惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Schneier on Security
Schneier on Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Tenable Blog
P
Proofpoint News Feed
V
Vulnerabilities – Threatpost
Project Zero
Project Zero
Latest news
Latest news
S
Schneier on Security
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Threatpost
Simon Willison's Weblog
Simon Willison's Weblog
Cyberwarzone
Cyberwarzone
T
The Exploit Database - CXSecurity.com
C
CERT Recently Published Vulnerability Notes
Spread Privacy
Spread Privacy
Cisco Talos Blog
Cisco Talos Blog
T
Troy Hunt's Blog
S
Secure Thoughts
C
Cisco Blogs
Application and Cybersecurity Blog
Application and Cybersecurity Blog
V2EX - 技术
V2EX - 技术
Hacker News: Ask HN
Hacker News: Ask HN
O
OpenAI News
L
LINUX DO - 最新话题
T
Threat Research - Cisco Blogs
Recent Commits to openclaw:main
Recent Commits to openclaw:main
P
Palo Alto Networks Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
博客园_首页
月光博客
月光博客
博客园 - 【当耐特】
雷峰网
雷峰网
C
CXSECURITY Database RSS Feed - CXSecurity.com
博客园 - 叶小钗
aimingoo的专栏
aimingoo的专栏
L
Lohrmann on Cybersecurity
D
DataBreaches.Net
美团技术团队
B
Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
有赞技术团队
有赞技术团队
D
Docker
Jina AI
Jina AI
The GitHub Blog
The GitHub Blog
H
Hacker News: Front Page
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
AI
AI
Martin Fowler
Martin Fowler
Attack and Defense Labs
Attack and Defense Labs
小众软件
小众软件

SANS Internet Storm Center, InfoCON: green

From a VHDX File to a Remcos RAT - SANS Internet Storm Center ISC Stormcast For Tuesday, June 16th, 2026 https://isc.sans.edu/podcastdetail/9974 Evil MSI Background: BASE64 Statistical Analysis - SANS ISC ISC Stormcast For Monday, June 15th, 2026 https://isc.sans.edu/podcastdetail/9972 ISC Stormcast For Friday, June 12th, 2026 https://isc.sans.edu/podcastdetail/9970 ISC Stormcast For Thursday, June 11th, 2026 https://isc.sans.edu/podcastdetail/9968 How has use of framing protection security headers changed in the past 3 years? ISC Stormcast For Wednesday, June 10th, 2026 https://isc.sans.edu/podcastdetail/9966 Microsoft June 2026 Patch Tuesday - SANS Internet Storm Center ISC Stormcast For Tuesday, June 9th, 2026 https://isc.sans.edu/podcastdetail/9964 TeamPCP Supply Chain Campaign: Activity Through 2026-06-07 ISC Stormcast For Monday, June 8th, 2026 https://isc.sans.edu/podcastdetail/9962 The Evil MSI Background is Back! - SANS Internet Storm Center ISC Stormcast For Friday, June 5th, 2026 https://isc.sans.edu/podcastdetail/9960 Microsoft's Coreutils for Windows - SANS Internet Storm Center ISC Stormcast For Thursday, June 4th, 2026 https://isc.sans.edu/podcastdetail/9958 Continuing Scans for swagger.json - SANS Internet Storm Center ISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956 New Wave Of Phishing Emails with SVG Files - SANS ISC ISC Stormcast For Tuesday, June 2nd, 2026 https://isc.sans.edu/podcastdetail/9954 ISC Stormcast For Monday, June 1st, 2026 https://isc.sans.edu/podcastdetail/9952 Unidentified RAT pushes NetSupport RAT - SANS ISC YARA-X 1.17.0 Release - SANS Internet Storm Center ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950 Analysis of a Year of Files Uploaded to DShield Sensors ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948 Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946 ISC Stormcast For Tuesday, May 26th, 2026 https://isc.sans.edu/podcastdetail/9944 Possible ACR Stealer From Page Impersonating Claude Microsoft Access VBA - SANS Internet Storm Center Wireshark 4.6.6 Released - SANS Internet Storm Center An Example of Stack String in High Level Language - SANS ISC Cross-Platform NPM Stealer - SANS Internet Storm Center ISC Stormcast For Friday, May 22nd, 2026 https://isc.sans.edu/podcastdetail/9942 Selective HTTP Proxying in Linux - SANS Internet Storm Center ISC Stormcast For Thursday, May 21st, 2026 https://isc.sans.edu/podcastdetail/9940 ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938 ISC Stormcast For Tuesday, May 19th, 2026 https://isc.sans.edu/podcastdetail/9936 TeamPCP Supply Chain Campaign: Activity Through 2026-05-17 [Guest Diary] New Malware Libraries means New Signatures ISC Stormcast For Friday, May 15th, 2026 https://isc.sans.edu/podcastdetail/9934 Simple bypass of the link preview function in Outlook Junk folder ISC Stormcast For Thursday, May 14th, 2026 https://isc.sans.edu/podcastdetail/9932 [GUEST DIARY] Tearing apart website fraud to see how it works. ISC Stormcast For Wednesday, May 13th, 2026 https://isc.sans.edu/podcastdetail/9930 Proxying the Unproxyable? Sending EXE traffic to a Proxy Microsoft May 2026 Patch Tuesday - SANS Internet Storm Center ISC Stormcast For Tuesday, May 12th, 2026 https://isc.sans.edu/podcastdetail/9928 Why we use CAPTCHAs - SANS Internet Storm Center ISC Stormcast For Monday, May 11th, 2026 https://isc.sans.edu/podcastdetail/9926 YARA-X 1.16.0 Release - SANS Internet Storm Center Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag ISC Stormcast For Friday, May 8th, 2026 https://isc.sans.edu/podcastdetail/9924 ISC Stormcast For Wednesday, May 6th, 2026 https://isc.sans.edu/podcastdetail/9920 Cleartext Passwords in MS Edge? In 2026? - SANS ISC SSL.com rotates their root certificate today - SANS ISC ISC Stormcast For Tuesday, May 5th, 2026 https://isc.sans.edu/podcastdetail/9918 TeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03) DShield Honeypot Update - SANS Internet Storm Center ISC Stormcast For Monday, May 4th, 2026 https://isc.sans.edu/podcastdetail/9916 Wireshark 4.6.5 Released - SANS Internet Storm Center Malicious Ad for Homebrew Leads to MacSync Stealer ISC Stormcast For Friday, May 1st, 2026 https://isc.sans.edu/podcastdetail/9914 ISC Stormcast For Thursday, April 30th, 2026 https://isc.sans.edu/podcastdetail/9912 Danger of Libredtail [Guest Diary] - SANS Internet Storm Center Today's Odd Web Requests - SANS Internet Storm Center ISC Stormcast For Wednesday, April 29th, 2026 https://isc.sans.edu/podcastdetail/9910 HTTP Requests with X-Vercel-Set-Bypass-Cookie Header ISC Stormcast For Tuesday, April 28th, 2026 https://isc.sans.edu/podcastdetail/9908 TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns ISC Stormcast For Friday, April 24th, 2026 https://isc.sans.edu/podcastdetail/9906 Apple Patches Exploited Notification Flaw - SANS ISC ISC Stormcast For Thursday, April 23rd, 2026 https://isc.sans.edu/podcastdetail/9904 ISC Stormcast For Wednesday, April 22nd, 2026 https://isc.sans.edu/podcastdetail/9902 [Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd) A .WAV With A Payload - SANS Internet Storm Center ISC Stormcast For Tuesday, April 21st, 2026 https://isc.sans.edu/podcastdetail/9900 Handling the CVE Flood With EPSS - SANS Internet Storm Center ISC Stormcast For Monday, April 20th, 2026 https://isc.sans.edu/podcastdetail/9898 ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896 Lumma Stealer infection with Sectop RAT (ArechClient2) ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894 [Guest Diary] Compromised DVRs and Finding Them in the Wild ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892 Scanning for AI Models - SANS Internet Storm Center Microsoft Patch Tuesday April 2026. - SANS ISC ISC Stormcast For Tuesday, April 14th, 2026 https://isc.sans.edu/podcastdetail/9890 Scans for EncystPHP Webshell - SANS Internet Storm Center ISC Stormcast For Monday, April 13th, 2026 https://isc.sans.edu/podcastdetail/9888 Obfuscated JavaScript or Nothing - SANS Internet Storm Center ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886 Number Usage in Passwords: Take Two - SANS ISC TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory More Honeypot Fingerprinting Scans - SANS Internet Storm Center ISC Stormcast For Wednesday, April 8th, 2026 https://isc.sans.edu/podcastdetail/9884 A Little Bit Pivoting: What Web Shells are Attackers Looking for? ISC Stormcast For Tuesday, April 7th, 2026 https://isc.sans.edu/podcastdetail/9882 How often are redirects used in phishing in 2026? - SANS ISC ISC Stormcast For Monday, April 6th, 2026 https://isc.sans.edu/podcastdetail/9880
Apple Patches Everything - SANS Internet Storm Center
2026-05-12 · via SANS Internet Storm Center, InfoCON: green
CVE-2025-43524: An app may be able to break out of its sandbox.
Affects Icons       x x       CVE-2026-28819: An app may be able to execute arbitrary code with kernel privileges.
Affects Wi-Fi   x x x x       CVE-2026-28840: An app may be able to gain root privileges.
Affects PackageKit       x x       CVE-2026-28846: A remote attacker may be able to cause unexpected app termination.
Affects SceneKit x x x x x x x x CVE-2026-28848: A remote attacker may be able to cause unexpected system termination.
Affects SMB     x x         CVE-2026-28870: An app may be able to access sensitive user data.
Affects GeoServices   x             CVE-2026-28872: A remote attacker may be able to cause a denial-of-service.
Affects Calendar   x             CVE-2026-28873: An app may be able to circumvent App Privacy Report logging.
Affects Privacy   x             CVE-2026-28877: An app may be able to access sensitive user data.
Affects Accounts   x             CVE-2026-28878: An app may be able to enumerate a user's installed apps.
Affects Crash Reporter       x         CVE-2026-28882: An app may be able to enumerate a user's installed apps.
Affects libxpc   x             CVE-2026-28883: Processing maliciously crafted web content may lead to an unexpected process crash.
Affects WebKit x   x     x x x CVE-2026-28894: A remote attacker may be able to cause a denial-of-service.
Affects Calling Framework   x             CVE-2026-28897: A local user may be able to cause unexpected system termination or read kernel memory.
Affects Kernel x x x x x x x x CVE-2026-28901: Processing maliciously crafted web content may lead to an unexpected process crash.
Affects WebKit               x CVE-2026-28906: An attacker may be able to track users through their IP address.
Affects Networking x x x x x     x CVE-2026-28907: Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Affects WebKit x x x     x x x CVE-2026-28908: An app may be able to modify protected parts of the file system.
Affects Kernel     x x x       CVE-2026-28913: Processing maliciously crafted web content may lead to an unexpected process crash.
Affects WebKit x   x     x x   CVE-2026-28914: A maliciously crafted ZIP archive may bypass Gatekeeper checks.
Affects zip     x           CVE-2026-28915: An app may be able to gain root privileges.
Affects CUPS     x x x       CVE-2026-28917: Processing maliciously crafted web content may lead to an unexpected process crash.
Affects WebKit x x x     x x x CVE-2026-28918: Parsing a maliciously crafted file may lead to an unexpected app termination.
Affects CoreSymbolication x   x     x x x CVE-2026-28919: An app may be able to gain root privileges.
Affects StorageKit     x x x       CVE-2026-28920: Visiting a maliciously crafted website may leak sensitive data.
Affects zlib x x x x x x x x CVE-2026-28922: An app may be able to access private information.
Affects CoreMedia     x x x       CVE-2026-28923: A malicious app may be able to break out of its sandbox.
Affects GPU Drivers     x x x       CVE-2026-28924: An app may be able to access Contacts without user consent.
Affects Sync Services     x x x       CVE-2026-28925: An app may be able to cause unexpected system termination or write kernel memory.
Affects HFS     x x x       CVE-2026-28929: Replying to an email could display remote images in Mail in Lockdown Mode.
Affects Mail Drafts   x x x x       CVE-2026-28930: An app may be able to access protected user data.
Affects Spotlight     x           CVE-2026-28936: Processing a maliciously crafted file may lead to unexpected app termination.
Affects CoreServices x x x   x     x CVE-2026-28940: Processing a maliciously crafted image may corrupt process memory.
Affects Model I/O x x x x   x   x CVE-2026-28941: Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
Affects Model I/O   x x x         CVE-2026-28942: Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affects WebKit x   x     x x   CVE-2026-28943: An app may be able to determine kernel memory layout.
Affects IOHIDFamily x x x x x x x   CVE-2026-28944: Processing maliciously crafted web content may lead to an unexpected process crash.
Affects WebRTC x   x         x CVE-2026-28947: Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affects WebKit               x CVE-2026-28951: An app may be able to gain root privileges.
Affects Kernel x x x x x       CVE-2026-28952: An app may be able to cause unexpected system termination.
Affects Kernel   x x x x       CVE-2026-28953: Processing maliciously crafted web content may lead to an unexpected process crash.
Affects WebKit   x             CVE-2026-28954: A maliciously crafted disk image may bypass Gatekeeper checks.
Affects Kernel   x x x x       CVE-2026-28956: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
Affects AppleJPEG x   x x x x x x CVE-2026-28957: An app may be able to capture a user's screen.
Affects Status Bar x x           x CVE-2026-28958: An app may be able to access sensitive user data.
Affects WebKit x   x         x CVE-2026-28959: An app may be able to cause unexpected system termination.
Affects APFS x x x x x x x x CVE-2026-28961: An attacker with physical access to a locked device may be able to view sensitive user information.
Affects Network Extensions     x           CVE-2026-28962: Processing maliciously crafted web content may disclose sensitive user information.
Affects WebKit x x x         x CVE-2026-28963: An attacker with physical access may be able to use Visual Intelligence to access sensitive user data during iPhone Mirroring.
Affects Screenshots x               CVE-2026-28964: An app may be able to access sensitive user data.
Affects CoreAnimation x             x CVE-2026-28965: A user may be able to view restricted content from the lock screen.
Affects WidgetKit x               CVE-2026-28969: An app may be able to cause unexpected system termination.
Affects IOKit x x x x x x x x CVE-2026-28971: A malicious iframe may use another website?s download settings.
Affects WebKit x   x         x CVE-2026-28972: An app may be able to cause unexpected system termination or write kernel memory.
Affects Kernel x x x x x x x x CVE-2026-28974: An app may be able to cause a denial-of-service.
Affects Spotlight x   x x   x x x CVE-2026-28976: An app may be able to gain root privileges.
Affects UserAccountUpdater     x           CVE-2026-28977: Processing a maliciously crafted file may lead to unexpected app termination.
Affects ImageIO x x x x x x x x CVE-2026-28978: A malicious app may be able to break out of its sandbox.
Affects Installer     x x x       CVE-2026-28983: A remote attacker may be able to cause a denial of service.
Affects LaunchServices x x x     x x x CVE-2026-28985: An attacker on the local network may be able to cause a denial-of-service.
Affects mDNSResponder x   x     x     CVE-2026-28986: An app may be able to cause unexpected system termination.
Affects Kernel x x x x x x x   CVE-2026-28987: An app may be able to leak sensitive kernel state.
Affects Kernel x x x x x x x   CVE-2026-28988: An app may be able to bypass certain Privacy preferences.
Affects Accounts x   x       x x CVE-2026-28990: Processing a maliciously crafted image may corrupt process memory.
Affects ImageIO x   x x x x x x CVE-2026-28991: An app may be able to cause a denial-of-service.
Affects Accelerate x   x     x x x CVE-2026-28992: An attacker may be able to cause unexpected app termination.
Affects IOHIDFamily x x x x x x x x CVE-2026-28993: An app may be able to access user-sensitive data.
Affects Shortcuts x x x x x     x CVE-2026-28994: An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Wi-Fi packets.
Affects Wi-Fi x x x x x x x   CVE-2026-28995: A malicious app may be able to break out of its sandbox.
Affects App Intents x x x     x x x CVE-2026-28996: An app may be able to access sensitive user data.
Affects Storage x   x x x x x x CVE-2026-39869: Processing an audio stream in a maliciously crafted media file may terminate the process.
Affects Audio x x x x x x x x CVE-2026-39870: Processing a maliciously crafted image may corrupt process memory.
Affects SceneKit     x x x       CVE-2026-39871: An app may be able to observe unprotected user data.
Affects TV App     x x x       CVE-2026-43652: An app may be able to access protected user data.
Affects Sandbox     x           CVE-2026-43653: An attacker on the local network may be able to cause a denial-of-service.
Affects mDNSResponder x x x   x x     CVE-2026-43654: An app may be able to disclose kernel memory.
Affects Kernel x x x x x x x x CVE-2026-43655: An app may be able to cause unexpected system termination or read kernel memory.
Affects IOSurfaceAccelerator x   x     x x   CVE-2026-43656: Parsing a maliciously crafted file may lead to an unexpected app termination.
Affects Quick Look x x x x x       CVE-2026-43658: Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affects WebKit x   x     x x x CVE-2026-43659: An app may be able to access sensitive user data.
Affects FileProvider x x x x x     x CVE-2026-43660: Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Affects WebKit x x x     x x x CVE-2026-43661: Processing a maliciously crafted image may corrupt process memory.
Affects ImageIO x   x     x x   CVE-2026-43666: An attacker on the local network may be able to cause a denial-of-service.
Affects mDNSResponder x x x x x x x x CVE-2026-43668: A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
Affects mDNSResponder x x x x x x x x