Aggregator
不许动,你被劫持了!
3 days 9 hours ago
Yak MITM劫持流程详解!
Five Charged in Scattered Spider Case
3 days 9 hours ago
Five men have been indicted in connection with crimes committed by the Scattered Spider group
Красная кнопка доверия: Bug Bounty получает экстренный тормоз
3 days 9 hours ago
Инструмент для контроля багхантеров повышает безопасность бизнеса.
Safepay
3 days 9 hours ago
cohenido
Safepay
3 days 9 hours ago
cohenido
Safepay
3 days 9 hours ago
cohenido
Safepay
3 days 9 hours ago
cohenido
Safepay
3 days 10 hours ago
cohenido
香港網安奪旗賽HKCERT CTF 2024 Write up(上)
3 days 10 hours ago
HKCERT CTF 2024 Web/Misc/Forensics Write up
Safepay
3 days 10 hours ago
cohenido
Safepay
3 days 10 hours ago
cohenido
CVE-2024-11456 | mdedev Run Contests, Raffles, and Giveaways with ContestsWP Plugin add_query_arg cross site scripting
3 days 10 hours ago
A vulnerability was found in mdedev Run Contests, Raffles, and Giveaways with ContestsWP Plugin up to 2.0.3 on WordPress. It has been rated as problematic. Affected by this issue is the function add_query_arg. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-11456. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-11371 | slimndap Theater Plugin up to 0.18.6.2 on WordPress add_query_arg cross site scripting
3 days 10 hours ago
A vulnerability was found in slimndap Theater Plugin up to 0.18.6.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function add_query_arg. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-11371. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10675 | cservit affiliate-toolkit Plugin up to 3.6.7 on WordPress cross site scripting
3 days 10 hours ago
A vulnerability was found in cservit affiliate-toolkit Plugin up to 3.6.7 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-10675. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10400 | themeum Tutor LMS Plugin up to 2.7.6 on WordPress rating_filter sql injection
3 days 10 hours ago
A vulnerability was found in themeum Tutor LMS Plugin up to 2.7.6 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation of the argument rating_filter leads to sql injection.
The identification of this vulnerability is CVE-2024-10400. The attack may be initiated remotely. There is no exploit available.
vuldb.com
5 Scattered Spider Gang Members Indicted in Multi-Million Dollar Cybercrime Scheme
3 days 10 hours ago
Five alleged members of the infamous Scattered Spider cybercrime crew have been indicted in the U.S. for targeting employees of companies across the country using social engineering techniques to harvest credentials and using them to gain unauthorized access to sensitive data and break into crypto accounts to steal digital assets worth millions of dollars.
All of the accused parties have been
The Hacker News
Vanta announces new products to enhance GRC and trust programs
3 days 10 hours ago
Vanta announced a number of new and upcoming products enabling customers to build, demonstrate and enhance their GRC and trust programs. The new offerings include Vanta for Marketplaces to strengthen trust across a company’s entire ecosystem; adaptive scoping; AI-powered chat for Trust Centers; developer-first workflows for faster remediation; and expanded reporting capabilities. The announcements coincide with a number of highlights for the company in 2024: Now continuously monitoring over 92 million resources across customers—from laptops … More →
The post Vanta announces new products to enhance GRC and trust programs appeared first on Help Net Security.
Industry News
35 000 ботов ежедневно: как ngioweb стал главным киберпреступным конвейером
3 days 10 hours ago
Всё больше незащищённых устройств открывают новые двери для атакующих.
成果分享 | Neural Dehydration:水印类型无关的通用黑盒模型水印移除攻击
3 days 10 hours ago
分享我实验室白泽智能团队被CCS2024 录用的最新研究 Neural Dehydration,该工作提出了一种与水印类型无关的通用移除攻击,成功破解了当下10款主流的黑盒模型水印,在保持目标模型可用性的同时,对数据的依赖性也极低。