Aggregator
CVE-2024-52531 | GNOME libsoup up to 3.6.0 soup_header_parse_param_list_strict buffer overflow (Nessus ID 211702)
CVE-2024-34088 | FRRouting up to 9.1 OSPF Daemon ospf_te.c get_edge denial of service (Nessus ID 211701)
CVE-2023-40400 | Apple watchOS App denial of service (Nessus ID 211708)
CVE-2023-40400 | Apple macOS App denial of service (Nessus ID 211708)
CVE-2023-42366 | BusyBox 1.36.1 awk.c next_token heap-based overflow (Nessus ID 211706)
CVE-2024-25431 | bytecodealliance wasm-micro-runtime 06df58f File check_was_abi_compatibility Privilege Escalation (Issue 3122 / 06df58f)
CVE-2023-40400 | Apple iOS/iPadOS App denial of service (Nessus ID 211708)
CVE-2023-7256 | tcpdump libpcap up to 1.8.x/1.9.x/1.10.4 sock_initaddress double free (Nessus ID 211708)
Deepfake attacks occur every five minutes
As cybercriminals continue to adapt their techniques to find new ways through defenses, AI-assisted fraud is growing increasingly sophisticated and frequent, according to Entrust. The findings reveal a deepfake attack happened every five minutes in 2024, while digital document forgeries increased 244% year-over-year. The rise of amateur fraudsters For the first time, digital document forgery surpassed physical counterfeits as the leading method of fraud in 2024, with digital forgeries accounting for 57% of all document … More →
The post Deepfake attacks occur every five minutes appeared first on Help Net Security.
Ike Goes Live On Mainnet: Unlocking Liquid Staking On Aleph Zero
Coinshift Launches csUSDL, Announces Strategic Partnerships
Chinese hackers target Linux with new WolfsBane malware
Feds Charge Five Men in ‘Scattered Spider’ Roundup
Qilin
Qilin
AI自动挖洞不是梦,谷歌AI工具OSS-FASZ又发现26个开源漏洞
福特就客户数据遭泄露一事展开调查
一名威胁者声称在黑客论坛上泄露了 44,000 条客户记录,还暗示黑客“IntelBroker”参与了 2024 年 11 月的泄密事件,泄露的福特客户记录中包含有客户信息,包括全名、位置、购买详细信息、经销商信息等。目前福特公司正在调查其遭受数据泄露的指控。
暴露的记录并不是极其敏感,但它们包含个人身份信息,这些信息可能会导致针对暴露个人的网络钓鱼和社会工程攻击。
目前,威胁者并没有试图出售该数据集,而是以 8 个积分(相当于 2 美元多一点)的价格将其提供给黑客论坛的注册会员。
据称福特数据在黑客论坛上泄露
该公司发言人表示福特公司已经意识到并正在积极调查有关福特数据被泄露的指控。
根据威胁者最近的表述,IntelBroker 参与此次泄露事件为威胁者的指控提供了一定的可信度。该黑客最近在思科的 DevHub 门户、诺基亚(通过第三方)、欧洲刑警组织的 EPE 门户网站和 T-Mobile(通过供应商)进行了实质性的违规行为。
威胁者泄露的数据样本中提到的地点来自世界各地,包括美国。为了减轻这种潜在数据泄露带来的风险,请谨慎对待未经请求的通信,并拒绝以任何借口透露更多信息的请求。
福特根据正在进行的调查的新发现确定福特的系统或客户数据没有遭到破坏。此事涉及第三方供应商和一小批公开的经销商的营业地址。目前此事现已得到解决。
Come playlist e podcast su Spotify promuovono software pirata
New infosec products of the week: November 22, 2024
Here’s a look at the most interesting products from the past week, featuring releases from Aon, Arkose Labs, HiddenLayer, Hornetsecurity, Radware, and Tanium. Arkose Device ID detects suspicious activity patterns By adding Arkose Device ID to the Arkose Labs’ platform, enterprises can assign unique device identifiers to all incoming traffic, gaining visibility into user behaviors tied to those devices from the first interaction—without requiring additional vendors or datasets. Aon Cyber Risk Analyzer empowers organizations to … More →
The post New infosec products of the week: November 22, 2024 appeared first on Help Net Security.