Aggregator
【火绒安全周报】戴尔确认遭遇勒索组织入侵/假银行卡以扶贫爱心之名专骗老年人
10 months 4 weeks ago
诚邀渠道合作伙伴共启新征程
10 months 4 weeks ago
当前环境异常,需完成验证后方可继续访问。
【火绒安全周报】戴尔确认遭遇勒索组织入侵/假银行卡以扶贫爱心之名专骗老年人
10 months 4 weeks ago
当前环境出现异常,需完成验证后方可继续访问。页面提供“去验证”按钮以引导用户进行相关操作。
Submit #621811: Tenda AC10 V16.03.10.13 Heap overflow [Accepted]
10 months 4 weeks ago
Submit #621811 / VDB-317592
Xuhsy
Submit #621797: LibTIFF v4.7.0 Buffer Overflow [Accepted]
10 months 4 weeks ago
Submit #621797 / VDB-317591
arthurx
Submit #621796: LibTIFF v4.7.0 Use After Free [Accepted]
10 months 4 weeks ago
Submit #621796 / VDB-317590
arthurx
GPD 推出配备 Ryzen AI Max+ 395 的掌机
10 months 4 weeks ago
深圳中软赢科准备在 Chinajoy 2025 上展示其最高端的掌机:使用 AMD Ryzen AI Max+ 395 APU 的 GPD WIN 5。AMD Ryzen AI Max 395 此前主要用于工作站,由基于 Zen5 架构的 16 核 32 线 CPU 和 Radeon 8060S GPU 组成,华硕和惠普推出的 Ryzen AI Max 395 笔记本电脑售价在 1.5-2 万元之间,很难想象如此强大的 APU 会用于掌机,也很难想象掌机的电池续航时间会有多久。
Predictive AI: The “Quiet Catalyst” Behind The Future of Cybersecurity
10 months 4 weeks ago
CVE-2025-8175 | D-Link DI-8400 16.07.26A1 jhttpd usb_paswd.asp share_enable null pointer dereference
10 months 4 weeks ago
A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument share_enable leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-8175. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
MCP协议中隐藏的十大AI集成安全风险
10 months 4 weeks ago
Model Context Protocol (MCP) 正迅速成为连接 AI 代理与数据源、工具、服务的标准通信协议,MCP 带来的安全漏洞也在显现,对 agentic AI 系统构成独特威胁。
MCP协议中隐藏的十大AI集成安全风险
10 months 4 weeks ago
当前环境出现异常状态,需完成验证操作后方可继续访问。
具透 | iOS 26 Public Beta 终于来了,升级以后记得试试这些功能
10 months 4 weeks ago
Apple发布iOS 26等系统公开测试版,引入液态玻璃设计风格,优化锁屏界面并支持3D效果与动态背景。主屏幕和小组件布局更灵活,Safari浏览器采用沉浸式设计。相机应用UI重构,照片功能升级。底部横条存在感降低。新增实时翻译、游戏聚合应用及电池续航优化等功能。
虚拟化逃逸与 Windows 内核提权深度教学
10 months 4 weeks ago
虚拟化逃逸 Windows 内核提权
CVE-2025-8174 | code-projects Voting System 1.0 candidates_add.php photo unrestricted upload
10 months 4 weeks ago
A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/candidates_add.php. The manipulation of the argument photo leads to unrestricted upload.
This vulnerability is handled as CVE-2025-8174. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Weaponized VSCode:基于笔记驱动的 VSCode 辅助渗透测试项目
10 months 4 weeks ago
404星链计划 | 新项目+2
10 months 4 weeks ago
本期404星链计划新收录的2个优质项目分别是WeaponizedVSCode和QScan。
404星链计划 | 新项目+2
10 months 4 weeks ago
当前环境出现异常问题,需完成验证后才能继续访问,并提供了"去验证"和"返回"两个操作选项。
Weaponized VSCode:基于笔记驱动的 VSCode 辅助渗透测试项目
10 months 4 weeks ago
当前环境异常,需完成验证后方可继续访问。
Submit #621708: D-Link DI-8400 DI-8400-16.07.26A1 NULL Pointer Dereference [Accepted]
10 months 4 weeks ago
Submit #621708 / VDB-317589
KrisW