Aggregator
CVE-2024-23752 | PandasAI up to 1.5.17 Python Code synthetic_dataframe code injection (Issue 868)
CVE-2023-52353 | mbed TLS up to 3.5.1 mbedtls_ssl_session_reset session fixiation (Issue 8654 / Nessus ID 211939)
CVE-2024-23730 | LlamaHub up to 0.0.66 OpenAPI Plugin Loader/ChatGPT Plugin Loader privilege escalation
BypassFuzzer: Fuzz 401/403/404 pages for bypasses
Bypass Fuzzer Fuzz 401/403ing endpoints for bypasses This tool performs various checks via headers, path normalization, verbs, etc. to attempt to bypass ACLs or URL validation. It will output the response codes and length...
The post BypassFuzzer: Fuzz 401/403/404 pages for bypasses appeared first on Penetration Testing Tools.
微信测试「朋友圈折叠」功能;华为推尊界 S800,70.8 万起;宇树预热「钢铁侠」新机器人 | 极客早知道
端午安康
分享图片
端午安康!
中国人民银行发布《中国人民银行业务领域网络安全事件报告管理办法》
Microsoft Reveals Techniques To Defending Against Advancing AiTM Attacks
Microsoft’s latest security research has unveiled sophisticated defense strategies against the rapidly evolving threat landscape of Adversary-in-the-Middle (AiTM) attacks, marking a critical development in enterprise cybersecurity. The emergence of AiTM attacks represents a fundamental shift in how threat actors approach credential theft, particularly as organizations increasingly adopt multifactor authentication (MFA) and other advanced security measures […]
The post Microsoft Reveals Techniques To Defending Against Advancing AiTM Attacks appeared first on Cyber Security News.
CVE-2023-28484 | libxml2 xmlSchemaFixupComplexType null pointer dereference (Bug 491 / Nessus ID 236630)
CVE-2022-43680 | Oracle Outside In Technology 8.5.6 DC-Specific Component denial of service (Nessus ID 211295)
CVE-2022-43680 | Oracle Financial Services Behavior Detection Platform 8.0.8.1/8.1.1.1/8.1.2.3/8.1.2.4 Third Party denial of service (Nessus ID 211295)
CVE-2022-43680 | Oracle Financial Services Currency Transaction Reporting 8.0.8.1.0/8.1.1.1.0/8.1.2.3.0/8.1.2.4.1 Application denial of service (Nessus ID 211295)
CVE-2022-43680 | Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Application denial of service (Nessus ID 211295)
CVE-2022-43680 | Oracle Database Server up to 19.19/21.10 Text denial of service (Nessus ID 211295)
CVE-2022-43680 | Oracle HTTP Server 12.2.1.4.0 Thirdparty denial of service (Nessus ID 211295)
CVE-2022-43680 | Oracle Enterprise Manager Base Platform 13.5.0.0 Enterprise Manager Install denial of service (Nessus ID 211295)
NullGate: A Modern Approach to Indirect Syscalls with Defender Bypass
NullGate This project implements a comfortable and modern way to use the NTAPI functions using indirect syscalls, coupled with the FreshyCalls method with a little twist for dynamic syscall number retrieval. It also uses a technique...
The post NullGate: A Modern Approach to Indirect Syscalls with Defender Bypass appeared first on Penetration Testing Tools.