Aggregator
CVE-2024-11328 | CLUEVO LMS, E-Learning Platform Plugin up to 1.13.2 on WordPress cross site scripting
CVE-2024-11686 | WhatsApp Click to Chat Plugin up to 3.0.4 on WordPress cross site scripting
CVE-2024-12819 | Searchie Plugin up to 1.17.0 on WordPress cross site scripting
CVE-2025-25069 | Apache Kvrocks up to 2.11.0 HTTP Request interpretation input
CVE-2024-12054 | ZF RSSPlus RSSPlus SecurityAccess Service authentication bypass (icsa-25-021-03)
Grip Security unveils SSPM solution to strengthen SaaS security posture
Grip Security has unveiled its SaaS Security Posture Management (SSPM) solution, which proactively identifies misconfigurations, enforces best practices and strengthens SaaS security posture against emerging risks. Unlike traditional SSPM products, Grip SSPM is built on a foundation of visibility and automation, enabling organizations to combine misconfiguration remediation and policy enforcement as part of a comprehensive security program that addresses SaaS security end-to-end. By consolidating SaaS security into a single platform, Grip SSPM streamlines operations, automates … More →
The post Grip Security unveils SSPM solution to strengthen SaaS security posture appeared first on Help Net Security.
清华大学李琦老师课题组招聘研究员、博士后、工程师
RedMike Hackers Exploited 1000+ Cisco Devices to Gain Admin Access
Researchers observed a sophisticated cyber-espionage campaign led by the Chinese state-sponsored group known as “Salt Typhoon,” also referred to as “RedMike.” Between December 2024 and January 2025, the group exploited over 1,000 unpatched Cisco network devices globally, targeting telecommunications providers and universities. The campaign highlights the ongoing vulnerability of critical infrastructure and the strategic intelligence […]
The post RedMike Hackers Exploited 1000+ Cisco Devices to Gain Admin Access appeared first on Cyber Security News.
作为换囚交易的一部分美国释放了 BTC-e 联合创始人
哪吒很棒,我们也很棒!——三刷《哪吒2》有感
哪吒很棒,我们也很棒!——三刷《哪吒2》有感
哪吒很棒,我们也很棒!——三刷《哪吒2》有感
哪吒很棒,我们也很棒!——三刷《哪吒2》有感
哪吒很棒,我们也很棒!——三刷《哪吒2》有感
哪吒很棒,我们也很棒!——三刷《哪吒2》有感
哪吒很棒,我们也很棒!——三刷《哪吒2》有感
Британский бэкдор в Apple подрывает приватность всего мира
报告解读:2024 年第四季度制造业受勒索软件打击最为严重
AMD Ryzen DLL Hijacking Vulnerability Let Attackers Execute Arbitrary Code
A high-severity security vulnerability, identified as CVE-2024-21966, has been discovered in the AMD Ryzen™ Master Utility, a software tool designed to optimize the performance of AMD Ryzen™ processors. The vulnerability, classified as DLL hijacking, could allow attackers to execute arbitrary code and escalate privileges on affected systems. With a CVSS score of 7.3, this vulnerability […]
The post AMD Ryzen DLL Hijacking Vulnerability Let Attackers Execute Arbitrary Code appeared first on Cyber Security News.