Aggregator
CVE-2024-2048 | HashiCorp Vault/Vault Enterprise up to 1.14.9/1.15.x TLS Certificate certificate validation
CVE-2024-1410 | Cloudflare quiche up to 0.19.1/0.20.0 resource consumption (GHSA-xhg9-xwch-vr7x)
CVE-2024-1765 | Cloudflare quiche up to 0.19.0/0.20.0 resource consumption (GHSA-78wx-jg4j-5j6g)
CVE-2024-5243 | TP-Link Omada ER605 buffer overflow
CVE-2024-5244 | TP-Link Omada ER605 reliance on security through obscurity
CVE-2024-5291 | D-Link DIR-2150 1.06B01 SOAP API Interface GetDeviceSettings os command injection (ZDI-24-442)
CVE-2024-5293 | D-Link DIR-2640 1.11B02_BETA02 lighttpd Webserver prog.cgi stack-based overflow (ZDI-24-444)
CVE-2024-5297 | D-Link D-View 2.0.1.28 executeWmicCmd os command injection (ZDI-24-448)
CVE-2024-5298 | D-Link D-View 2.0.1.28 queryDeviceCustomMonitorResult routine (ZDI-24-449)
CVE-2024-5296 | D-Link D-View 2.0.1.28 TokenUtils hard-coded key (ZDI-24-447)
CVE-2024-5294 | D-Link DIR-3040 120B03 prog.cgi websSecurityHandler memory leak (ZDI-24-445)
CVE-2023-27359 | TP-Link AX1800 hotplugd Firewall Rule race condition
Sophisticated DevilsTongue Spyware Tracks Windows Users Worldwide
Insikt Group has uncovered new infrastructure tied to the Israeli spyware vendor Candiru, now operating under Saito Tech Ltd., highlighting the persistent deployment of its advanced DevilsTongue malware. Utilizing Recorded Future Network Intelligence, researchers identified eight distinct operational clusters, each exhibiting variations in infrastructure design and administration. These include victim-facing components for deploying and commanding […]
The post Sophisticated DevilsTongue Spyware Tracks Windows Users Worldwide appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
维基百科编辑对 AI 生成文章采用加速删除政策
UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware
The Ukrainian threat intelligence group UAC-0099 has significantly evolved its cyber warfare capabilities, deploying a sophisticated new malware toolkit targeting Ukrainian state authorities, Defense Forces, and defense industrial enterprises. The National Cyber Incident Response Team CERT-UA has documented a series of coordinated attacks employing HTA (HTML Application) files as the primary delivery mechanism for the […]
The post UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware appeared first on Cyber Security News.
Why Marcus Is Wrong About AI
Не чип, а стукач. США хотят отслеживать путь каждого GPU до последней розетки
Google’s Salesforce Instances Hacked in Ongoing Attack – Hackers Exfiltrate User Data
Google has confirmed that one of its corporate Salesforce instances was compromised in June by the threat group tracked as UNC6040. This incident is part of a Salesforce attack campaign involving voice phishing attacks aimed at stealing sensitive data from organizations’ Salesforce environments, followed by extortion demands. The breach highlights the growing risks of social […]
The post Google’s Salesforce Instances Hacked in Ongoing Attack – Hackers Exfiltrate User Data appeared first on Cyber Security News.