 FBI:Ghost 勒索软件入侵 70 个国家/地区
9 months 3 weeks ago