Aggregator
Live Webinar | Get Ahead and Stay Ahead of Threats with Tanium and Microsoft
7 months ago
Attack Exposure: Unpatched Cleo Managed File-Transfer Software
7 months ago
At Least 1,000 Hosts Still Vulnerable as Ransomware Group Claims Mass Exploits
More than 1,000 Cleo managed file-transfer hosts remain internet-exposed and unpatched, despite warnings of a mass attack targeting critical vulnerabilities in the widely used software. The Clop ransomware operation, which has repeatedly targeted MFT software, claimed credit for the attacks.
More than 1,000 Cleo managed file-transfer hosts remain internet-exposed and unpatched, despite warnings of a mass attack targeting critical vulnerabilities in the widely used software. The Clop ransomware operation, which has repeatedly targeted MFT software, claimed credit for the attacks.
От пылинки до сверхмагнита: учёные нашли квазичастицу во всех магнитных материалах
7 months ago
Как спин электронов может сделать электронику умнее и долговечнее.
CVE-2021-40596 | Sourcecodester Online Learning System Login.php faculty_id sql injection
7 months ago
A vulnerability, which was classified as critical, has been found in Sourcecodester Online Learning System. Affected by this issue is some unknown functionality of the file Login.php. The manipulation of the argument faculty_id leads to sql injection.
This vulnerability is handled as CVE-2021-40596. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-34852 | sanluan PublicCMS up to 4.0.202302 permission
7 months ago
A vulnerability was found in sanluan PublicCMS up to 4.0.202302 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2023-34852. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2023-6123 | OpenText ALM Octane 16.2.100 neutralization
7 months ago
A vulnerability classified as critical was found in OpenText ALM Octane 16.2.100. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper neutralization.
This vulnerability is known as CVE-2023-6123. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-1512 | MasterStudy LMS WordPress Plugin up to 3.2.5 on WordPress sql injection (ID 3036794)
7 months ago
A vulnerability has been found in MasterStudy LMS WordPress Plugin up to 3.2.5 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-1512. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-25630 | Cilium up to 1.14.6 CRD missing encryption (GHSA-7496-fgv9-xw82)
7 months ago
A vulnerability was found in Cilium up to 1.14.6. It has been rated as problematic. Affected by this issue is some unknown functionality of the component CRD Handler. The manipulation leads to missing encryption of sensitive data.
This vulnerability is handled as CVE-2024-25630. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-25631 | Cilium up to 1.14.6 External kvstore missing encryption (GHSA-x989-52fc-4vr4)
7 months ago
A vulnerability classified as problematic was found in Cilium up to 1.14.6. Affected by this vulnerability is an unknown functionality of the component External kvstore. The manipulation leads to missing encryption of sensitive data.
This vulnerability is known as CVE-2024-25631. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-1925 | Ctcms 2.1.2 Upsys.php unrestricted upload
7 months ago
A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of the file ctcms/apps/controllers/admin/Upsys.php. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-1925. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-1926 | SourceCodester Free and Open Source Inventory Management System 1.0 search_sales_report.php customer sql injection
7 months ago
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /app/ajax/search_sales_report.php. The manipulation of the argument customer leads to sql injection.
The identification of this vulnerability is CVE-2024-1926. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-1927 | SourceCodester Web-Based Student Clearance System 1.0 /Admin/login.php txtpassword sql injection
7 months ago
A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /Admin/login.php. The manipulation of the argument txtpassword leads to sql injection.
This vulnerability is known as CVE-2024-1927. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-1928 | SourceCodester Web-Based Student Clearance System 1.0 Edit User Profile Page /admin/edit-admin.php Fullname sql injection
7 months ago
A vulnerability, which was classified as critical, has been found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit-admin.php of the component Edit User Profile Page. The manipulation of the argument Fullname leads to sql injection.
This vulnerability is handled as CVE-2024-1928. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Malicious Microsoft VSCode extensions target devs, crypto community
7 months ago
Malicious Visual Studio Code extensions were discovered on the VSCode marketplace that download heavily obfuscated PowerShell payloads to target developers and cryptocurrency projects in supply chain attacks. [...]
Bill Toulas
Психолог поневоле: GPT-4 осваивает терапию, но никак не может подавить в себе расиста
7 months ago
Почему люди доверяют свои тайны искусственному интеллекту?
Phishers Spoof Google Calendar Invites in Fast-Spreading, Global Campaign
7 months ago
Attackers are using links to the popular Google scheduling app to lead users to pages that steal credentials, with the ultimate goal of committing financial fraud.
Elizabeth Montalbano, Contributing Writer
Typecho插件:ImageAccelerator文章图片加速
7 months ago
开发初衷:随着网站内容对多媒体资源的依赖逐步加深,使用第三方图床已成为许多站长降低服务器压力和节省存储成本的常用选择。然而,大部分第三方图床的节点主要分布在海外,这导致国内访问速度受到显著影响,...
黑海洋
Good Samaritan Health Center of Cobb Has Been Claimed a Victim to Qilin Ransomware
7 months ago
Good Samaritan Health Center of Cobb Has Been Claimed a Victim to Qilin Ransomware
Dark Web Informer - Cyber Threat Intelligence
A Threat Actor Claims to be Selling Access to an Unidentified Law Company in UK
7 months ago
A Threat Actor Claims to be Selling Access to an Unidentified Law Company in UK
Dark Web Informer - Cyber Threat Intelligence