Aggregator
CVE-2025-4736 | PHPGurukul Daily Expense Tracker 1.1 /register.php email sql injection (EUVD-2025-15393)
CVE-2025-20082 | Intel Server D50DNP Board/Server M50FCP Board UEFI Firmware SmiVariable Driver toctou (intel-sa-01269 / EUVD-2025-14552)
CVE-2025-20095 | Intel RealSense SDK Software up to 2.56.1 default permission (intel-sa-01305 / EUVD-2025-14561)
CVE-2025-21094 | Intel Server D50DNP Board/Server M50FCP Board UEFI firmware DXE Module input validation (intel-sa-01269 / EUVD-2025-14555)
CVE-2025-20079 | Intel Advisor Software uncontrolled search path (intel-sa-01263 / EUVD-2025-14564)
CVE-2025-20083 | Intel Slim Bootloader improper authentication (intel-sa-01290 / EUVD-2025-14567)
Зашёл на сайт — отдал сессию: критический баг в Chrome превращает любую страницу в шпиона
Polymorphic phishing attacks flood inboxes
AI is transforming the phishing threat landscape at a pace many security teams are struggling to match, according to Cofense. In 2024, researchers tracked one malicious email every 42 seconds. Many of the 42-second attacks were part of polymorphic phishing attacks. Unlike traditional phishing methods, polymorphic phishing attacks rely on dynamic changes to the appearance and structure of malicious emails or links. Attackers use sophisticated algorithms to alter subject lines, sender addresses, and email content … More →
The post Polymorphic phishing attacks flood inboxes appeared first on Help Net Security.
CVE-2007-1111 | ActiveCalendar data/xmlevents.php css cross site scripting (EDB-29646 / XFDB-32690)
Что случается один раз в минуту, дважды в момент и ни разу в тысячу лет — и почему GPT знает это с первого раза?
«Введите ключ восстановления» — Microsoft сломала всё с последним обновлением Windows
CVE-2004-1972 | Video Gallery Plugin 0.1 on PHP-Nuke sql injection (EDB-24060 / XFDB-15979)
Cybersecurity Skills Framework connects the dots between IT job roles and the practical skills needed
The Linux Foundation, in collaboration with OpenSSF and Linux Foundation Education, has released the Cybersecurity Skills Framework, a global reference guide that helps organizations identify and address critical cybersecurity competencies across a broad range of IT job families. “Cybersecurity is now a leadership issue, not just a technical one,” said Steve Fernandez, General Manager at OpenSSF. “Our framework gives organizations a straightforward way to identify gaps and prioritize the security skills that matter most, based … More →
The post Cybersecurity Skills Framework connects the dots between IT job roles and the practical skills needed appeared first on Help Net Security.
ChatGPT скоро сможет составлять протоколы и отчёты — а вы точно хотите, чтобы он всё слышал?
How working in a stressful environment affects cybersecurity
Stressful work environments don’t just erode morale, they can quietly undermine cybersecurity. When employees feel overworked, unsupported, or mistreated, their judgment and decision-making suffer. “From an organizational perspective, a toxic culture often leads to increased errors, missed threats, decreased productivity, and higher turnover rates,” said Rob Lee, Chief of Research and Head of Faculty at SANS Institute. According to CyberArk, 65% of office workers admit they’ve bypassed cybersecurity policies to stay productive. Frustration and anger … More →
The post How working in a stressful environment affects cybersecurity appeared first on Help Net Security.