Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Chrome Browser Bug Under Active Attack – Update your chrome now
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Chrome Browser Bug Under Active Attack – Update your chrome nowPost Views: 56
Reading Time: 1 Minute
Google is warning that a bug in its Chrome web browser is actively under attack, and it is urging users to upgrade to the latest 91.0.4472.101 version to mitigate the issue.
In all, Google rolled out fixes for 14 bugs impacting its Windows, Mac and Linux browsers as part of its June update to the Chrome desktop browser.
“Google is aware that an exploit for CVE-2021-30551 exists in the wild,” wrote Chrome technical program manager Prudhvikumar Bommana in a Wednesday post. That exploit is identified as a type confusion bug within Google’s V8 open-source JavaScript and WebAssembly engine.
The confusion vulnerability is tied to the browser’s ActionScript Virtual Machine. “Usually, when a piece of code doesn’t verify the type of object that is passed to it, and uses it blindly without type-checking, it leads to type confusion,” according to a technical description of the bug. Possible Wider Impact of Exploited Chrome Browser BugThe update coincides with the release of the Android Chrome browser to Chrome 91 (91.0.4472.101), also on Wednesday. While the desktop and mobile versions of the Chrome web browser share the same version number, it is unclear if the updated Android Chrome browser is impacted by the same vulnerabilities.
Also unclear is if Microsoft’s Edge browser, based on the Chromium open-source browser codebase (principally developed and maintained by Google), is also impacted.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries In related news, on Tuesday, Microsoft released a patch for vulnerabilities under active attack, including CVE-2021-33742, impacting its Edge browser. That bug is a remote-code execution (RCE) vulnerability within the Edge browser’s MSHTML component.
“The MSHTML platform is used by Internet Explorer mode in Microsoft Edge as well as other applications through WebBrowser control,” Microsoft explained. Critical Browser Cache Bug: CVE-2021-30544As part of the June Chrome update, Google patched a critical use-after-free bug (CVE-2021-30544) within the browser’s optimization engine called BFCache. This browser component enables back-and-forward navigation between cached webpages within Chrome.
As customary with recently disclosed bugs, Google did not release the details tied to any of the vulnerabilities patched Wednesday. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third-party library that other projects similarly depend on, but haven’t yet fixed,” the Google advisory stated.
See Also: Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework Google credits Rong Jian and Guang Gong of 360 Alpha Lab for finding the BFCache bug in May. For their bug hunting efforts, the pair earned $25,000. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-1-90x90.png Intel Plugs 29 Holes in CPUs, Bluetooth, Security1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/vtornik-patchej-Microsoft-90x90.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-de[...]
Chrome Browser Bug Under Active Attack – Update your chrome now
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Chrome Browser Bug Under Active Attack – Update your chrome nowPost Views: 56
Reading Time: 1 Minute
Google is warning that a bug in its Chrome web browser is actively under attack, and it is urging users to upgrade to the latest 91.0.4472.101 version to mitigate the issue.
In all, Google rolled out fixes for 14 bugs impacting its Windows, Mac and Linux browsers as part of its June update to the Chrome desktop browser.
“Google is aware that an exploit for CVE-2021-30551 exists in the wild,” wrote Chrome technical program manager Prudhvikumar Bommana in a Wednesday post. That exploit is identified as a type confusion bug within Google’s V8 open-source JavaScript and WebAssembly engine.
The confusion vulnerability is tied to the browser’s ActionScript Virtual Machine. “Usually, when a piece of code doesn’t verify the type of object that is passed to it, and uses it blindly without type-checking, it leads to type confusion,” according to a technical description of the bug. Possible Wider Impact of Exploited Chrome Browser BugThe update coincides with the release of the Android Chrome browser to Chrome 91 (91.0.4472.101), also on Wednesday. While the desktop and mobile versions of the Chrome web browser share the same version number, it is unclear if the updated Android Chrome browser is impacted by the same vulnerabilities.
Also unclear is if Microsoft’s Edge browser, based on the Chromium open-source browser codebase (principally developed and maintained by Google), is also impacted.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries In related news, on Tuesday, Microsoft released a patch for vulnerabilities under active attack, including CVE-2021-33742, impacting its Edge browser. That bug is a remote-code execution (RCE) vulnerability within the Edge browser’s MSHTML component.
“The MSHTML platform is used by Internet Explorer mode in Microsoft Edge as well as other applications through WebBrowser control,” Microsoft explained. Critical Browser Cache Bug: CVE-2021-30544As part of the June Chrome update, Google patched a critical use-after-free bug (CVE-2021-30544) within the browser’s optimization engine called BFCache. This browser component enables back-and-forward navigation between cached webpages within Chrome.
As customary with recently disclosed bugs, Google did not release the details tied to any of the vulnerabilities patched Wednesday. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third-party library that other projects similarly depend on, but haven’t yet fixed,” the Google advisory stated.
See Also: Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework Google credits Rong Jian and Guang Gong of 360 Alpha Lab for finding the BFCache bug in May. For their bug hunting efforts, the pair earned $25,000. See Also: Jeff Moss, aka Dark Tangent, the person who founded DEF CON and Black Hat Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-1-90x90.png Intel Plugs 29 Holes in CPUs, Bluetooth, Security1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/vtornik-patchej-Microsoft-90x90.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-de[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Chrome Browser Bug Under Active Attack – Update your chrome now https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Chrome Browser Bug Under Active Attack – Update your chrome nowPost…
sign-1-1-90x90.png RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/microsoft-exploit-90x90.jpg Windows Container Malware Targets Kubernetes Clusters3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1_6QWMn0DApM4jmbubKuCmNA-90x90.png GitHub’s new policies allow removal of PoC exploits used in attacks4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-90x90.png Google PPC Ads Used to Deliver Infostealers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-90x90.png Researchers Uncover Hacking Operations Targeting Government Entities in South Korea1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ransomware-payment-90x90.jpg Cyber-Insurance Fuels Ransomware Payment Surge1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/banner-2021.2-release-90x90.png Kali Linux 2021.2 Release (Kaboxer, Kali-Tweaks, Bleeding-Edge & Privileged Ports)1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif.com-gif-maker-90x90.jpg Cyber attack hits JBS meat works in Australia, North America1 week ago
The post Chrome Browser Bug Under Active Attack – Update your chrome now first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/microsoft-exploit-90x90.jpg Windows Container Malware Targets Kubernetes Clusters3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/1_6QWMn0DApM4jmbubKuCmNA-90x90.png GitHub’s new policies allow removal of PoC exploits used in attacks4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-2-90x90.png Google PPC Ads Used to Deliver Infostealers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/Untitled-design-1-90x90.png Researchers Uncover Hacking Operations Targeting Government Entities in South Korea1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ransomware-payment-90x90.jpg Cyber-Insurance Fuels Ransomware Payment Surge1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/banner-2021.2-release-90x90.png Kali Linux 2021.2 Release (Kaboxer, Kali-Tweaks, Bleeding-Edge & Privileged Ports)1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/06/ezgif.com-gif-maker-90x90.jpg Cyber attack hits JBS meat works in Australia, North America1 week ago
The post Chrome Browser Bug Under Active Attack – Update your chrome now first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
Sensitive Data Exposure on renowned Airline Company
Hello Folks 👋,Continue reading on Medium »
Read more...
Hello Folks 👋,Continue reading on Medium »
Read more...
Sensitive Data Exposure on renowned Airline Company
https://0xparth.medium.com/sensitive-data-exposure-on-renowned-airline-company-821eb4408144?source=rss------bug_bounty-5
https://0xparth.medium.com/sensitive-data-exposure-on-renowned-airline-company-821eb4408144?source=rss------bug_bounty-5
Hello Folks 👋,Continue reading on Medium » (https://0xparth.medium.com/sensitive-data-exposure-on-renowned-airline-company-821eb4408144?source=rss------bug_bounty-5)
Host Header Attack : Open Redirection
https://0xparth.medium.com/host-header-attack-open-redirection-ae92e8493d8c?source=rss------bug_bounty-5
https://0xparth.medium.com/host-header-attack-open-redirection-ae92e8493d8c?source=rss------bug_bounty-5
Hello Folks 👋,Continue reading on Medium » (https://0xparth.medium.com/host-header-attack-open-redirection-ae92e8493d8c?source=rss------bug_bounty-5)
Pentesting a Crypto Exchange for fun and profit
https://farjaalahmad.medium.com/pentesting-a-crypto-exchange-for-fun-and-profit-921af5ebac39?source=rss------bug_bounty-5
https://farjaalahmad.medium.com/pentesting-a-crypto-exchange-for-fun-and-profit-921af5ebac39?source=rss------bug_bounty-5
Hey guys, it’s been a long time since I published my first write-up. In my last write-up, I mentioned multiple vulnerabilities regarding a…Continue reading on Medium » (https://farjaalahmad.medium.com/pentesting-a-crypto-exchange-for-fun-and-profit-921af5ebac39?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Pentesting a Crypto Exchange for fun and profit
Hey guys, it’s been a long time since I published my first write-up. In my last write-up, I mentioned multiple vulnerabilities regarding a…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Why do Hackers Target the Gaming Industry?
https://cdn-images-1.medium.com/max/2600/1*nC0b2tOghBKuCxjgTxyVjA.jpeg
Hacking in the games industry is not rare. It is an industry that has been growing exponentially for many years. This growth means much…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Why do Hackers Target the Gaming Industry?
https://cdn-images-1.medium.com/max/2600/1*nC0b2tOghBKuCxjgTxyVjA.jpeg
Hacking in the games industry is not rare. It is an industry that has been growing exponentially for many years. This growth means much…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Why do Hackers Target the Gaming Industry?
Hacking in the games industry is not rare. It is an industry that has been growing exponentially for many years. This growth means much…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Host Header Attack : Open Redirection
https://cdn-images-1.medium.com/max/600/1*GwGdOiGaiPIFovIty8HtBQ.jpeg
Hello Folks 👋,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Host Header Attack : Open Redirection
https://cdn-images-1.medium.com/max/600/1*GwGdOiGaiPIFovIty8HtBQ.jpeg
Hello Folks 👋,
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Host Header Attack : Open Redirection
Hello Folks 👋,
Immunity Canvas
https://www.reddit.com/r/Pentesting/comments/nxbpmh/immunity_canvas/
Guys, Someone Please guide me on how to install Immunity Canvas. If you have cracked one please give me a link submitted by /u/SecSolutions_16 (https://www.reddit.com/user/SecSolutions_16)
[link] (https://www.reddit.com/r/Pentesting/comments/nxbpmh/immunity_canvas/) [comments] (https://www.reddit.com/r/Pentesting/comments/nxbpmh/immunity_canvas/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/nxbpmh/immunity_canvas/
Guys, Someone Please guide me on how to install Immunity Canvas. If you have cracked one please give me a link submitted by /u/SecSolutions_16 (https://www.reddit.com/user/SecSolutions_16)
[link] (https://www.reddit.com/r/Pentesting/comments/nxbpmh/immunity_canvas/) [comments] (https://www.reddit.com/r/Pentesting/comments/nxbpmh/immunity_canvas/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Immunity Canvas
Guys, Someone Please guide me on how to install Immunity Canvas. If you have cracked one please give me a link
Pentesting a Crypto Exchange for fun and profit
Hey guys, it’s been a long time since I published my first write-up. In my last write-up, I mentioned multiple vulnerabilities regarding a…Continue reading on Medium »
Read more...
Hey guys, it’s been a long time since I published my first write-up. In my last write-up, I mentioned multiple vulnerabilities regarding a…Continue reading on Medium »
Read more...
hacking: security in practice
WhatsApp
Is hacking someone’s WhatsApp possible?
submitted by /u/icannotthinkit
[link] [comments]
Is hacking someone’s WhatsApp possible?
submitted by /u/icannotthinkit
[link] [comments]
reddit
WhatsApp
Is hacking someone’s WhatsApp possible?
hacking: security in practice
How is it possible?
So here is the thing, there is an web application which is prone to scripting, its architecture is based of scripting. How is it possible that one can disable anything present on web application by getting the targets ID, which is hidden but you you find of the target via a short python script, then send a remote command to the servers from there the automated bots will disable the target. Whether its an account, post or a community. How is it possible?
submitted by /u/Mr-Invincible3
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How is it possible?
So here is the thing, there is an web application which is prone to scripting, its architecture is based of scripting. How is it possible that one can disable anything present on web application by getting the targets ID, which is hidden but you you find of the target via a short python script, then send a remote command to the servers from there the automated bots will disable the target. Whether its an account, post or a community. How is it possible?
submitted by /u/Mr-Invincible3
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How is it possible?
So here is the thing, there is an web application which is prone to scripting, its architecture is based of scripting. How is it possible that one...