Aggregator
欧盟《健康数据空间条例》正式版本(全文翻译)
欧盟《健康数据空间条例》正式版本(全文翻译)
欧盟《健康数据空间条例》正式版本(全文翻译)
CVE-2024-27564漏洞被利用攻击ChatGPT,一周内攻击次数超万次
Hackers target AI and crypto as software supply chain risks grow
The growing sophistication of software supply chain attacks is driven by widespread flaws in open-source and third-party commercial software, along with malicious campaigns that specifically target AI and cryptocurrency development pipelines, according to a ReversingLabs report. According to ReversingLabs data, open-source software remained a key element of supply chain risk in 2024. For example, incidents of exposed development secrets via publicly accessible, open-source packages rose 12% compared to 2023. And critical and exploitable software flaws … More →
The post Hackers target AI and crypto as software supply chain risks grow appeared first on Help Net Security.
Cloudflare推出后量子加密技术,抵御量子计算机攻击
Cybersecurity jobs available right now: March 18, 2025
Application Security Expert monday.com | United Kingdom | Hybrid – View job details As an Application Security Expert, you will provide guidance on security best practices and compliance, and undertake security testing. Develop security testing plans and integrate them into the software development lifecycle. Perform and oversee security testing and manage remediation of identified vulnerabilities. Application Security Analyst II, Information Security First National Financial | Canada | On-site – View job details As an Application … More →
The post Cybersecurity jobs available right now: March 18, 2025 appeared first on Help Net Security.
ZDI-CAN-23480: Pratt & Whitney
ZDI-CAN-26713: PDF-XChange
ZDI-CAN-26141: Academy Software Foundation
CVE-2024-57790 | IXON IXrouter IX2400 3.0 UART/SSH hard-coded password
CVE-2025-25667 | Tenda AC8V4 16.03.34.06 get_parentControl_list_Info urls stack-based overflow
CVE-2025-25668 | Tenda AC8V4 16.03.34.06 sub_47D878 shareSpeed stack-based overflow
CVE-2025-25875 | itsourcecode Simple ChatBox up to 1.0 /message.php sql injection
CVE-2024-55156 | Java SDK for CloudEvents 4.0.1 XML Event Mesage deserializeArgs xml external entity reference
CVE-2024-57176 | White-Jotter 0.2.2 URL shiroFilter path traversal
CVE-2022-41545 | Netgear C7800 6.01.07 Administrative Web Interface cleartext transmission
谷歌以320亿美元收购Wiz,加速AI时代云安全与多云战略
Critical Apache Tomcat RCE Vulnerability Exploited in Just 30hrs of Public Exploit
Security researchers have confirmed that a critical remote code execution (RCE) vulnerability in Apache Tomcat, tracked as CVE-2025-24813, is being actively exploited in the wild. The vulnerability, which enables attackers to take control of servers with a simple PUT request, was disclosed last week, and proof-of-concept exploits were published on GitHub merely 30 hours later. […]
The post Critical Apache Tomcat RCE Vulnerability Exploited in Just 30hrs of Public Exploit appeared first on Cyber Security News.