β Crimeware server used by NetWalker ransomware seized and shut down β
π Read
via "Naked Security".
The site was running from 2014 and allegedly raked in more than $20m, which the DOJ is seeking to claw back...π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News
π’ Stealthy Kerberoasting attacks surge and lend support to latest ransomware trend π’
π Read
via "ITPro".
Kerberoasting techniques could be emerging as a viable alternative to traditional ransomware attacks, experts have warned π Read
via "ITPro".
ITPro
Stealthy Kerberoasting attacks surge and lend support to latest ransomware trend
Kerberoasting techniques could be emerging as a viable alternative to traditional ransomware attacks, experts have warned
π΄ Following Pushback, Zoom Says It Won't Use Customer Data to Train AI Models π΄
π Read
via "Dark Reading".
Company's experience highlights the tightrope tech organizations walk when integrating AI into their products and services.π Read
via "Dark Reading".
Dark Reading
Following Pushback, Zoom Says It Won't Use Customer Data to Train AI Models
Company's experience highlights the tightrope tech organizations walk when integrating AI into their products and services.
βΌ CVE-2023-30749 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ihomefinder Optima Express + MarketBoost IDX Plugin plugin <=Γ 7.3.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30483 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <=Γ 3.3.9.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29097 βΌ
π Read
via "National Vulnerability Database".
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in a3rev Software a3 Portfolio plugin <=Γ 3.1.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30475 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP WooCommerce Affiliate Plugin Γ’β¬β Coupon Affiliates plugin <=Γ 5.4.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31041 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30754 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly Γ’β¬β Ad Manager, AdSense Ads & Ads.Txt plugin <=Γ 1.8.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30751 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in iControlWP Article Directory Redux plugin <=Γ 1.0.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30752 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Silvia Pfeiffer and Andrew Nimmo External Videos plugin <=Γ 2.0.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30477 βΌ
π Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Essitco AFFILIATE Solution plugin <=Γ 1.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28535 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <=Γ 2.2.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30489 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <=Γ 1.2.16 versions.π Read
via "National Vulnerability Database".
π΄ Health Data of 4M Stolen in Cl0p MOVEit Breach of Colorado Department π΄
π Read
via "Dark Reading".
State's Department of Health Care Policy & Financing is the latest to acknowledge an attack by the Russian group's ongoing exploitation of third-party systems.π Read
via "Dark Reading".
Dark Reading
Health Data of 4M Stolen in Cl0p MOVEit Breach of Colorado Department
State's Department of Health Care Policy & Financing is the latest to acknowledge an attack by the Russian group's ongoing exploitation of third-party systems.
π jSQL Injection 0.91 π
π Read
via "Packet Storm Security".
jSQL Injection is a lightweight application used to find database information from a distant server. jSQL Injection is also part of the official penetration testing distribution Kali Linux and is included in various other distributions like Pentest Box, Parrot Security OS, ArchStrike and BlackArch Linux. This is the source code release.π Read
via "Packet Storm Security".
Packetstormsecurity
jSQL Injection 0.91 β Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
βΌ CVE-2023-40359 βΌ
π Read
via "National Vulnerability Database".
xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue.π Read
via "National Vulnerability Database".
βΌ CVE-2023-28768 βΌ
π Read
via "National Vulnerability Database".
Improper frame handling in the Zyxel XGS2220-30 firmware version V4.80(ABXN.1), XMG1930-30 firmware version V4.80(ACAR.1), and XS1930-10 firmware versionΓ V4.80(ABQE.1) could allow an unauthenticated LAN-based attacker to cause denial-of-service (DoS) conditions by sending crafted frames to an affected switch.π Read
via "National Vulnerability Database".
βΌ CVE-2023-33013 βΌ
π Read
via "National Vulnerability Database".
A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.π Read
via "National Vulnerability Database".
βΌ CVE-2023-40354 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are 2.5.28, 6.4.9, 22.08.8, and 23.02.3.π Read
via "National Vulnerability Database".
βΌ CVE-2023-4322 βΌ
π Read
via "National Vulnerability Database".
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.π Read
via "National Vulnerability Database".