Aggregator
网络攻击影响国家金融稳定!外媒称伊朗被迫支付超2000万元赎金
5 months 1 week ago
曾多次攻击伊朗企业的黑客组织IRLeaks对此次事件负责
CVE-2007-6091 | JiRos Banner System login_confirm.asp sql injection (EDB-30775 / BID-26479)
5 months 1 week ago
A vulnerability has been found in JiRos Banner System and classified as critical. Affected by this vulnerability is an unknown functionality of the file advertiser/login_confirm.asp. The manipulation leads to sql injection.
This vulnerability is known as CVE-2007-6091. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
评论 | 把未成年人模式建设好、运用好
5 months 1 week ago
青少年模式是未成年人模式的前身,是防止未成年人网络沉迷、接触不良网络信息的“防火墙”。
评论 | 整治“人肉开盒”,不妨换个思路
5 months 1 week ago
“人肉开盒”,是指通过非法手段进行网络搜索、挖掘,搜集个人隐私信息,并在网上公布,引导网民对被“开盒”者进行网暴,往往给受害者造成巨大精神压力和伤害。尤其令人痛心的是,部分未成年人也参与到“人肉开盒”中。
专家观点 | 如何让人工智能实现认知正义
5 months 1 week ago
近几年,人工智能成为人类的“好帮手”,但也出现了各种问题。其中,人工智能系统基于不良的数据来源和有缺陷的算法设计生成错误的“知识”,且没有对所输出内容进行价值判断的能力,无法承担相应认知责任,导致系统性的认知偏差,是一个比较突出的问题。
关注 | 公安机关网安部门指导互联网平台强化自律自治
5 months 1 week ago
公安机关网安部门高度重视,在持续高压严打网络违法犯罪、强化网络乱象治理的同时,指导超大型互联网平台切实压紧压实主体责任,充分发挥公约协议的自律自治作用,共同营造清朗网络空间,各大互联网平台积极响应。
聚焦 | 2024外滩大会今日起在上海黄浦举办
5 months 1 week ago
今年大会主题延续“科技·创造可持续未来”,致力于构建一个促进国际交流、科技与人文融合的对话平台,助力上海打造具有全球影响力的国际金融中心和科技创新中心。
报名开启 | CCS 2024成都网络安全系列活动——国家漏洞库网络安全漏洞治理产业协同创新研讨活动
5 months 1 week ago
CCS 2024成都网络安全系列活动——国家漏洞库网络安全漏洞治理产业协同创新研讨活动报名开启!
可信数据空间 | 启明星辰数据要素安全流通平台正式发布
5 months 1 week ago
构建数据要素【分类流通、分级保护】的可信数据流通安全治理空间,推动安全能力覆盖数据供给、流通、使用全过程。
Cloud Access Security Brokers (CASBs): Are They Still Relevant?
5 months 1 week ago
Understanding how CASBs are developed and how to use them effectively can assist them in safeguarding their cloud-based assets against evolving threats.
The post Cloud Access Security Brokers (CASBs): Are They Still Relevant? appeared first on Security Boulevard.
Devin Partida
伪造学历的南非铁路客运集团前首席工程师被判 15 年徒刑
5 months 1 week ago
南非铁路客运集团 (Prasa)前首席工程师 Daniel Mthimkhulu 因伪造工程学位和博士学位被判 15 年徒刑。Mthimkhulu 担任 Prasa 工程负责人长达五年之久,他的薪水高达 15.6 万美元,他在简历中声称自己拥有多个机械工程学位,其中包括来自南非著名的 Witwatersrand 大学学位,以及德国一所大学的博士学位。但法庭获悉他只读完高中。他在 2015 年 7 月被捕。15 年前他靠着伪造的学位迅速晋升为总工程师。他还伪造了来自德国的工作邀请函,说服公司提高其薪水以免他跳槽。他牵头购买了数十列西班牙火车,结果因为火车太高而无法使用。
向250万个主机发送5亿次HTTP请求
5 months 1 week ago
CVE-2024-8407 | alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba handlers.go emailAddress cross site scripting
5 months 1 week ago
A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file cmd/akademy/handler/handlers.go. The manipulation of the argument emailAddress leads to cross site scripting.
This vulnerability is known as CVE-2024-8407. The attack can be launched remotely. Furthermore, there is an exploit available.
This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
vuldb.com
CVE-2024-8413 | RaspControl 1.0 index.php action cross site scripting
5 months 1 week ago
A vulnerability was found in RaspControl 1.0. It has been rated as problematic. This issue affects some unknown processing of the file index.php. The manipulation of the argument action leads to cross site scripting.
The identification of this vulnerability is CVE-2024-8413. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7834 | Overwolf up to 250.1.0 on Windows dll uncontrolled search path
5 months 1 week ago
A vulnerability, which was classified as critical, has been found in Overwolf up to 250.1.0 on Windows. Affected by this issue is some unknown functionality in the library dll. The manipulation leads to uncontrolled search path.
This vulnerability is handled as CVE-2024-7834. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44383 | WAYOS FBM-291W 19.09.11 msp_info_htm command injection
5 months 1 week ago
A vulnerability, which was classified as problematic, was found in WAYOS FBM-291W 19.09.11. This affects the function msp_info_htm. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2024-44383. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-44400 | D-Link DI-8400 16.07.26A1 upgrade_filter_asp command injection
5 months 1 week ago
A vulnerability has been found in D-Link DI-8400 16.07.26A1 and classified as critical. This vulnerability affects the function upgrade_filter_asp. The manipulation leads to command injection.
This vulnerability was named CVE-2024-44400. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-45507 | Apache OFBiz up to 18.12.15 URL server-side request forgery
5 months 1 week ago
A vulnerability classified as critical was found in Apache OFBiz up to 18.12.15. Affected by this vulnerability is an unknown functionality of the component URL Handler. The manipulation leads to server-side request forgery.
This vulnerability is known as CVE-2024-45507. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8289 | WooCommerce Multivendor Marketplace Solution Plugin up to 4.2.0 on WordPress authorization
5 months 1 week ago
A vulnerability has been found in WooCommerce Multivendor Marketplace Solution Plugin up to 4.2.0 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-8289. Access to the local network is required for this attack. There is no exploit available.
vuldb.com