Tehditleri anlayın, önlem alın.
Güncel siber güvenlik haberleri, teknik rehberler ve editoryal olarak incelenmiş kritik CVE kayıtları, hepsi Türkçe, hepsi teknik doğrulukla.
Editoryal İnceleme
Kritik güvenlik açıkları CyberSectr editörleri tarafından Türkçe olarak analiz edilir.
Otomatik CVE Takibi
NVD, CISA KEV ve EPSS kaynaklarından teknik veriler otomatik senkronize edilir.
Türkçe İçerik
Güncel tehditler ve savunma stratejileri üzerine özgün, düşük kaliteli AI içerik barındırmayan makaleler.
Fidye Yazılımlarına Karşı Kurumsal Savunma Stratejileri
Kurumların fidye yazılımı saldırılarına karşı alabileceği katmanlı savunma önlemleri ve olay müdahale planlaması.
Devamını okuSon Makaleler
Tümünü görÖne Çıkan CVE'ler
Tüm CVE listesidjust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and custom `dispatch()` guards — and the djust admin extension's staff gate (applied only in the HTTP `as_view` wrapper) were enforced on the initial HTTP GET but silently bypassed over WebSocket, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view — including admin list/create/change/delete — and dispatch its handlers. This is fixed in djust 1.0.7. `check_view_auth` now honors the Django `AccessMixin` family on every transport; a new system check S004 fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-`dispatch` forms); and the admin base mixin declares `login_required = True` + an active-staff `check_permissions` gate. As a workaround, gate views using djust's `login_required` / `permission_required` / `check_permissions` attributes (honored on all transports) rather than HTTP-only mixins/decorators.
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
