Aggregator
Hackers Exploit Cellular Router’s API to Send Malicious SMS Messages With Weaponized Links
Hackers have recently leveraged a vulnerability in the web-based management interfaces of certain cellular routers to co-opt their built-in SMS functionality for nefarious purposes. By targeting exposed APIs, attackers are able to dispatch large volumes of malicious SMS messages containing weaponized links that lead to drive-by downloads or credential-stealing pages. This emerging threat vector exploits […]
The post Hackers Exploit Cellular Router’s API to Send Malicious SMS Messages With Weaponized Links appeared first on Cyber Security News.
CVE-2022-50397 | Linux Kernel up to 5.4.219/5.10.149/5.15.74/5.19.16/6.0.2 ieee802154 raw_sendmsg assertion (Nessus ID 265562 / WID-SEC-2025-2092)
Siemens simplifies OT security with virtualized, encrypted connectivity
Siemens launched SINEC Secure Connect, the zero trust security platform designed for operational technology (OT) networks. The software solution virtualizes network structures using overlay networks. It enables Machine-to-Machine, Machine-to-Cloud, and Machine-to-Datacenter connections, plus secure remote access to industrial systems, all without relying on VPNs. Shop floor devices using SINEC Secure Connect remain protected from unauthorized external access while maintaining the necessary operational connectivity. This allows industrial companies to realize secure, flexible, and future-proof OT networking. … More →
The post Siemens simplifies OT security with virtualized, encrypted connectivity appeared first on Help Net Security.
CVE-2015-4042 | GNU Coreutils up to 8.23 sort.c keycompare_mb integer overflow (Nessus ID 266248 / ID 168072)
CVE-2016-10228 | GNU C Library up to 2.25 iconv -c input validation (Nessus ID 266254 / BID-96525)
CVE-2021-33574 | GNU C Library up to 2.33 mq_notify sigevent use after free (Nessus ID 266254)
CVE-2019-5736 | runc up to 1.0-rc6 /proc/self/exe container error (RHSA-2019:0303 / EDB-46369)
Атака нулевого дня длиной в год. Broadcom очищает китайский след в системах VMWare
CVE-2001-0897 | Infopop Ultimate Bulletin Board up to 5.47 IMG Tag cross site scripting (ID 10265 / XFDB-6142)
CVE-2001-0899 | Rick Fournier Network Tools 0.2 on PHP-Nuke $hostinput privileges management (EDB-21155 / Nessus ID 11106)
CVE-2001-0889 | University of Cambridge Exim 3.22 Pipe privileges management (VU#283723 / ID 50039)
CVE-2001-0900 | Francisco Burzi Gallery 1.2.3 modules.php include path traversal (EDB-21157 / Nessus ID 10810)
CVE-2001-0910 | EMC NetWorker 6.0 DNS authentication spoofing (Nessus ID 56496 / ID 68504)
CVE-2001-0911 | PHP-Nuke/PostNuke Cookie Password missing encryption (Nessus ID 11236 / ID 10437)
Rhadamanthys 0.9.x – walk through the updates
Research by: hasherezade Highlights Introduction Rhadamanthys is a complex, multi-modular malware sold on the underground market since September 2022. It was first advertised by the actor “kingcrete2022.” From the outset, its design showed the hallmarks of experienced developers, and analysis soon revealed that it drew heavily from an earlier project by the same authors, Hidden […]
The post Rhadamanthys 0.9.x – walk through the updates appeared first on Check Point Research.