Aggregator
CVE-2024-35176 | rexml Gem up to 3.2.6 on Ruby XML Data Parser attribute resource consumption (GHSA-vg3r-rm7w-2xgh / Nessus ID 210110)
Intel Maps New vPro Chips to MITRE's ATT&CK Framework
New infosec products of the week: March 7, 2025
Here’s a look at the most interesting products from the past week, featuring releases from Outpost24, Palo Alto Networks, Red Canary, and Sonatype. Outpost24 introduces CyberFlex to streamline attack surface management and pen testing Outpost24 has launched Outpost24 CyberFlex, a comprehensive application security solution that combines Attack Surface Management (ASM) and Penetration Testing as a Service (PTaaS) to manage and secure an organization’s external-facing applications, and deliver enhanced visibility in a flexible and agile way. … More →
The post New infosec products of the week: March 7, 2025 appeared first on Help Net Security.
艾普拉斯急聘汽车网络安全高级工程师,职等你来展身手!!
Cisco Secure Client for Windows Let Attackers Execute Arbitrary Code With SYSTEM Privileges
A newly identified vulnerability in the Cisco Secure Client for Windows could allow attackers to execute arbitrary code with SYSTEM privileges. The vulnerability lies within the interprocess communication (IPC) channel and can be exploited by an authenticated, local attacker to perform a DLL hijacking attack. This vulnerability is present only when the Secure Firewall Posture […]
The post Cisco Secure Client for Windows Let Attackers Execute Arbitrary Code With SYSTEM Privileges appeared first on Cyber Security News.