Aggregator
BSidesSF 2025: Something’s Phishy: See The Hook Before The Bait
Creator/Author/Presenter: Malachi Walker
Our deep appreciation to Security BSides - San Francisco and the Creators/Authors/Presenters for publishing their BSidesSF 2025 video content on YouTube. Originating from the conference’s events held at the lauded CityView / AMC Metreon - certainly a venue like no other; and via the organization's YouTube channel.
Additionally, the organization is welcoming volunteers for the BSidesSF Volunteer Force, as well as their Program Team & Operations roles. See their succinct BSidesSF 'Work With Us' page, in which, the appropriate information is to be had!
The post BSidesSF 2025: Something’s Phishy: See The Hook Before The Bait appeared first on Security Boulevard.
CVE-2024-33625 | CyberPower PowerPanel up to 4.9.0 JWT Signing Key hard-coded password (icsa-24-123-01)
CVE-2024-34074 | Frappe up to 14.73.0/15.25.0 Login Page redirect
CVE-2021-1484 | Cisco Catalyst SD-WAN Manager up to 20.4.1.1 Web UI argument injection (cisco-sa-vman-cmdinj-nRHKgfHX)
CVE-2021-1464 | Cisco Catalyst SD-WAN Manager up to 20.1.12 Requests improper authentication (cisco-sa-vman-authorization-b-GUEpSLK)
CVE-2021-1481 | Cisco Catalyst SD-WAN Manager up to 20.4.1.1 HTTP data query logic injection (cisco-sa-vmanage-cql-inject-c7z9QqyB)
CVE-2021-1482 | Cisco Catalyst SD-WAN Manager up to 20.4.1.1 Web-based Management Interface improper authorization (cisco-sa-vman-auth-bypass-Z3Zze5XC)
CVE-2021-1483 | Cisco Catalyst SD-WAN Manager up to 20.4.1.1 Web UI xml external entity reference (cisco-sa-vman-xml-ext-entity-q6Z7uVUg)
CVE-2021-1466 | Cisco Catalyst SD-WAN Manager up to 20.1.1.1 vDaemon Service denial of service (cisco-sa-sdwan-vdaemon-bo-RuzzEA2)
CVE-2024-28866 | GoCD up to 24.0.x redirect_to cross site scripting
CVE-2024-20394 | Cisco AppDynamics Network Visibility Service denial of service (cisco-sa-appd-netvisdos-9zNbsJtK)
CVE-2024-4067 | micromatch up to 4.05 index.js micromatch.braces redos (ID 243 / Nessus ID 209968)
CVE-2024-4068 | micromatch braces up to 3.0.2 lib/parse.js excessive platform resource consumption within a loop (Nessus ID 209012)
孙宇晨搭乘 Blue Origin 飞船完成亚轨道飞行
苦中作乐,路在脚下
似是而非的年终总结
Cyera launches AI Guardian to secure all types of AI systems
Cyera launched AI Guardian, a solution built to secure any type of AI. It expands Cyera’s platform to meet the needs of enterprises adopting AI at scale, anchored by two core products: AI-SPM, providing inventory on all AI assets at a granular level, and AI Runtime Protection, monitoring and responding to AI data risks in real-time. The launch comes as enterprises scale AI initiatives while facing new security and operational risks. According to Forrester, enterprises … More →
The post Cyera launches AI Guardian to secure all types of AI systems appeared first on Help Net Security.
New Plague Linux malware stealthily maintains SSH access
LastPass unveils SaaS Protect to clamp down on shadow IT, AI risks
Building on the company’s existing SaaS Monitoring capabilities, LastPass SaaS Protect introduces a set of policy enforcements that enable organizations to move from passive visibility into proactive access control. Business benefits include: Real-time SaaS governance: Quickly restrict access to unsanctioned or high-risk SaaS apps and guide user behavior with custom warnings. Audit-ready compliance: Generate governance reports with SOC 2 and other compliance frameworks in mind. SaaS cost optimization: Identify duplicate or over-licensed apps to help … More →
The post LastPass unveils SaaS Protect to clamp down on shadow IT, AI risks appeared first on Help Net Security.