Aggregator
四川某科技公司未落实网络安全保护义务致数据泄露被处罚
7 months ago
当前环境出现异常,需完成验证后才能继续访问。
lockc: Making containers more secure with eBPF and Linux Security Modules
7 months ago
lockc lockc is open source software for providing MAC (Mandatory Access Control) type of security audit for container workloads. The main reason why lockc exists is that containers do not contain. Containers are not as secure and isolated...
The post lockc: Making containers more secure with eBPF and Linux Security Modules appeared first on Penetration Testing Tools.
ddos
INC
7 months ago
You must login to view this content
cohenido
CVE-2025-37105 | HPE AutoPass License Server up to 9.17 hsqldb code injection (EUVD-2025-21734)
7 months ago
A vulnerability was found in HPE AutoPass License Server up to 9.17 and classified as critical. Affected by this issue is some unknown functionality of the component hsqldb. The manipulation leads to code injection.
This vulnerability is handled as CVE-2025-37105. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-53908 | rommapp romm up to 3.10.2/4.0.0-beta2 /api/raw path traversal (GHSA-fx9g-xw4j-jwc3)
7 months ago
A vulnerability, which was classified as problematic, has been found in rommapp romm up to 3.10.2/4.0.0-beta2. Affected by this issue is some unknown functionality of the file /api/raw. The manipulation leads to path traversal: '/dir/../filename'.
This vulnerability is handled as CVE-2025-53908. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-51630 | TOTOLINK N350RT 9.3.5u.6139_B20201216 setIpPortFilterRules ePort buffer overflow (EUVD-2025-21773)
7 months ago
A vulnerability classified as critical was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. This vulnerability affects the function setIpPortFilterRules. The manipulation of the argument ePort leads to buffer overflow.
This vulnerability was named CVE-2025-51630. The attack can be initiated remotely. There is no exploit available.
vuldb.com
探讨AI安全研究最前沿,InForSec夏令营导师面对面共聚西电,欢迎报名参会!
7 months ago
2025年8月6~7日,2025 InForSec夏令营将召开为期两天的InForSec学术交流会暨“导师面对面”专题活动。欢迎大家报名参会!
探讨AI安全研究最前沿,InForSec夏令营导师面对面共聚西电,欢迎报名参会!
7 months ago
当前环境异常,需完成验证后继续访问.
美国铁路关基系统曝漏洞,英国零售商650万数据遭窃取|一周特辑
7 months ago
点击查看更多本周网络安全大事件。
CVE-2024-41068 | Linux Kernel up to 6.9.10 s390 lib/list_debug.c sclp_init state issue (Nessus ID 207884 / WID-SEC-2024-1722)
7 months ago
A vulnerability was found in Linux Kernel up to 6.9.10 and classified as problematic. This issue affects the function sclp_init in the library lib/list_debug.c of the component s390. The manipulation leads to state issue.
The identification of this vulnerability is CVE-2024-41068. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41065 | Linux Kernel up to 6.9.10 pseries mm/usercopy.c information disclosure (Nessus ID 207773 / WID-SEC-2024-1722)
7 months ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.9.10. This issue affects some unknown processing of the file mm/usercopy.c of the component pseries. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-41065. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41063 | Linux Kernel up to 6.9.10 hci_unregister_dev deadlock (Nessus ID 208953 / WID-SEC-2024-1722)
7 months ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.9.10. This affects the function hci_unregister_dev. The manipulation leads to deadlock.
This vulnerability is uniquely identified as CVE-2024-41063. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41061 | Linux Kernel up to 6.9.10 AMD Display dml2_calculate_rq_and_dlg_params array index (94166fe12543/0ad4b4a2f635 / Nessus ID 210060)
7 months ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.9.10. Affected by this vulnerability is the function dml2_calculate_rq_and_dlg_params of the component AMD Display. The manipulation leads to improper validation of array index.
This vulnerability is known as CVE-2024-41061. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Security, AI Oversight Are Flashpoints in Draft Defense Bill
7 months ago
House, Senate Versions of 2026 NDAA Offer Competing Approaches to Cyber
Washington is wagering that future conflicts will unfold as much in cyberspace as on the battlefield, with House and Senate lawmakers unveiling dueling drafts of a nearly $900 billion defense bill that spotlights needs for cybersecurity and artificial intelligence technology.
Washington is wagering that future conflicts will unfold as much in cyberspace as on the battlefield, with House and Senate lawmakers unveiling dueling drafts of a nearly $900 billion defense bill that spotlights needs for cybersecurity and artificial intelligence technology.
Texas Drug, Alcohol Testing Firm Hack Affects Nearly 750,000
7 months ago
Cybercrime Group Bian Lian Claimed Responsibility for Attack Last Year
A Texas-based firm that conducts workplace drug and alcohol testing for private employers and for compliance with state and federal agencies, including the Department of Transportation, disclosed to regulators that a July 2024 hacking incident affected nearly 750,000 people.
A Texas-based firm that conducts workplace drug and alcohol testing for private employers and for compliance with state and federal agencies, including the Department of Transportation, disclosed to regulators that a July 2024 hacking incident affected nearly 750,000 people.
Botnet Abuses GitHub Repositories to Spread Malware
7 months ago
Hackers Using Amadey Bot to Drops Payloads From Fake GitHub Accounts
Threat actors are using public GitHub repositories to host and distribute malware through the Amadey botnet in an ongoing campaign linked to a broader malware-as-a-service operation, Cisco Talos said in a report published Thursday.
Threat actors are using public GitHub repositories to host and distribute malware through the Amadey botnet in an ongoing campaign linked to a broader malware-as-a-service operation, Cisco Talos said in a report published Thursday.
UK Creative Community, Big Tech Resume AI Copyright Talks
7 months ago
New Working Group Launched After Two Failed Attempts to Resolve AI Training Impasse
The U.K. government on Wednesday began its latest round of talks between creative owners and the artificial intelligence sector to work out a potential deal on the use of copyrighted content to train AI models. The discussions follow two previous failed attempts.
The U.K. government on Wednesday began its latest round of talks between creative owners and the artificial intelligence sector to work out a potential deal on the use of copyrighted content to train AI models. The discussions follow two previous failed attempts.
New CrushFTP zero-day exploited in attacks to hijack servers
7 months ago
CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. [...]
Lawrence Abrams
CrushFTP zero-day exploited in attacks to gain admin access on servers
7 months ago
CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. [...]
Lawrence Abrams