A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is an unknown function of the file /tour(cor).php. The manipulation of the argument mai leads to sql injection.
This vulnerability is traded as CVE-2024-11970. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
Also: Python Library Update Steals Credentials; Drug Cartels Launder With Tether This week's cryptohack roundup includes a U.S. federal judge striking down the SEC's expanded "Dealer Rule," a Python crypto library update stealing credentials, why digital payment apps are being excluded from some types of federal oversight, and drug cartels laundering profits via Tether.
Nearly two dozen security vulnerabilities have been disclosed in Advantech EKI industrial-grade wireless access point devices, some of which could be weaponized to bypass authentication and execute code with elevated privileges.
"These vulnerabilities pose significant risks, allowing unauthenticated remote code execution with root privileges, thereby fully compromising the confidentiality,
The Tor Project has put out an urgent call to the privacy community asking volunteers to help deploy 200 new WebTunnel bridges by the end of the year to fight government censorship. [...]
A vulnerability was found in Apache Arrow R up to 16.1.0. It has been rated as problematic. This issue affects the function to_data_frame. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2024-52338. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Cradlepoint NetCloud Exchange Client 1.110.50 on Windows. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to incorrect default permissions.
This vulnerability was named CVE-2024-11969. Attacking locally is a requirement. There is no exploit available.
A vulnerability was found in Linux Kernel up to 6.4.6. It has been classified as critical. This affects the function bcm_proc_show. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2023-52922. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
安全公司 ESET 的研究人员报告了第一个杀不死的 Linux UEFI Bootkit。该恶意程序被攻击者命名为 Bootkitty,相比 Windows 平台上的类似恶意程序,Bootkitty 相对简陋,关键底层功能不完善,主要感染 Ubuntu,感染其它 Linux 发行版的手段缺乏。安全研究人员猜测它可能是一个概念验证版本,尚未观察到实际感染证据。Bootkit 是一种感染固件的恶意程序,此类恶意程序无法通过格式化硬盘等常规方法杀死。最新发现意味着 UEFI Bootkit 不再只针对 Windows 操作系统。
UK’s Wirral University Teaching Hospital suffered a cyberattack that caused delays in appointments and procedures. Wirral University Teaching Hospital NHS Foundation Trust (WUTH) is an NHS Foundation Trust. It provides healthcare for people of the Wirral Peninsula and the surrounding areas of North West England and North Wales. The trust is responsible for Arrowe Park […]