Aggregator
Attackers exploit SimpleHelp RMM Software flaws for initial access
CVE-2009-3270 | Apple iTunes up to 12.5 on Windows Expat resource management (HT207599 / EDB-12509)
TP-Link Router Web Interface XSS Vulnerability – PoC Exploit Released
A recently discovered Cross-site Scripting (XSS) vulnerability, CVE-2024-57514, affecting the TP-Link Archer A20 v3 Router has raised security concerns among users. The flaw CVE-2024-57514, identified in firmware version 1.0.6 Build 20231011 rel.85717(5553), allows attackers to execute arbitrary JavaScript code through the router’s web interface, potentially leading to malicious exploitation. Discovery of the Vulnerability The vulnerability stems […]
The post TP-Link Router Web Interface XSS Vulnerability – PoC Exploit Released appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2007-1649 | PHP 5.2.1 information disclosure (EDB-3559 / Nessus ID 17797)
JVN: 複数のB&R製品における非推奨暗号アルゴリズムの使用の脆弱性
Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns
Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns
Cofense Intelligence has continually observed the abuse or usage of legitimate domain service exploitation. This report highlights observed phishing threat actor abuse of .gov top-level domains (TLDs) for different countries over two years from November 2022 to November 2024.
The post Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns appeared first on Security Boulevard.
Снял номер, но остался за дверью: хакеры взломали популярную систему онлайн-бронирования
JVN: 複数のSchneider Electric製品における複数の脆弱性
CVE-2023-28128 | Ivanti Avalanche FileStoreConfig unrestricted upload (ID 172398)
CVE-2023-28127 | Ivanti Avalanche getLogFile path traversal
CVE-2023-31974 | yasm 1.3.0 /nasm/nasm-pp.c error use after free (Issue 208)
CVE-2023-30083 | libming 0.4.8 swftophp util/decompile.c newVar_N weak iv (Issue 266)
CVE-2023-30056 | FICO Origination Manager Decision Module 4.8.1 session fixiation (ID 172192)
CVE-2023-29791 | kodbox up to 1.37 Debug Information cross site scripting
UAC-0063 Expands Cyber Attacks to European Embassies Using Stolen Documents
UAC-0063 Expands Cyber Attacks to European Embassies Using Stolen Documents
Vulnerability in Airline Integration Service enables A Hacker to Gain Entry To User Accounts
A recent security vulnerability in a widely used airline integration service has exposed millions of users to account takeovers, raising concerns over the safety of online travel services. Security researchers from Salt Labs discovered the flaw, which enabled hackers to access user accounts without authorization, potentially compromising sensitive information and airline loyalty points. The Exploit […]
The post Vulnerability in Airline Integration Service enables A Hacker to Gain Entry To User Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.