Aggregator
CVE-1999-0920 | University of Washington POP2d/IMAP4 4.4 memory corruption (EDB-19226 / Nessus ID 10130)
8 months 3 weeks ago
A vulnerability was found in University of Washington POP2d and IMAP4 4.4. It has been classified as very critical. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-1999-0920. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #449684: sourcecodester Best Courier Management System Project in PHP v1.0 Unauthorized Tenant Deletion [Accepted]
8 months 3 weeks ago
Submit #449684 / VDB-286245
谷歌新推出的还原凭证工具简化了安卓迁移后的应用程序登录过程
8 months 3 weeks ago
安全客
APT-C-60 Hackers Exploit StatCounter and Bitbucket in SpyGlace Malware Campaign
8 months 3 weeks ago
The threat actor known as APT-C-60 has been linked to a cyber attack targeting an unnamed organization in Japan that used a job application-themed lure to deliver the SpyGlace backdoor.
That's according to findings from JPCERT/CC, which said the intrusion leveraged legitimate services like Google Drive, Bitbucket, and StatCounter. The attack was carried out around August 2024.
"In this attack,
The Hacker News
《永夜星河》掀起追剧潮,成为商业价值最高的剧集之一,恒星引力做对了什么?
8 months 3 weeks ago
恒星引力做对了什么?
Banshee Stealer: недовольный клиент уничтожил преступную империю
8 months 3 weeks ago
Зачем переплачивать за стилер, если теперь он доступен бесплатно?
将 windows 系统通过 dd 重装成 linux debian 系统
8 months 3 weeks ago
在网上,有好多能把 Linux 系统重装成 Windows 系统的脚本。但是呢,能把 Windows 系统重装成 Linux 系统的脚本特别少。萌咖的 dd 脚本,因为它所在的服务器停用了,相关...
黑海洋
CVE-2024-11025 | SMA Sunny Central SC 1760-US prior 10.01.18.R Administration Panel sql injection (VDE-2024-074)
8 months 3 weeks ago
A vulnerability was found in SMA Sunny Central SC 1760-US, Sunny Central SC 1850-US, Sunny Central SC 2000 EV-US, Sunny Central SC 2000-US, Sunny Central SC-2200-10, Sunny Central SC 2200-US, Sunny Central SC-2475-10, Sunny Central SC 2500 EV-US, Sunny Central SC 2660 UP, Sunny Central SC 2660 UP-US, Sunny Central SC 2750 EV-US, Sunny Central SC 2750 UP-US, Sunny Central SC 2800 UP, Sunny Central SC 2800 UP-US, Sunny Central SC 2930 UP, Sunny Central SC 2930 UP-US, Sunny Central SC 3060 UP, Sunny Central SC 3060 UP-US, Sunny Central SC 4000 UP, Sunny Central SC 4000 UP-US, Sunny Central SC 4200 UP, Sunny Central SC 4200 UP-US, Sunny Central SC 4400 UP, Sunny Central SC 4400 UP-JP, Sunny Central SC 4400 UP-US, Sunny Central SC 4600 UP, Sunny Central SC 4600 UP-US, Sunny Central Storage SCS-1900-10, Sunny Central Storage SCS-2200-10, Sunny Central Storage SCS 2300 UP-XT, Sunny Central Storage SCS 2300 UP-XT-US, Sunny Central Storage SCS 2400 UP-XT, Sunny Central Storage SCS 2400 UP-XT-US, Sunny Central Storage SCS-2475-10, Sunny Central Storage SCS 2530 UP-XT, Sunny Central Storage SCS 2530 UP-XT-US, Sunny Central Storage SCS 2630 UP-XT, Sunny Central Storage SCS 2630 UP-XT-US, Sunny Central Storage SCS-2900-10, Sunny Central Storage SCS 3450 UP, Sunny Central Storage SCS 3450 UP-US, Sunny Central Storage SCS 3450 UP-XT, Sunny Central Storage SCS 3450 UP-XT-JP, Sunny Central Storage SCS 3450 UP-XT-US, Sunny Central Storage SCS 3600 UP, Sunny Central Storage SCS 3600 UP-US, Sunny Central Storage SCS 3600 UP-XT, Sunny Central Storage SCS 3600 UP-XT-US, Sunny Central Storage SCS 3800 UP, Sunny Central Storage SCS 3800 UP-US, Sunny Central Storage SCS 3800 UP-XT, Sunny Central Storage SCS 3800 UP-XT-US, Sunny Central Storage SCS 3950 UP, Sunny Central Storage SCS 3950 UP-US, Sunny Central Storage SCS 3950 UP-XT and Sunny Central Storage SCS 3950 UP-XT-US. It has been rated as critical. Affected by this issue is some unknown functionality of the component Administration Panel. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-11025. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
PSLoramyra: Technical Analysis of Fileless Malware Loader
8 months 3 weeks ago
In this article, ANY.RUN‘s analyst team will explore a malicious loader known as PSLoramyra. This advanced malware leverages PowerShell, VBS, and BAT scripts to inject malicious payloads into a system, execute them directly in memory, and establish persistent access. Classified as a fileless loader, PSLoramyra bypasses traditional detection methods by loading its primary payload entirely […]
The post PSLoramyra: Technical Analysis of Fileless Malware Loader appeared first on ANY.RUN's Cybersecurity Blog.
Dmitry Alexandrov
为包括星巴克在内的美国和英国商店提供服务的软件公司 Blue Yonder 遭勒索软件攻击
8 months 3 weeks ago
安全客
CVE-2024-11667 | Zyxel ATP/USG FLEX/USG FLEX 50(W)/USG20(W)-VPN up to 5.38 URL path traversal
8 months 3 weeks ago
A vulnerability was found in Zyxel ATP, USG FLEX, USG FLEX 50(W) and USG20(W)-VPN up to 5.38. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component URL Handler. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-11667. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-52323 | Zoho ManageEngine Analytics Plus up to 6099 information disclosure
8 months 3 weeks ago
A vulnerability was found in Zoho ManageEngine Analytics Plus up to 6099. It has been classified as problematic. Affected is an unknown function. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-52323. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
甲骨文ARM架构VPS搭建 Mtproxy
8 months 3 weeks ago
很多人白嫖了 Oracle ARM 架构的服务器不知道放点啥,用来搭建 MTP 代理,却很容易失败,遇到各种错误阻碍,今天简单整理下在 ARM 架构下搭建 MTProxy 的方法教程。MTPro...
黑海洋
CVE-2015-7611 | Apache James Server 2.3.2 os command injection (Entry 133798 / EDB-48130)
8 months 3 weeks ago
A vulnerability was found in Apache James Server 2.3.2. It has been classified as critical. This affects an unknown part. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2015-7611. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Matrix黑客组织部署新型大规模IoT僵尸网络进行DDoS攻击
8 months 3 weeks ago
近日,一起大规模的数据泄露事件震动了网络安全界。名为“HikkI-Chan”的黑客在臭名昭著的Breach Forums上泄露了超过3.9亿VK用户的个人信息。
【安全圈】CVE-2024-8114:GitLab 漏洞允许权限升级
8 months 3 weeks ago
【安全圈】Firefox和Tor浏览器遭遇神秘0Day漏洞攻击
8 months 3 weeks ago
【安全圈】星巴克遭勒索攻击,回到纸质办公时代
8 months 3 weeks ago
【安全圈】VPN正在成为企业入侵的关键路径
8 months 3 weeks ago