Aggregator
Финишная прямая: как любовь к пробежкам довела хакера до тюремной шконки
CVE-2022-2840 | Zephyr Project Manager up to 3.2.4 on Wordpress /wp-admin/admin-ajax.php project_id/task_id sql injection (ID 168652 / EDB-51024)
Careto – A legendary Threat Group Targets Windows By Deploy Microphone Recorder And Steal Files
Recent research has linked a series of cyberattacks to The Mask group, as one notable attack targeted a Latin American organization in 2022, where attackers compromised the organization’s MDaemon email server and exploited the WorldClient webmail component to maintain persistent access. While the initial compromise vector remains unknown, the successful exploitation of the MDaemon server […]
The post Careto – A legendary Threat Group Targets Windows By Deploy Microphone Recorder And Steal Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
RiseLoader Attack Windows By Employed A VMProtect To Drop Multiple Malware Families
RiseLoader, a new malware family discovered in October 2024, leverages a custom TCP-based binary protocol similar to RisePro for downloading and executing second-stage payloads. Despite RisePro’s development discontinuation in June 2024, RiseLoader’s emergence suggests a potential connection to the threat group behind RisePro and PrivateLoader. The malware often employs VMProtect for code obfuscation and has […]
The post RiseLoader Attack Windows By Employed A VMProtect To Drop Multiple Malware Families appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
1-Click RCE Attack In Kerio Control UTM Allow Attackers Gain Firewall Root Access Remotely
GFI Software’s Kerio Control, a popular UTM solution, was found to be vulnerable to multiple HTTP Response Splitting vulnerabilities, which affecting versions 9.2.5 through 9.4.5, could potentially allow attackers to inject malicious code into web pages, leading to cross-site scripting (XSS) attacks and other security compromises. The vulnerabilities, tracked as CVE-2024-52875 and KIS-2024-07, highlight the […]
The post 1-Click RCE Attack In Kerio Control UTM Allow Attackers Gain Firewall Root Access Remotely appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356)
BeyondTrust has fixed an unauthenticated command injection vulnerability (CVE-2024-12356) in its Privileged Remote Access (PRA) and Remote Support (RS) products that may allow remote code execution, and is urging organizations with on-premise installations to test the patch and implement it quickly. About CVE-2024-12356 BeyondTrust Privileged Remote Access is an enterprise solution that mediates secure remote access to enterprise environments for employees and trusted vendors. BeyondTrust Remote Support allows organizations’ IT helpdesk personnel to securely connect … More →
The post BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356) appeared first on Help Net Security.
Глоток невесомости: японцы создают первое космическое саке за 100 млн йен
CVE-2024-29018 | docker DNS Request resource transfer (GHSA-mq39-4gv4-mvpx / Nessus ID 213083)
CVE-2024-47582 | SAP NetWeaver AS JAVA 7.50 xml external entity reference (Nessus ID 213081)
CVE-2024-47579 | SAP NetWeaver AS for JAVA 7.50 Adobe Document Services upload file information disclosure (Nessus ID 213081)
CVE-2024-47580 | SAP NetWeaver AS for JAVA 7.50 Adobe Document Services file information disclosure (Nessus ID 213081)
CVE-2024-47578 | SAP NetWeaver AS for JAVA 7.50 Adobe Document Service server-side request forgery (Nessus ID 213081)
CVE-2024-49910 | Linux Kernel up to 6.11.2 AMD Display set_output_gamma null pointer dereference (d8ee900b92b6/dd340acd42c2 / Nessus ID 213095)
CVE-2024-49904 | Linux Kernel up to 6.10.13/6.11.2 AMD list_for_each_entry_safe null pointer dereference (5ec731ef47f1/8e87763946f7/4416377ae1fd / Nessus ID 213095)
European Commission Opens TikTok Election Integrity Probe
工程中心再添一项ISO体系认证
吸尘器、洗地机、机器人……你都如何做好「日常清洁」?
工程中心再添一项ISO体系认证
Azure Data Factory And Apache Airflow Integration Flaws Let Attackers Gain Write Access
Researchers have uncovered vulnerabilities in Microsoft Azure Data Factory’s integration with Apache Airflow, which could potentially allow attackers to gain unauthorized access and control over critical Azure resources. By exploiting these vulnerabilities, attackers could compromise the integrity of the Azure environment, potentially leading to data breaches, service disruptions, and other severe consequences. The identified vulnerabilities […]
The post Azure Data Factory And Apache Airflow Integration Flaws Let Attackers Gain Write Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.