Aggregator
银狐超进化!引爆2025开年最大黑产攻击
10 months 1 week ago
微步在线
慢雾:2025 Q1 MistTrack 被盗表单分析
10 months 1 week ago
本系列通过真实案例剖析作恶手法,帮助行业参与者从中学习并更好地保护自己的资产。
慢雾:2025 Q1 MistTrack 被盗表单分析
10 months 1 week ago
本系列通过真实案例剖析作恶手法,帮助行业参与者从中学习并更好地保护自己的资产。
慢雾:2025 Q1 MistTrack 被盗表单分析
10 months 1 week ago
本系列通过真实案例剖析作恶手法,帮助行业参与者从中学习并更好地保护自己的资产。
慢雾:2025 Q1 MistTrack 被盗表单分析
10 months 1 week ago
本系列通过真实案例剖析作恶手法,帮助行业参与者从中学习并更好地保护自己的资产。
慢雾:2025 Q1 MistTrack 被盗表单分析
10 months 1 week ago
本系列通过真实案例剖析作恶手法,帮助行业参与者从中学习并更好地保护自己的资产。
慢雾:2025 Q1 MistTrack 被盗表单分析
10 months 1 week ago
本系列通过真实案例剖析作恶手法,帮助行业参与者从中学习并更好地保护自己的资产。
CVE-2009-3360 | Datemill 1.0 photo_view.php st cross site scripting (EDB-34549 / XFDB-53177)
10 months 1 week ago
A vulnerability classified as problematic has been found in Datemill 1.0. This affects an unknown part of the file photo_view.php. The manipulation of the argument st leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2009-3360. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Staatssecretaris opent fonds voor innovatieve bedrijven
10 months 1 week ago
Er is nu een fonds dat ondernemers financieel ondersteunt bij het ontwikkelen van zowel civiel als militair te gebruiken innovaties. Dit zogenoemde Security Fund (SecFund) is vandaag geopend door staatssecretaris van Defensie Gijs Tuinman. Hij deed dit bij de Brabantse Ontwikkelings Maatschappij in Tilburg. Het fonds biedt startkapitaal voor startups, scale-ups en mkb die in de innovatiebehoefte van Defensie voorzien. De bijdrage aan het fonds groeit dit jaar naar verwachting van € 25 miljoen naar € 100 miljoen.
Google is making sending end-to-end encrypted emails easy
10 months 1 week ago
Sending end-to-end encrypted (E2EE) emails from Gmail enterprise accounts is about to become much easier than it is now, Google has announced on Tuesday. The company will first make available this simplified capability to users who want to send E2EE emails to other Gmail users in their own organization, and will extend it in the coming weeks to include E2EE emails to external enterprise or personal Gmail inboxes. Finally, later this year, they will be … More →
The post Google is making sending end-to-end encrypted emails easy appeared first on Help Net Security.
Zeljka Zorz
CVE-2025-22213
10 months 1 week ago
joomla-cms5.2.4后台rce漏洞分析复现
受限上传漏洞绕过浏览器安全策略触发储存型 XSS 分析
10 months 1 week ago
OSS存储桶+绕文件上传+存储XSS+绕安全策略+实战案例
FreeBuf早报 | 28亿 Twitter 用户数据疑泄露;英国政府修订网络安全法
10 months 1 week ago
此次事件曝光了约 28.7 亿个 Twitter (现称 X)用户账户的 400GB 数据。
CVE-2024-0217 | PackageKitd prior 1.2.7 use after free (Nessus ID 233683)
10 months 1 week ago
A vulnerability classified as problematic was found in PackageKitd. Affected by this vulnerability is an unknown functionality. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-0217. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-23022 | FreeType 2.8.1 cff/cf2intrp.c cf2_doFlex integer overflow (Issue 1312 / Nessus ID 233690)
10 months 1 week ago
A vulnerability has been found in FreeType 2.8.1 and classified as problematic. This vulnerability affects the function cf2_doFlex of the file cff/cf2intrp.c. The manipulation leads to integer overflow.
This vulnerability was named CVE-2025-23022. Attacking locally is a requirement. There is no exploit available.
vuldb.com
PolarCTF网络安全2025春季个人挑战赛-Writeup
10 months 1 week ago
PolarCTF网络安全2025春季个人挑战赛-Writeup
Суд раскрыл секрет: QLED – бюджетный фосфор по премиальной цене
10 months 1 week ago
В погоне за прибылью QLED-индустрия тайно отказалась от квантовых технологий.
В преддверии большой атаки: 24 тысячи разведчиков прощупывают защиту GlobalProtect
10 months 1 week ago
Пользователям сервиса стоит насторожиться?
Helping Your Clients Achieve NIST Compliance: A Step by Step Guide for Service Providers
10 months 1 week ago
Introduction
As the cybersecurity landscape evolves, service providers play an increasingly vital role in safeguarding sensitive data and maintaining compliance with industry regulations. The National Institute of Standards and Technology (NIST) offers a comprehensive set of frameworks that provide a clear path to achieving robust cybersecurity practices.
For service providers, adhering to NIST
The Hacker News