共 127 个订阅源,第 5 / 7 页
ClearSky Team has identified a targeted Russian cyber campaign against Ukraine utilizing twonovel malware strains, BadPaw and MeowMeow. The attack chain initiates with a phishing email containing a link to a ZIP archive. Onceextracted, an i…
In early April, ClearSky’s team discovered a persistent Yemeni/Houthi influence campaignoperating in Israel and the Gulf states. We first exposed the campaign in 2019. It continuesto operate in a similar manner to what was uncovered in 2019…
A new zero-day vulnerability, CVE-2024-43451, was discovered by ClearSky Cyber Security in June 2024. This vulnerability affects Windows systems and is being actively exploited in attacks against Ukrainian entities. The vulnerability activa…
报告编号: 360-TIC-202608-FIN01 一、报告概述 范围说明 基于360威胁情报中心对全球…
报告编号: TIC-202609-AI01 报告周期: 2026年8月29日—9月4日 一、报告概述 基于360威胁…
报告编号: TIC-202608-AI03 报告周期: 2026年8月22日—8月28日 一、报告概述 基于360威胁…
On average, the FreeBSD security team releases about 2 security advisories per month. AI has changed this. In April, the project released 8 advisories, with 6 powered by AI . In May, the count decreased slightly to 7. Today I took a look at…
TLDR: I wrote a new book for Corelight called NDR Essentials . It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at taosecurity.com . Why? It was time . That’s what I thought when I hea…
It looks like we're finally making progress towards an independent US Cyber Force: https://www.csis.org/programs/strategic-technologies-program/projects/commission-us-cyber-force-generation However, this bill by Sen Gillibrand to put it und…
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I've started playing around with YouTube's "create video thumbnail", which hopefully will give …
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D prin…
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite You're not going to believe this, but turns out you can't always take criminals at their word. …
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
<h3 id="overview">Overview</h3> <p>The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections…
<h3 id="overview">Overview</h3> <p>Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairin…
<h3 id="overview">Overview</h3> <p>A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user…
Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2) FROM: d…
Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8) FROM: disclosure () 0day-rub…
Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8) FROM: disclosure () 0day-rubbi…
Ransomware attacks can ripple through supply chains, causing serious disruption and massive financial consequences for multiple businesses in one fell swoop. As such, CISOs are spending more time considering how to keep operations secure as…
Security and compliance—a phrase often uttered in the same breath as if they are two sides of the same coin, two members of the same team, or two great tastes that go great together. The truth is, they can be. But it takes some effort. How …
PCI DSS compliance is often seen as a one-off task, that is, you do the audit, implement controls, and then move on. But then there comes the problem - systems aren’t static, meaning that files, scripts, and configurations change constantly…
DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes. Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked t…
Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days. Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, maki…
Australia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same. Remember when social media was filled only with posts from your friends, rather than what an alg…
Google has recently announced that Gmail for the web is getting client-side encryption for more customers. Already available for some Workspace subscribers, the client-side encryption in Gmail on the web is being expanded to Workspace Enter…
You’d think the time spent working from home in the last two years or so helped netizens across the planet figure out how to master the world of WWW in a more efficient manner. But new research from NordPass shows that despite so many peopl…
PayPal has officially announced the support of passkeys, as the company wants to increase the security of user accounts and therefore provide customers with a more secure method of logging in. Stepping away from passwords is something that …