Aggregator
实网攻防演练来袭 | “AI告警研判官”到岗!
5 hours 15 minutes hence
火山引擎云安全
科威特遭受攻击:230多个域名用于复杂的网络钓鱼行动
3 hours 45 minutes hence
安全客
glibc漏洞使数百万Linux系统面临代码执行风险
3 hours 41 minutes hence
安全客
木马化的KeePass用于部署Cobalt Strike并窃取凭据
3 hours 39 minutes hence
安全客
RVTools供应链攻击:Bumblebee恶意软件通过可信的VMware实用程序交付
3 hours 36 minutes hence
安全客
微软确认5月Windows 10更新触发Bitbit恢复
3 hours 26 minutes hence
安全客
ChatGPT推出Codex,一种用于软件编程的AI工具
3 hours 18 minutes hence
安全客
微软将在2028年之前更新Windows 10上的Office应用程序
3 hours 15 minutes hence
安全客
以色列逮捕Nomad Bridge价值1.9亿美元加密货币黑客攻击背后的新嫌疑人
3 hours 12 minutes hence
安全客
Windows远程桌面网关UAF漏洞允许远程代码执行
2 hours 33 minutes hence
安全客
护航大模型应用安全,360助力能源行业新质生产力发展
2 hours 30 minutes hence
安全客
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
2 hours 43 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
活动预告|CodeWisdom 软件智能化开发与运维系列学术报告 第17期:彻底改变大规模系统的质量保证
3 hours ago
报告人:杨晨源(伊利诺伊大学厄巴纳-香槟分校)
报告时间:5月23日 周五下午 15:00
CVE-2025-4802
3 hours 19 minutes ago
Currently trending CVE - Hype Score: 5 - Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or ...
CVE-2023-25690
3 hours 19 minutes ago
Currently trending CVE - Hype Score: 6 - Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations are affected when mod_proxy is enabled along with some form of RewriteRule
or ProxyPassMatch in which a non-specific pattern matches
some ...
CVE-2023-41992
3 hours 19 minutes ago
Currently trending CVE - Hype Score: 7 - The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against ...
CVE-2024-23282
3 hours 19 minutes ago
Currently trending CVE - Hype Score: 12 - The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, watchOS 10.5, iOS 17.5 and iPadOS 17.5, iOS 16.7.8 and iPadOS 16.7.8. A maliciously crafted email may be able to initiate FaceTime calls without user authorization.
CVE-2024-46982
3 hours 19 minutes ago
Currently trending CVE - Hype Score: 33 - Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent ...
CVE-2025-32421
3 hours 19 minutes ago
Currently trending CVE - Hype Score: 33 - Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-condition vulnerability. This issue only affects the Pages Router under certain misconfigurations, causing normal endpoints to serve `pageProps` data instead ...