Aggregator
CVE-2024-37283 | Elastic Agent up to 8.14.x elastic-agent.yml log file
CVE-2024-44893 | jeecg-boot JimuReport 1.7.8 GET Request list privileges management
CVE-2024-42266 | Linux Kernel up to 6.10.3 fs/btrfs/subpage.c cow_file_range_inline return value (061e41581606/478574370bef / WID-SEC-2024-1875)
CVE-2024-25637 | CMS up to 3.5.14 AJAX cross site scripting
CVE-2024-40509 | openPetra 2023.02 serverMFinDev.asmx cross site scripting
CVE-2024-47076 | OpenPrinting libcupsfilters up to 2.1b1 IPP Attribute cfGetPrinterAttributes5 input validation (GHSA-rj88-6mr5-rcw8 / Nessus ID 207865)
CVE-2024-47175 | OpenPrinting libppd up to 2.1b1 buffer overflow (GHSA-rj88-6mr5-rcw8 / Nessus ID 207865)
CVE-2024-45758 | h2oai H2O up to 3.46.0.4 JDBC Connection connection_url deserialization (Nessus ID 213041)
CVE-2024-8370 | Grocy up to 4.2.0 SVG File Upload recipepictures force_serve_as cross site scripting
SVG Security Analysis Toolkit to Detect Malicious Scripts Hidden in SVG Files
As attackers increasingly leverage Scalable Vector Graphics (SVG) for stealthy code injection, security researchers face mounting challenges in detecting obfuscated payloads embedded within SVG assets. The SVG Security Analysis Toolkit by HackingLZ offers a comprehensive solution: a suite of four Python-based tools designed to reveal hidden scripts, decode obfuscated URLs, and verify protection mechanisms, all […]
The post SVG Security Analysis Toolkit to Detect Malicious Scripts Hidden in SVG Files appeared first on Cyber Security News.
ida + mcp,配置vs code和cursor实现AI自动化逆向
INC
You must login to view this content
Law enforcement is using AI to synthesize evidence. Is the justice system ready for it?
Rhysida
You must login to view this content
New Spear-Phishing Attack Deploys DarkCloud Malware to Steal Keystrokes and Credentials
Adversaries don’t work 9–5 and neither do we. At eSentire, our 24/7 SOCs are staffed with elite threat hunters and cyber analysts who hunt, investigate, contain and respond to threats within minutes. Backed by threat intelligence, tactical threat response and advanced threat analytics from our Threat Response Unit (TRU), eSentire delivers rapid detection and disruption […]
The post New Spear-Phishing Attack Deploys DarkCloud Malware to Steal Keystrokes and Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
African Authorities Arrest 260 Suspects in Romance, Sextortion Scams
Authorities in 14 African countries arrested 260 people, seized 1,235 electronic devices and took down 18 criminal infrastructures in a sprawling Interpol operation aimed at the growing global problem of romance and sextortion scams being run via social media and other platforms. The operation is part of a larger effort to address the problem of scam centers, which started in Southeast Asia but are spreading globally.
The post African Authorities Arrest 260 Suspects in Romance, Sextortion Scams appeared first on Security Boulevard.