Aggregator
.NET内网实战: 通过LNK 文件实现目标权限持久化
9 months ago
投50亿美元,英伟达联手英特尔;谷歌将Gemini加入浏览器;网约车司机平均月入过万 | 极客早知道
9 months ago
消息称马云已「强势回归」,阿里巴巴暂无回应;OpenAI 最新研究揭示「AI 阴谋论」;单日票房破 3 亿,电影《731》刷新两项中国影史纪录
科技爱好者周刊(第 366 期):旧金山疯狂的 AI 广告
9 months ago
文章记录了每周科技动态与观点分享,重点介绍了旧金山铺天盖地的 AI 广告现象及其背后资本推动的原因,并涵盖开源软件更新、风力发电机运输飞机设计等科技新闻,同时推荐了多个工具与 AI 应用,并分享了关于技术选择与职业发展的观点。
Active Directory Security Tip #6: Domain Controller Operating System Versions
9 months ago
文章提供了一个Active Directory PowerShell脚本,用于查询当前域中所有域控制器的操作系统版本及其所在站点位置。
第五届长城杯-京津冀 writeup by Mini-Venom
9 months ago
第五届长城杯-京津冀 writeup by Mini-Venom
9 months ago
当前环境异常,请进行验证以恢复访问权限。
How AI-Native Development Platforms Enable Fake Captcha Pages
9 months ago
Cybercriminals are abusing AI-native platforms like Vercel, Netlify, and Lovable to host fake captcha pages that deceive users, bypass detection, and drive phishing campaigns.
Ryan Flores
CVE-2023-52652 | Linux Kernel up to 5.15.152/6.1.82/6.6.22/6.7.10/6.8.1 ntb_register_device memory leak (WID-SEC-2024-1008)
9 months ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.15.152/6.1.82/6.6.22/6.7.10/6.8.1. Affected by this issue is the function ntb_register_device. Such manipulation leads to memory leak.
This vulnerability is referenced as CVE-2023-52652. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2024-27027 | Linux Kernel up to 6.7.10/6.8.1 dpll drivers/dpll/dpll_core.c dpll_xa_ref_*_del privilege escalation (769324eb3514/b27e32e9367d/b446631f355e / WID-SEC-2024-1008)
9 months ago
A vulnerability was found in Linux Kernel up to 6.7.10/6.8.1 and classified as problematic. Affected by this issue is the function dpll_xa_ref_*_del of the file drivers/dpll/dpll_core.c of the component dpll. Executing manipulation can lead to privilege escalation.
The identification of this vulnerability is CVE-2024-27027. The attack needs to be done within the local network. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-27056 | Linux Kernel up to 6.7.10 wifi allocation of resources (ed35a509390e/78f65fbf421a / Nessus ID 227909)
9 months ago
A vulnerability was found in Linux Kernel up to 6.7.10 and classified as problematic. The impacted element is an unknown function of the component wifi. Such manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-27056. The attack can only be initiated within the local network. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-27023 | Linux Kernel up to 6.1.79/6.6.18/6.7.6 md mddev_suspend allocation of resources (Nessus ID 210815 / WID-SEC-2024-1008)
9 months ago
A vulnerability was found in Linux Kernel up to 6.1.79/6.6.18/6.7.6. It has been declared as critical. Affected by this vulnerability is the function mddev_suspend of the component md. Executing manipulation can lead to allocation of resources.
This vulnerability is tracked as CVE-2024-27023. The attack is only possible within the local network. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-50296 | Linux Kernel up to 6.0.2 UM cpu_max_bits_warn stack-based overflow (Nessus ID 265243 / WID-SEC-2025-2053)
9 months ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.0.2. The affected element is the function cpu_max_bits_warn of the component UM. The manipulation results in stack-based buffer overflow.
This vulnerability is known as CVE-2022-50296. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2024-1139 | Red Hat Advanced Cluster Management for Kubernetes information disclosure (RHSA-2024:1887 / EUVD-2024-1331)
9 months ago
A vulnerability classified as problematic has been found in Red Hat Advanced Cluster Management for Kubernetes, OpenShift Container Platform and OpenShift Container Platform. This vulnerability affects unknown code. Performing manipulation results in information disclosure.
This vulnerability was named CVE-2024-1139. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-1647 | Bootstrap up to 3.4.1 cross site scripting (EUVD-2025-15170 / Nessus ID 237630)
9 months ago
A vulnerability classified as problematic has been found in Bootstrap. This affects an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-1647. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-1656 | Autodesk Revit 9.0.7/2023.1.4/2024/2024.2.1/2025 PDF File heap-based overflow (EUVD-2025-11000 / Nessus ID 234621)
9 months ago
A vulnerability was found in Autodesk Revit 9.0.7/2023.1.4/2024/2024.2.1/2025. It has been rated as critical. The impacted element is an unknown function of the component PDF File Handler. This manipulation causes heap-based buffer overflow.
This vulnerability is tracked as CVE-2025-1656. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-50255 | Smartvista BackOffice SmartVista Suite 2.2.22 GET Request cross-site request forgery (EUVD-2025-29877)
9 months ago
A vulnerability classified as problematic has been found in Smartvista BackOffice SmartVista Suite 2.2.22. Affected is an unknown function of the component GET Request Handler. Performing manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2025-50255. The attack must be initiated from a local position. There is no exploit available.
vuldb.com
CVE-2024-45336 | Google Go up to 1.22.10/1.23.4 net-http cross-domain policy (EUVD-2024-41740 / Nessus ID 214540)
9 months ago
A vulnerability was found in Google Go up to 1.22.10/1.23.4 and classified as problematic. This affects an unknown function of the component net-http. Such manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is referenced as CVE-2024-45336. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
ShadowLeak: Radware Uncovers Zero-Click Attack on ChatGPT
9 months ago
Radware discovered a server-side data theft attack, dubbed ShadowLeak, targeting ChatGPT. OpenAI patched the zero-click vulnerability. Researchers at Radware uncovered a server-side data theft attack targeting ChatGPT, called ShadowLeak. The experts discovered a zero-click vulnerability in ChatGPT’s Deep Research agent when connected to Gmail and browsing. The researchers explained that using a crafted email could trigger the agent to […]
Pierluigi Paganini
ChatGPT Search is now smarter as OpenAI takes on Google Search
9 months ago
OpenAI has rolled out a big update to ChatGPT Search, which is an AI-powered search feature, similar to Google AI Mode. [...]
Mayank Parmar