CVE-2025-32756:在多個 Fortinet 產品中遭到猖獗刺探利用的零時差弱點
Fortinet has observed threat actors exploiting CVE-2025-32756, a critical zero-day arbitrary code execution vulnerability which affects multiple Fortinet products including FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera....
CVE-2024-55591:受到猖獗利用的 Fortinet 驗證繞過零時差弱點
Fortinet patched a zero day authentication bypass vulnerability in FortiOS and FortiProxy that has been actively exploited in the wild as a zero-day since November 2024....
2024 年 Microsoft Patch Tuesday 年度評論
Microsoft addressed over 1000 CVEs as part of Patch Tuesday releases in 2024, including 22 zero-day vulnerabilities....
Volt Typhoon:美國民族國家贊助的威脅執行者鎖定的重大基礎設施
Volt Typhoon, a state-sponsored actor linked to the People’s Republic of China, has consistently targeted U.S. critical infrastructure with the intent to maintain persistent access. Tenable Research examines the tactics, techniques and procedures of this threat actor....
CVE-2024-47575:有關 FortiManager 和 FortiManager Cloud 中 FortiJump 零時差攻擊的常見問答集
Frequently asked questions about a zero-day vulnerability in Fortinet’s FortiManager that has reportedly been exploited in the wild....
Microsoft’s June 2024 Patch Tuesday Addresses 49 CVEs
Microsoft addresses 49 CVEs in its June 2024 Patch Tuesday release with one rated as critical and no zero-day or publicly disclosed vulnerabilities. Our counts omitted two CVEs that were not issued by Microsoft, which include CVE-2023-50868 (issued by MITRE) and CVE-2024-29187 (issued by GitHub)....
CVE-2024-4358、CVE-2024-1800: 針對 Telerik Report Server 進行中的重大刺探利用鏈已有攻擊程式
Researchers have released an exploit chain to achieve remote code execution on unpatched instances of Progress Telerik Report Server. Immediate patching is recommended....
Microsoft 在 2024 年 4 月份的 Patch Tuesday 中解決了 147 個 CVE (CVE-2024-29988)
Microsoft addresses 147 CVEs in its April 2024 Patch Tuesday release with three critical vulnerabilities and no zero-day or publicly disclosed vulnerabilities....
Microsoft 的 2024 年 2 月份 Patch Tuesday 解決了 73 個 CVE (CVE-2024-21351、 CVE-2024-21412)
Microsoft addresses 73 CVEs, including three zero-day vulnerabilities that were exploited in the wild....
CVE-2024-21762:Fortinet FortiOS 超出邊界寫入 SSL VPN 重大弱點
Fortinet warns of “potentially” exploited flaw in the SSL VPN functionality of FortiOS, as government agencies warn of pre-positioning by Chinese state-sponsored threat actors in U.S. critical infrastructure through exploitation of known vulnerabilities...
CVE-2023-29357、CVE-2023-24955: 針對 Microsoft SharePoint Server 弱點的刺探利用鏈
A proof-of-concept exploit chain has been released for two vulnerabilities in Microsoft SharePoint Server that can be exploited to achieve unauthenticated remote code execution....
Microsoft 的 2023 年 9 月 Patch Tuesday 解決了 61 個 CVE (CVE-2023-36761)
Microsoft addresses 61 CVEs including two vulnerabilities that were exploited in the wild...