Aggregator
敬畏与驾驭:系统复杂性视角下的软件智能化研发体系演进
Как одна цифра в ссылке разрушает бизнес: разбираем уязвимость IDOR
Fixing vulnerability data quality requires fixing the architecture first
In this Help Net Security interview, Art Manion, Deputy Director at Tharros, examines why vulnerability data across repositories stays inconsistent and hard to trust. The problem starts with systems not designed to collect or manage that data well. They introduce the idea of Minimum Viable Vulnerability Enumeration (MVVE), a minimum set of assertions needed to confirm two systems describe the same vulnerability, and find no true minimum exists. Assertions vary by case and change over … More →
The post Fixing vulnerability data quality requires fixing the architecture first appeared first on Help Net Security.
Claude Code Windows环境避坑指南
CVE-2024-2256 | oik Plugin up to 4.10.0 on WordPress Shortcode cross site scripting
CVE-2024-1795 | Husky Plugin up to 1.3.5.2 on WordPress sql injection
CVE-2024-1796 | Husky Plugin up to 1.3.5.1 on WordPress Shortcode cross site scripting
CVE-2024-2399 | Premium Addons for Elementor Pro Plugin up to 4.10.23 on WordPress cross site scripting (ID 3051259)
CVE-2024-2294 | Backuply Plugin up to 1.2.7 on WordPress path traversal
CVE-2024-2308 | Elementvader Addons for Elementor Plugin up to 1.2.2 on WordPress cross site scripting
CVE-2024-1685 | Social Media Share Buttons Plugin up to 2.1.0 on WordPress code injection
CVE-2024-1857 | wpswings Ultimate Gift Cards for WooCommerce Plugin up to 2.6.6 on WordPress wps_wgm_preview_email_template authorization
CVE-2024-1787 | Contests by Rewards Fuel Plugin up to 2.0.64 on WordPress update_rewards_fuel_api_key cross site scripting
CVE-2024-1785 | Contests by Rewards Fuel Plugin up to 2.0.62 on WordPress cross-site request forgery
CVE-2024-1995 | Smart Custom Fields Plugin up to 4.2.2 on WordPress Post authorization
CVE-2024-2387 | nasirahmed Advanced Form Integration Plugin up to 1.82.0 on WordPress integration_id sql injection
Linux 7.0 释出
500 млн устройств, ни одного ордера. Полиция и спецслужбы следят за людьми через рекламу — и это законно
ZeroID: Open-source identity platform for autonomous AI agents
ZeroID is an open-source identity platform that implements an identity and credentialing layer specifically for autonomous agents and multi-agent systems. The attribution problem The core issue ZeroID targets is attribution in agentic workflows. When an orchestrator agent spawns sub-agents to carry out parts of a task, each sub-agent may call APIs, write files, or execute shell commands. Existing approaches offer limited traceability: shared service accounts carry no delegation trail, and standard OAuth 2.0 and OIDC … More →
The post ZeroID: Open-source identity platform for autonomous AI agents appeared first on Help Net Security.