Aggregator
CVE-2024-26688 | Linux Kernel up to 6.7.5 null pointer dereference (Nessus ID 239850 / WID-SEC-2024-0773)
CVE-2024-26697 | Linux Kernel up to 6.7.5 nilfs2 nilfs_recovery_copy_block uninitialized pointer (Nessus ID 239850 / WID-SEC-2024-0773)
CVE-2024-26685 | Linux Kernel up to 6.7.5 nilfs2 end_buffer_async_write race condition (Nessus ID 232182 / WID-SEC-2024-0773)
CVE-2022-3061 | Linux Kernel i740 Driver ioctl pixclock divide by zero (Nessus ID 236648 / WID-SEC-2024-0773)
CVE-2024-26686 | Linux Kernel up to 6.1.81/6.7.5 lock_task_sighand denial of service (cf4b8c39b9a0/27978243f165/7601df8031fd / Nessus ID 207693)
CVE-2023-39323 | Google Go Build code injection (Nessus ID 211363 / WID-SEC-2023-2516)
I Hacked (Logged) In Through The Front Door
Identity-based attacks have become the path of least resistance and it is the responsibility of all organizations to shore up their defenses to mitigate these threats.
The post I Hacked (Logged) In Through The Front Door appeared first on Security Boulevard.
研究揭示全球精英离岸隐藏财富的模式
CVE-2024-7595 | GRE Protocol/GRE6 Protocol improper authentication (Nessus ID 242166)
CVE-2024-47174 | NixOS nix up to 2.18.7/2.24.7 HTTPS Connection certificate validation (GHSA-6fjr-mq49-mm2c / Nessus ID 242201)
CVE-2024-45593 | NixOS nix up to 2.24.5 NAR path traversal (GHSA-h4vv-h3jq-v493 / Nessus ID 242201)
CVE-2024-27297 | NixOS nix up to 2.3.17/2.18.1/2.19.3/2.20.4 on Linux Unix Domain Socket toctou (GHSA-2ffj-w4mj-pg37 / Nessus ID 242201)
CVE-2024-38531 | NixOS nix up to 2.23.0 insecure preserved inherited permissions (Nessus ID 242201)
Veranderende wereldorde bevestigt belang van een weerbaar Nederland
Лицо админа = вы: подмена SID ломает модель персональной биометрии в Windows Hello. Эксплоит в паблике
PyPI Blocks Inbox.ru Domains After 1,500+ Fake Package Uploads
The Python Package Index (PyPI) has implemented an administrative block on the inbox.ru email domain, prohibiting its use for new user registrations and as additional verification addresses. This action stems from a recent campaign that exploited the domain to create over 250 fraudulent accounts, which in turn uploaded more than 1,500 empty projects. These bogus […]
The post PyPI Blocks Inbox.ru Domains After 1,500+ Fake Package Uploads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CNNVD关于Oracle多个安全漏洞的通报
Cloud Cost Conundrum: Rising Expenses Hinder AI Innovation in Europe
Critical SharePoint RCE Vulnerability Exploited via Malicious XML in Web Part
A severe remote code execution (RCE) vulnerability has been discovered in Microsoft SharePoint that allows attackers to execute arbitrary code through malicious XML content embedded within web parts. According to the recent report, the vulnerability, which affects the deserialization process of webpart properties, represents a significant security risk for organizations running vulnerable SharePoint installations. Technical […]
The post Critical SharePoint RCE Vulnerability Exploited via Malicious XML in Web Part appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.