Aggregator
黑客宣称窃取 Telefónica 106GB 数据并公开部分佐证
Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours
Experts at Wiz have identified a new wave of attacks targeting TeamCity servers—a widely used platform for orchestrating CI/CD workflows. Threat actors exploited a misconfigured Java Debug Wire Protocol (JDWP) interface, enabling remote command...
The post Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours appeared first on Penetration Testing Tools.
CVE-2024-39002 | rjrodger rjrodger jsonic-next 2.12.1 util.clone prototype pollution
CVE-2024-39003 | amoyjs amoy common 1.0.10 setValue prototype pollution
CVE-2024-48597 | Online Clinic Management System 1.0 editp.php?action=edit ID sql injection
CVE-2024-35286 | Mitel MiCollab up to 9.8.0.33 NuPoint Messenger sql injection
CVE-2024-35287 | Mitel MiCollab up to 9.8.1.5 NuPoint Messenger unnecessary privileges
CVE-2024-47912 | Mitel MiCollab up to 9.8.1.201 Conferencing Component access control (misa-2024-0027)
CVE-2024-40087 | Vilo Mesh WiFi System up to 5.16.1.33 TCP Service Port 5432 missing authentication
CVE-2024-40084 | Vilo Mesh WiFi System up to 5.16.1.33 Boa Webserver buffer overflow
CVE-2024-47223 | Mitel MiCollab up to 9.8.1.201 AWV sql injection (misa-2024-0028)
CVE-2024-40088 | Vilo Mesh WiFi System up to 5.16.1.33 Boa Webserver path traversal
CVE-2024-6040 | parisneo lollms-webui up to 9.8 lollms_binding_infos client_id cross-site request forgery
CVE-2024-38131 | Microsoft Windows up to Server 2022 23H2 Clipboard Virtual Channel Extension sensitive data storage in improperly locked memory (EUVD-2024-37091)
CVE-2024-35285 | Mitel MiCollab up to 9.8.0.33 NuPoint Messenger command injection
Weaponized Versions of PuTTY and WinSCP Attacking IT Admins Via Search Results
A sophisticated SEO poisoning campaign targeting system administrators with malicious backdoor malware. Arctic Wolf security researchers have uncovered a dangerous search engine optimization (SEO) poisoning and malvertising campaign that has been targeting IT professionals since early June 2025. The campaign uses fake websites hosting Trojanized versions of popular IT tools, specifically PuTTY and WinSCP, to […]
The post Weaponized Versions of PuTTY and WinSCP Attacking IT Admins Via Search Results appeared first on Cyber Security News.