Aggregator
Smashing Security podcast #389: WordPress vs WP Engine, and the Internet Archive is down
CVE-2024-45290 | PHPOffice PhpSpreadsheet up to 1.29.1/2.1.0 XLSX File absolute path traversal
CVE-2024-45291 | PHPOffice PhpSpreadsheet up to 1.29.1/2.1.0 XLSX File setEmbedImages absolute path traversal
CVE-2024-8925 | PHP up to 8.1.29/8.2.23/8.3.11 HTTP POST Request (GHSA-9pqp-7h25-4f32 / Nessus ID 208984)
CVE-2024-38029 | Microsoft Windows Server 2022 23H2 OpenSSH file inclusion
CVE-2024-38097 | Microsoft Azure Monitor Agent link following
CVE-2024-43481 | Microsoft Power BI Report Server cross site scripting
CVE-2024-43528 | Microsoft Windows up to Server 2022 23H2 Secure Kernel Mode heap-based overflow
CVE-2024-43532 | Microsoft Windows up to Server 2022 23H2 Remote Registry Service failing open
MongoDB Queryable Encryption now supports range queries on encrypted data
MongoDB Queryable Encryption allows customers to securely encrypt sensitive application data and store it in an encrypted format within the MongoDB database. It also enables direct equality and range queries on the encrypted data without the need for cryptographic expertise. Adding range query support expands data retrieval options, allowing for more powerful search capabilities. You can configure Queryable Encryption using the following methods: Automatic encryption: Allows encrypted read and write operations to be performed seamlessly, … More →
The post MongoDB Queryable Encryption now supports range queries on encrypted data appeared first on Help Net Security.
腾讯微信使用的 MMTLS 加密协议存在安全弱点
CVE-2014-7748 | Garip Ve Ilginc Olaylar 0.1 X.509 Certificate cryptographic issues (VU#582497)
Непоколебимый: история инженера, 11 лет штурмующего свалку ради биткоинов
云上规模化的威胁检测与防护 | FCIS 2024议题前瞻
CVE-2024-10068 | OpenSight Software FlashFXP 5.4.0.3970 FlashFXP.exe uncontrolled search path
Google: 70% of exploited flaws disclosed in 2023 were zero-days
Submit #419684: OpenSight Software LLC FlashFXP 5.4.0.3970 DLL Hijacking [Accepted]
高收入的低稳定性
Organization Hacked Following Accidental Hiring of North Korean Remote IT Worker
A company has fallen victim to a cyberattack after unknowingly hiring a North Korean cybercriminal as a remote IT worker. The unidentified firm, based in the UK, US, or Australia, discovered the breach after the hacker downloaded sensitive data and issued a ransom demand. The incident highlights the growing threat of North Korean operatives infiltrating […]
The post Organization Hacked Following Accidental Hiring of North Korean Remote IT Worker appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.