Aggregator
跟ChatGPT o1探讨黎巴嫩突发寻呼机(BP机)爆炸事件技术可行性
VMware vCenter Server 漏洞让攻击者能够执行远程代码
CVE-2007-2884 | Microsoft Visual Basic 6.0 resource management (EDB-3976 / XFDB-34476)
ThreeAM
GSMA Plans End-to-End Encryption for Cross-Platform RCS Messaging
志愿军女军人
CVE-2014-8493 | ZTE ZXHN H108L 4.0.0d Zrq Gr4 access control (ID 129139 / EDB-35276)
Remote attack on pagers used by Hezbollah caused 9 deaths and thousands of injuries
Data Detection & Response (DDR): Not the Dance Revolution It Claims
From Dreams to Reality: The Magic of 3D Printing, with Elle Hunt
I was in my mid-30s before I felt comfortable standing up in front of an audience and talking about technology. Come to think of it, "comfortable" isn't really the right word, as, frankly, it was nerve-racking. This, with my obvious bias as her father, makes it
CVE-2016-7992 | tcpdump up to 4.8.x Classical IP over ATM Parser print-cip.c cip_if_print memory corruption (RHSA-2017:1871 / Nessus ID 96844)
Exploding Hezbollah Pagers Not Likely a Cybersecurity Attack
It doesn't appear to be a cyberattack, security experts said of the hundreds of pagers that blew up Tuesday across Lebanon, an apparent salvo against Hezbollah militants by the Israeli government. "The only logical explanation is that explosives and a side channel for detonation was likely used."
Apple Moves to Dismiss Suit Against Spyware Firm NSO Group
Apple has filed a motion to dismiss its lawsuit against NSO Group, citing concerns over the potential exposure of sensitive threat intelligence information. The tech giant believes continuing the lawsuit could compromise its ability to protect users and lead to the disclosure of sensitive data.
UK Orgs Tout Government Help in Ransomware Incidents
Timely notification of ransomware incidents to British law enforcement agencies played a crucial role in understanding the threats and in developing mitigation strategies, the former security heads of Royal Mail and the University of Manchester said.
Can CISA’s Federal Cybersecurity Alignment Plan Really Work?
The U.S. Cybersecurity and Infrastructure Security Agency has released a new plan to further align federal cybersecurity operations that experts say will likely face significant implementation roadblocks due to a lack of funding, leadership buy-in and technical resources.
As Geopolitical Tensions Mount, Iran's Cyber Operations Grow
2024网安周 | 梆梆安全多元视角解读移动应用安全新路径
珠江水岸,南海之门。2024年国家网络安全宣传周于9月9日在广州南沙隆重举行。
网络安全为人民、网络安全靠人民。2024网安周开幕式、系列论坛、座谈会、主题日一场场引人注目、影响广泛的活动陆续展开,网络安全领域专家学者、从业人士以及致力于网安事业的高校师生、社会大众等齐聚一堂,共同展现出一幅全民行动、共同筑牢网络安全防线的生动画面。
个人信息保护分论坛
9月10日上午
梆梆安全 · 陈 露
9月10日上午,由中央网信办网络数据管理局指导,中国互联网协会主办的“个人信息保护分论坛”在广州南沙举行。政府部门、行业组织、互联网企业等相关单位共聚一堂,探讨当下个人信息保护的实践路径。广东省委网信办一级巡视员许华,中央网信办网络数据管理局数据安全监管处副处长王兆兴出席论坛并致辞。
梆梆安全陈露受邀在论坛上作主题为《监管驱动下的移动应用隐私合规建设》演讲,聚焦移动应用隐私合规监管态势,围绕高频问题剖析监管驱动下的移动应用隐私合规建设思路。
信息化时代,APP覆盖每一个人工作生活的方方面面,移动应用安全作为网络安全的重要组成部分,与人民群众的利益息息相关。随着国家个人信息保护体系不断完善,监管部门对个人信息保护的治理行动持续进行,移动应用安全治理也越来越受到应用开发者、运营者、使用者、包括监管者的高度重视。APP违规收集个人信息,强制、频繁、过度索取权限等问题依然是当下出现的高频问题,梆梆安全通过个人信息保护策略建设、合规融入开发阶段、移动应用隐私合规评估等动作助力个人信息保护。
网络安全博览会
9月11日上午
梆梆安全 · 刘 洋
9月11日上午,2024年国家网络安全宣传周网络安全博览会暨网络安全产品和服务供需洽谈会持续进行中,博览会作为国家网络安全宣传周重要活动之一,聚焦网络安全高质量发展主线,通过开展网络安全行业展示、业务洽谈、网安人才现场招聘,群众互动体验等多种形式,打造集行业交流、人才对接、科普宣传于一体的“新型博览会”。
梆梆安全刘洋作主题为《移动应用端到端全渠道的安全防护体系实践》演讲,针对当前移动端应用安全风险及移动应用安全事件提出的移动应用全渠道的整体安全建设防护体系,对移动应用端的数据安全和漏洞风险进行解析同时对移动应用端攻防对抗进行全渠道安全建设体系,聚焦移动应用的运营安全,通过全渠道的安全防护手段,保障移动应用的安全运营。
在2024年国家网络安全宣传周系列论坛、博览会等重要活动中,梆梆安全资深安全专家从多元视角与观众深入分享,吸引了众多行业监管、移动应用开发者、高校师生、媒体等驻足交流。未来,梆梆安全会继续深耕移动应用安全领域,助力大众增强网络安全防范意识,积极践行维护网络安全使命,合力共建网络强国。