Aggregator
1 个月,2 场胜仗,李斌从「斌子」变成「斌神」
马斯克沉迷的「刷刷刷」游戏,要来中国了
CVE-2024-43441 Apache HugeGraph 硬编码漏洞 复现
14 Million-Download SHA JavaScript Library Exposes Users to Hash Manipulation Attacks
A critical security vulnerability has been discovered in the widely-used sha.js npm package, exposing millions of applications to sophisticated hash manipulation attacks that could compromise cryptographic operations and enable unauthorized access to sensitive systems. The vulnerability, designated CVE-2025-9288, affects all versions up to 2.4.11 of the library, which has accumulated over 14 million downloads across […]
The post 14 Million-Download SHA JavaScript Library Exposes Users to Hash Manipulation Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Quickly Format Python Code for Better Readability
Учёные превратили обычный белок в квантовый бит — прямо внутри живой клетки
The new battleground for CISOs is human behavior
Attackers don’t always need a technical flaw. More often, they just trick your people. Social engineering works, and AI makes it harder to catch.” Only about one in four cybersecurity teams are effective at collaborating with the broader business (Source: LevelBlue) A new LevelBlue report shows how this problem is growing worldwide. Forty-one percent of organizations say they are experiencing more cyberattacks than a year ago, rising to 49% in Asia-Pacific. Employees are struggling to … More →
The post The new battleground for CISOs is human behavior appeared first on Help Net Security.
CVE-2025-9331 | Spacious Plugin up to 1.9.11 on WordPress Demo Data Import welcome_notice_import_handler authorization
Exploring Passwordless Authentication
CVE-2025-43753 | Liferay Portal/DXP cross site scripting (WID-SEC-2025-1894)
CVE-2025-41452 | Danfoss AK-SM8xxA up to 4.3.0 Web Interface Configuration Setting external control of system or configuration setting (EUVD-2025-25498)
New HTTP Smuggling Technique Allows Hackers to Inject Malicious Requests
Cybersecurity researchers have uncovered a sophisticated HTTP request smuggling attack that exploits inconsistent parsing behaviors between front-end proxy servers and back-end application servers. This newly discovered technique leverages malformed chunk extensions to bypass security controls and inject unauthorized requests into web applications, representing a significant evolution in HTTP smuggling methodologies. The attack technique was identified […]
The post New HTTP Smuggling Technique Allows Hackers to Inject Malicious Requests appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-43752 | Liferay Portal/DXP document_library allocation of resources (WID-SEC-2025-1894)
CVE-2025-41451 | Danfoss AK-SM8xxA up to 4.3.0 Configuration os command injection (EUVD-2025-25499)
I think the new dmt cart hardware color fits very well.
Обучение кибербезопасности не работает: время тратится, а фишинг всё равно побеждает
Local governments struggle to defend critical infrastructure as threats grow
A small-town water system, a county hospital, and a local school district may not seem like front-line targets in global conflict, but they are. These organizations face daily cyber attacks, from ransomware to foreign adversaries probing for weak points. What happens to them can ripple into national security, disrupting everything from healthcare to transportation. That is the warning in a new report from the Multi-State Information Sharing and Analysis Center (MS-ISAC), which reviews the current … More →
The post Local governments struggle to defend critical infrastructure as threats grow appeared first on Help Net Security.
ChatGPT-5 Downgrade Attack Allows Hackers to Evade AI Defenses With Minimal Prompts
Security researchers from Adversa AI have uncovered a critical vulnerability in ChatGPT-5 and other major AI systems that allows attackers to bypass safety measures using simple prompt modifications. The newly discovered attack, dubbed PROMISQROUTE, exploits AI routing mechanisms that major providers use to save billions of dollars annually by directing user queries to cheaper, less […]
The post ChatGPT-5 Downgrade Attack Allows Hackers to Evade AI Defenses With Minimal Prompts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
DevOps in the cloud and what is putting your data at risk
In this Help Net Security video, Greg Bak, Head of Product Enablement at GitProtect, walks through some of the biggest security risks DevOps teams are dealing with. He covers how AI tools can introduce vulnerabilities, including cases where they ignore safeguards and cause data loss, and explains how ransomware is now targeting Git repositories through exposed credentials. Greg also talks about major outages and vulnerabilities in popular SaaS platforms like Jira, GitHub, GitLab, and Bitbucket, … More →
The post DevOps in the cloud and what is putting your data at risk appeared first on Help Net Security.