Aggregator
CVE-2025-23363 | Siemens Teamcenter up to 14.0.0.2 Link redirect (ssa-656895)
10 months ago
A vulnerability classified as problematic has been found in Siemens Teamcenter. This affects an unknown part of the component Link Handler. The manipulation leads to open redirect.
This vulnerability is uniquely identified as CVE-2025-23363. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
美国有史以来最大、最严重的数据泄露事件?马斯克DOGE访问权引发安全担忧;黑客承认入侵SEC的X账户并发布虚假消息 | 牛览
10 months ago
新闻速览 •《公共安全视频图像信息系统管理条例》公布,4月1日起施行 •美国有史以来最大、最严重的数据泄露事件 […]
aqniu
CVE-2024-54090 | Siemens APOGEE PXC BACnet out-of-bounds (ssa-615116)
10 months ago
A vulnerability was found in Siemens APOGEE PXC BACnet, APOGEE PXC P2 Ethernet and TALON TC BACnet. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2024-54090. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-54089 | Siemens APOGEE PXC BACnet inadequate encryption (ssa-615116)
10 months ago
A vulnerability was found in Siemens APOGEE PXC BACnet, APOGEE PXC P2 Ethernet and TALON TC BACnet. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to inadequate encryption strength.
This vulnerability is known as CVE-2024-54089. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-24499 | Siemens SCALANCE WAB762-1 up to 2.9.9 input validation (ssa-769027)
10 months ago
A vulnerability was found in Siemens SCALANCE WAB762-1 up to 2.9.9. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2025-24499. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
【安全圈】涉嫌伪造SEC帖子背后的黑客可能会在认罪协议中没收5万美元
10 months ago
【安全圈】8Base 勒索软件暗网网站被查封,四名运营商被捕
10 months ago
【安全圈】苹果修复了在“极其复杂”的攻击中被利用的零日漏洞
10 months ago
【安全圈】Deepseek 安全故障:AI 网络防御的未来将何去何从?
10 months ago
AI驱动的安全漏洞发现正在重塑网络安全新模式
10 months ago
网络安全是安全数字时代最大的挑战之一。随着网络攻击日益复杂和不断演进,传统的安全措施已经无法完全保护我们的系统 […]
aqniu
[Meachines] [Easy] Previse EAR+Php files analysis RCE+TRP00F权限提升+Gzip路径劫持权限提升
10 months ago
#EAR #Php files analysis RCE #TRP00F权限提升 #Gzip路径劫持权限提升
从 IAM 松散管理到零信任架构:Sendbird AWS 安全实战演进实录
10 months ago
本文总结了 Sendbird 从初创期到成熟阶段的 AWS 安全实践。
CVE-2024-54015 | Siemens SIPROTEC 5 up to 9.89 default credentials (ssa-767615)
10 months ago
A vulnerability was found in Siemens SIPROTEC 5 up to 9.89 and classified as problematic. This issue affects some unknown processing. The manipulation leads to use of default credentials.
The identification of this vulnerability is CVE-2024-54015. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45386 | Siemens SIMATIC PCS neo Session Token session expiration (ssa-342348)
10 months ago
A vulnerability has been found in Siemens SIMATIC PCS neo, SIMOCODE ES, SIRIUS Safety ES, SIRIUS Soft Starter ES and TIA Administrator and classified as very critical. This vulnerability affects unknown code of the component Session Token Handler. The manipulation leads to session expiration.
This vulnerability was named CVE-2024-45386. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Apple fixes zero-day flaw exploited in “extremely sophisticated” attack (CVE-2025-24200)
10 months ago
Users of iPhones and iPads that run iOS/iPadOS 18 and iPadOS 17 are urged to implement the latest updates to plug a security feature bypass vulnerability (CVE-2025-24200) exploited in the wild in “an extremely sophisticated” attack. The vulnerability (CVE-2025-24200) “A physical attack may disable USB Restricted Mode on a locked device,” Apple explained. USB Restricted Mode is a feature Apple introduced in 2018 to protect users against device unlocking (“cracking”) tools such as
The post Apple fixes zero-day flaw exploited in “extremely sophisticated” attack (CVE-2025-24200) appeared first on Help Net Security.
Zeljka Zorz
Цифровое неравенство: как ИИ создаёт новые профессиональные элиты
10 months ago
Anthropic выяснила, каким специалистам не грозит замена ИИ.
2024年澳大利亚人每秒遭受一起网络攻击
10 months ago
安全客
邮件安全防护与溯源:从协议、防护到溯源
10 months ago
当今电子邮件已成为信息传递的重要渠道,但随之而来的邮件伪造问题不容忽视,文本介绍的是邮箱发送的基本协议以及防护策略,包括SPF、DKIM校验、DMARC策略等,以及邮件溯源的基本方法。
Apple Mitigates “Extremely Sophisticated” Zero-Day Exploit
10 months ago
Apple has patched a zero-day vulnerability being exploited in targeted attacks