CVE-2024-0012,CVE-2024-9474:Palo Alto PAN-OS 中的零日漏洞在现实环境中遭利用
Palo Alto Networks confirmed two zero-day vulnerabilities were exploited as part of attacks in the wild against PAN-OS devices, with one being attributed to Operation Lunar Peek.
Microsoft 的 2024 年 11 月补丁星期二解决了 87 个 CVE (CVE-2024-43451,CVE-2024-49039)
Microsoft addresses 87 CVEs and one advisory (ADV240001) in its November 2024 Patch Tuesday release, with four critical vulnerabilities and four zero-day vulnerabilities, including two that were exploited in the wild.
CVE-2024-47575:有关 FortiManager 和 FortiManager Cloud 中 FortiJump 零日漏洞的常见问题
Frequently asked questions about a zero-day vulnerability in Fortinet’s FortiManager that has reportedly been exploited in the wild.
从缺陷到数据外泄: MITRE CVE 25 周年的 25 个重大 CVE
Twenty five years after the launch of CVE, the Tenable Security Response Team has handpicked 25 vulnerabilities that stand out for their significance.
Oracle 2024 年 10 月关键补丁更新解决了 198 个 CVE
Oracle addresses 198 CVEs in its fourth quarterly update of 2024 with 334 patches, including 35 critical updates.
Microsoft 的 2024 年 10 月补丁星期二解决了 117 个 CVE(CVE-2024-43572,CVE-2024-43573)
Microsoft addresses 117 CVEs with three rated as critical and four zero-day vulnerabilities, two of which were exploited in the wild.
CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177: Frequently Asked Questions About Common UNIX Printing System (CUPS) Vulnerabilities
Frequently asked questions about multiple vulnerabilities in the Common UNIX Printing System (CUPS) that were disclosed as zero-days on September 26.
Microsoft 2024 年 9 月补丁星期二修复了 79 个 CVE (CVE-2024-43491)
Microsoft addresses 79 CVEs with seven critical vulnerabilities and four zero-day vulnerabilities, including three that were exploited in the wild.
CVE-2021-20123、CVE-2021-20124:Tenable Research 发现的 DrayTek 漏洞已增加到 CISA KEV
With patches out for three years, attackers have set their sights on a pair of vulnerabilities affecting DrayTek VigorConnect.
AA24-241A:关于针对美国企业的伊朗网络攻击者的联合网络安全咨询
A joint Cybersecurity Advisory highlights Iran-based cyber actor ransomware activity targeting U.S. organizations. The advisory includes CVEs exploited, alongside techniques, tactics and procedures used by the threat actors.
CVE-2024-7593:Ivanti Virtual Traffic Manager 身份验证绕过漏洞
Ivanti released a patch for a critical severity authentication bypass vulnerability and a warning that exploit code is publicly available
Microsoft 2024 年 8 月补丁星期二解决了 88 个 CVE
Microsoft addresses 88 CVEs with seven critical vulnerabilities and 10 zero-day vulnerabilities, six of which were exploited in the wild.