Aggregator
ESET APT Activity Report Q2 2024–Q3 2024
CVE-2024-20536 | Cisco Data Center Network Manager 12.1.2e/12.1.2p/12.1.3b Web-based Management Interface/REST API Endpoint sql injection (cisco-sa-ndfc-sqli-CyPPAxrL)
5 Most Common Malware Techniques in 2024
UK Cybersecurity Wages Soar Above Inflation as Stress Levels Rise
CVE-2024-10203 | Zoho ManageEngine EndPoint Central up to 11.3.2416.21/11.3.2428.9 Agent privileges management
CVE-2024-30141 | HCL BigFix Compliance 2.0.11 information exposure (KB0117197)
SteelFox and Rhadamanthys Malware Use Copyright Scams, Driver Exploits to Target Victims
Загадка пульсаров раскрыта? Физики заглянули внутрь нейтронных звезд
CVE-2024-30142 | HCL BigFix Compliance 2.0.11 Session Cookie missing secure attribute (KB0117197)
China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait
CVE-2024-30140 | HCL BigFix Compliance 2.0.11 Web Page Cache redirect (KB0117197)
CVE-2011-0836 | Oracle Peoplesoft And Jdedwards Product Suite up to 8.98.4.1 (EDB-35638 / SBV-31147)
2024 年将是平均气温比工业化前水平高出 1.5 摄氏度的第一年
Цена «свободного доступа»: Роскомнадзор рекомендует отказаться от CloudFlare
AsyncRAT’s Infection Tactics via Open Directories: Technical Analysis
Editor’s note: The current article is authored by RacWatchin8872, who is a threat intelligence analyst. You can find him on X. This article covers two distinct methods used to infect systems with AsyncRAT via open directories. These techniques show how attackers are constantly adapting, finding new ways to use publicly accessible files to broaden AsyncRAT’s […]
The post AsyncRAT’s Infection Tactics <br>via Open Directories: Technical Analysis appeared first on ANY.RUN's Cybersecurity Blog.
Critical vulnerability in Cisco industrial wireless access points fixed (CVE-2024-20418)
Cisco has fixed a critical command injection vulnerability (CVE-2024-20418) affecting its Ultra-Reliable Wireless Backhaul (URWB) Access Points that can be exploited via a HTTP requests and allows complete compromise of the devices. There are no workarounds to address this flaw, though vulnerable access points can be protected by switching off URWB mode, the company shared in the advisory. The good news is that the vulnerability was discovered by a Cisco employee during internal security testing … More →
The post Critical vulnerability in Cisco industrial wireless access points fixed (CVE-2024-20418) appeared first on Help Net Security.