Aggregator
SouthKorea Spy Agency Says DeepSeek Excessively Collects Personal Data
SEOUL, South Korea’s National Intelligence Service (NIS) has raised concerns over the Chinese AI app DeepSeek, accusing it of “excessively” collecting personal data and posing national security risks. The NIS issued an advisory urging government agencies to adopt stringent security measures when dealing with the app, which has drawn scrutiny for its data handling practices […]
The post SouthKorea Spy Agency Says DeepSeek Excessively Collects Personal Data appeared first on Cyber Security News.
CVE-2024-13643 | MVPThemes Zox News Plugin up to 3.17.0 on WordPress backup_options authorization
CVE-2025-1224 | ywoa up to 2024.07.03 UserMapper.xml listNameBySql sql injection (IBI731)
Alabama Man Pleaded Guilty for Hacking U.S. Securities and Exchange Commission X Account
Eric Council Jr., a 25-year-old from Athens, Alabama, pleaded guilty on February 10, 2025, to charges stemming from the January 2024 hacking of the U.S. Securities and Exchange Commission’s (SEC) social media account on X (formerly Twitter). The breach involved a fraudulent announcement that caused Bitcoin’s price to rise by more than $1,000 before dropping […]
The post Alabama Man Pleaded Guilty for Hacking U.S. Securities and Exchange Commission X Account appeared first on Cyber Security News.
CVE-2024-13643 | MVPThemes Zox News Plugin up to 3.17.0 on WordPress backup_options authorization
Akira Ransomware Leads The Number of Ransomware Attacks For January 2025
January 2025 marked a significant month in the ransomware landscape, with Akira emerging as the leading threat. According to recent reports, Akira was responsible for 72 attacks globally, highlighting its rapid rise in prominence. This surge in activity is part of a broader trend where ransomware groups are becoming increasingly sophisticated in their tactics and […]
The post Akira Ransomware Leads The Number of Ransomware Attacks For January 2025 appeared first on Cyber Security News.
CVE-2025-0181 | Chimpstudio WP Foodbakery Plugin up to 4.7 on WordPress authentication bypass
CVE-2025-0180 | Chimpstudio WP Foodbakery Plugin up to 4.7 on WordPress privileges management
CVE-2024-52606 | SolarWinds Orion Platform up to 2024.4.1 server-side request forgery (Nessus ID 216060)
CVE-2024-28989 | SolarWinds Web Help Desk up to 12.8.4 hard-coded key
CVE-2024-45718 | SolarWinds Kiwi Syslog NG up to 1.3 Configuration File cleartext storage
CVE-2024-52612 | SolarWinds Orion Platform up to 2024.4.1 cross site scripting
CVE-2024-52611 | SolarWinds Orion Platform up to 2024.4.1 information exposure (Nessus ID 216060)
Kill
CVE-2025-0181 | Chimpstudio WP Foodbakery Plugin up to 4.7 on WordPress authentication bypass
CVE-2025-0180 | Chimpstudio WP Foodbakery Plugin up to 4.7 on WordPress privileges management
深度解读 | 六部门印发方案,要求完善数据流通安全治理
独家|360发布全球高级威胁研究报告:我国14大重点行业面临境外APT威胁
360发布高级威胁研究报告:我国新能源汽车领域面临APT威胁加剧
近年来,我国新能源产业实现跨越式发展,尤其是新能源汽车领域,政策扶持与技术革新并进,市场规模急剧扩大。但随着从封闭网络向开放网络升级,新能源汽车面临的安全问题已经陆续出现。
近日,360数字安全集团基于360安全大模型赋能,重磅发布《2024年全球高级持续性威胁(APT)研究报告》(以下简称“报告”)。该报告提到,我国新能源领域的发展成为全球关注的焦点,别有用心的攻击者对我国新能源企业和汽车制造相关产业链的攻击活动逐渐显露。
新能源汽车不仅掌握着车主个人数据,还存储着车辆行驶轨迹、环境感知、实时影像等数据。这些数据一旦被攻击者窃取,轻则侵犯个人隐私,重则危害公共安全,甚至国家安全。然而,新能源汽车依赖的车载系统和大量软硬件,为攻击者提供了更为广泛的暴露面。360安全大模型监测显示,近几年,APT-C-00(海莲花)和APT-C-01(毒云藤)等组织已经开始将我国新能源汽车领域的科研和制造企业作为重点目标,进行长期的网络攻击。
此外,报告还披露了我国受APT攻击影响单位的14个重点行业领域,其中政府机构、教育、科研、国防军工和交通运输是遭受APT攻击活动最为集中的5个行业。APT组织针对特定行业的攻击,通常实施窃取敏感数据,甚至战略性破坏,用以服务于攻击者背后势力的政治、军事或经济等目的。
面对不断升维的高级威胁挑战,360作为国内唯一兼具数字安全和人工智能双重能力的企业,基于近20年的实战经验积累,率先提出用AI重塑安全,推出首个AI实战应用的安全行业大模型——360安全大模型。在此赋能下,360截至目前已累计捕获56个针对我国发起网络攻击的境外APT组织,积累了丰富的实战经验和技术实力。未来,360将继续深耕创新技术,积极探索高级威胁的应对思路和防护机制,不断为政企机构打造出更多体系化的解决方案。