Aggregator
Submit #597565: TOTOLINK A3002RU V3.0.0-B20230809.1615 Buffer Overflow [Accepted]
CVE-2025-5138 | Bitwarden up to 2.25.1 PDF File cross site scripting
CISOs flag gaps in GenAI strategy, skills, and infrastructure
95% of C-suite leaders say that GenAI is driving a new level of innovation in their organizations, according to NTT DATA. While CEOs and business leaders are committed to GenAI adoption, CISOs and operational leaders lack the necessary guidance, clarity and resources to address security risks and infrastructure challenges associated with deployment. The C-Suite disconnect 99% of C-Suite executives are planning further GenAI investments over the next two years, with 67% of CEOs planning significant … More →
The post CISOs flag gaps in GenAI strategy, skills, and infrastructure appeared first on Help Net Security.
Он сидит в реестре, запускается каждый миг и крадёт всё, что вы когда-либо вводили с клавиатуры
CVE-2017-7047 | Apple iOS up to 10.3.2 libxpc memory corruption (HT207923 / EDB-42407)
Who’s guarding the AI? Even security teams are bypassing oversight
Even security teams, the ones responsible for protecting the business, are adding to AI-related risk. A new survey by AI security company Mindgard, based on responses from over 500 cybersecurity professionals at RSAC 2025 Conference and Infosecurity Europe 2025, found that many security staff are using AI tools on the job without approval. Al tools usage by security teams (Source: Mindgard) This growing use of unapproved AI, often called shadow AI, is becoming a major … More →
The post Who’s guarding the AI? Even security teams are bypassing oversight appeared first on Help Net Security.
CVE-2025-45542 | CloudClassroom-PHP-Project 1.0 registrationform pass sql injection (EUVD-2025-16669 / EDB-52314)
Звонят роботы и клянчат данные? ASRJam сделает их глухими, а вас — недосягаемыми
CVE-2012-3575 | RBX Gallery 2.1 File Upload uploader.php access control (EDB-19019 / XFDB-76170)
AI Index 2025: What’s changing and why it matters
Stanford recently released its AI Index 2025, and it’s packed with insights on how AI is changing. For CISOs, it’s a solid check-in on where things stand. It covers what the tech can do now, how governments are responding, and where public opinion is heading. Here’s what’s worth knowing. AI is improving fast and showing up everywhere New models are performing better on hard benchmarks and tackling complex tasks like coding and math with more … More →
The post AI Index 2025: What’s changing and why it matters appeared first on Help Net Security.
亚利桑那州立大学 | HoneyPLC:用于工业控制系统的下一代蜜罐
Скачали "Google Translate" со стороны? Поздравляем, теперь за вами следит SpyNote
CVE-2025-4102 | Beaver Builder Plugin up to 2.9.1 on WordPress save_enabled_icons unrestricted upload
CVE-2025-47293 | powsybl-core up to 6.7.1 XML Parser com.powsybl.commons.xml.XmlReader xml external entity reference (GHSA-qpj9-qcwx-8jv2 / EUVD-2025-18700)
CVE-2025-47771 | powsybl-core up to 6.7.1 SparseMatrix read deserialization (GHSA-f5cx-h789-j959 / EUVD-2025-18706)
CVE-2025-49715 | Microsoft Dynamics 365 FastTrack Implementation exposure of private personal information to an unauthorized actor
CVE-2025-48058 | powsybl-core up to 6.7.1 redos (GHSA-rqpx-f6rc-7hm5 / EUVD-2025-18708)
CVE-2025-6264 | Rapid7 Velociraptor up to 0.74.2 VQL Query Admin.Client.UpdateClientConfig default permission
New infosec products of the week: June 20, 2025
Here’s a look at the most interesting products from the past week, featuring releases from BigID, Dashlane, Sumsub, and Jumio. Dashlane’s AI model alerts businesses to phishing risks In contrast to rule-based filters or reliance on a threat intel database, Dashlane’s AI phishing alerts leverage an AI model that analyzes 79 phishing indicators in real-time, such as hidden login forms, external link ratios and concealed iFrames, to determine whether a domain is potentially malicious. Analysis … More →
The post New infosec products of the week: June 20, 2025 appeared first on Help Net Security.