Aggregator
谨防发送有后门的 Linux 虚拟机的钓鱼电子邮件!
9 months 2 weeks ago
安全客
CVE-2015-2875 | Seagate Storage up to 3.4.1 Download Request path traversal (VU#903500)
9 months 2 weeks ago
A vulnerability was found in Seagate Storage up to 3.4.1 and classified as critical. Affected by this issue is some unknown functionality of the component Download Request Handler. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2015-2875. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
GoZone ransomware accuses and threatens victims
9 months 2 weeks ago
A new ransomware dubbed GoZone is being leveraged by attackers that don’t seem to be very greedy: they are asking the victims to pay just $1,000 in Bitcoin if they want their files decrypted. The GoZone HTML ransom note (Source: SonicWall) The ransom notes shown by the malware lay out another incentive for paying up: they claim that child sexual abuse material has been found on the targeted computer and urge the victim to pay … More →
The post GoZone ransomware accuses and threatens victims appeared first on Help Net Security.
Zeljka Zorz
新的 Android 银行恶意软件“ToxicPanda”以欺诈性汇款为目标用户
9 months 2 weeks ago
安全客
下一代 Switch 将支持向后兼容
9 months 2 weeks ago
任天堂在 2024 年上半年财报上宣布,下一代 Switch 将向后兼容,玩家将能在新游戏机上玩第一代 Switch 游戏库中的作品。任天堂社长古川俊太郎表示更多信息将会稍后公布。Switch 是任天堂至今最长寿的主力游戏机,下一代 Switch 将在 2024 财年(截至 2025 年 3 月)之内公布。古川俊太郎表示,Switch 一代的账号系统以及在线服务都将延续到第二代。根据截至 9 月 30 日的 2024 年上半年财报,任天堂净销售额下降了 34%,硬件和软件都进一步下降,它下调了全年预期。
Изменения в Google Cloud: эра паролей закончится в 2025 году
9 months 2 weeks ago
Google Cloud делает MFA обязательной для всех пользователей.
FreeBuf早报 | 攻击施耐德的黑客索要40万根法式长棍;德国计划将白帽黑客行为合法化
9 months 2 weeks ago
德国政府已提出立法草案,将旨在寻找安全漏洞的道德黑客行为排除在刑事起诉之外。
CVE-2015-2874 | Seagate Storage up to 3.4.1 Telnet Server credentials management (VU#903500)
9 months 2 weeks ago
A vulnerability has been found in Seagate Storage up to 3.4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Telnet Server. The manipulation leads to credentials management.
This vulnerability is known as CVE-2015-2874. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Google Cloud to Mandate Multifactor Authentication by 2025
9 months 2 weeks ago
Google wants to ensure a smooth transition towards required MFA across all Google Cloud accounts with a phased rollout running throughout 2025
Weekoverzicht Defensieoperaties
9 months 2 weeks ago
Defensie helpt een Amerikaanse landmachteenheid bij het vervoer van militair materieel door Nederland. Het gaat om honderden pantser- en wielvoertuigen en containers. Een overzicht van Defensieoperaties in de week van 30 oktober tot en met 6 november 2024.
德国大型药品批发商遭勒索攻击,欲扰乱超6000家药房供应
9 months 2 weeks ago
安全客
Фишинг без ссылок и вирусов: DocuSign стал новым оружием киберпреступников
9 months 2 weeks ago
Мошенники нашли новый способ красть деньги с помощью легитимных сервисов.
CVE-2015-2871 | Chiyu BF-660C net.htm read/modify access control (VU#360431)
9 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Chiyu BF-660C. This affects an unknown part of the file net.htm. The manipulation of the argument read/modify leads to improper access controls.
This vulnerability is uniquely identified as CVE-2015-2871. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
谷歌警告安卓系统中存在被主动利用的 CVE-2024-43093 漏洞
9 months 2 weeks ago
安全客
网络安全信息与动态周报2024年第44期(10月28日-11月3日)
9 months 2 weeks ago
本周,互联网网络安全态势整体评价为良。
黑客泄露 30 万份《麻省理工科技评论》杂志用户记录
9 months 2 weeks ago
安全客
CVE-2024-10920 | mariazevedo88 travels-java-api up to 5.0.1 JWT Secret JwtAuthenticationTokenFilter.java doFilterInternal hard-coded key
9 months 2 weeks ago
A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travelsjavaapi\filters\JwtAuthenticationTokenFilter.java of the component JWT Secret Handler. The manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is handled as CVE-2024-10920. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Невидимый Linux в Windows: хакеры маскируют атаки через QEMU
9 months 2 weeks ago
Внутри вашего компьютера может быть скрыта полноценная ОС, которая крадет вашу личность.
Decart представил Oasis: ИИ генерирует Minecraft без единой строчки кода
9 months 2 weeks ago
ИИ-модель способна удивить и насторожить игроков.