Last month, Sophos X-Ops reported several MDR cases where threat actors exploited a vulnerability in Veeam backup servers. We continue to track the activities of this threat cluster, which recently included deployment of a new ransomware. The vulnerability, CVE-2024-40711, was used as part of a threat activity cluster we named STAC 5881. Attacks leveraged compromised […]
South Korea warned that pro-Russian groups have attacked government and private sector websites following the deployment of North Korean soldiers in Ukraine
A vulnerability was found in mooSocial mooDating 1.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /friends of the component URL Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2023-3844. The attack can be launched remotely. Furthermore, there is an exploit available.
We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
A vulnerability was found in PHPMailer up to 5.2.13. It has been rated as critical. This issue affects the function sendCommand of the file class.phpmailer.php. The manipulation leads to improper input validation.
The identification of this vulnerability is CVE-2015-8476. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.