Three men in the United Kingdom have pleaded guilty to operating otp[.]agency, a once popular online service that helped attackers intercept the one-time passcodes (OTPs) that many websites require as a second authentication factor in addition to passwords.
Launched in November 2019, OTP Agency was a service for intercepting one-time passwords needed to log in to various websites. Scammers would enter the target’s phone number and name, and the service would initiate an automated phone call to the target that alerts them about unauthorized activity on their account.
A vulnerability was found in Xoops Core module. It has been rated as critical. Affected by this issue is some unknown functionality of the file viewcat.php of the component Core. The manipulation of the argument cid leads to sql injection.
This vulnerability is handled as CVE-2007-1814. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, has been found in Apple iOS up to 10.3.1. This issue affects some unknown processing of the component Kernel. The manipulation leads to information disclosure (Memory).
The identification of this vulnerability is CVE-2017-6987. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in IglooFTP Pro 3.8. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2003-0561. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in Farm Frenzy Gold 1.0.1. This vulnerability affects unknown code of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability was named CVE-2014-5830. The attack can only be done within the local network. There is no exploit available.
The Federal Trade Commission (FTC) requires security camera vendor Verkada to create a comprehensive information security program as part of a settlement after multiple security failures enabled hackers to access live video feeds from internet-connected cameras. [...]