Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 6 / 13
257 résultats taggé vulnerability  ✕
Critical Exim bug bypasses security filters on 1.5 million mail servers https://www.bleepingcomputer.com/news/security/critical-exim-bug-bypasses-security-filters-on-15-million-mail-servers/
13/07/2024 00:38:28
QRCode
archive.org
thumbnail

Censys warns that over 1.5 million Exim mail transfer agent (MTA) instances are unpatched against a critical vulnerability that lets threat actors bypass security filters.

bleepingcomputer EN 2024 Bypass Email Exim Mail Security-Bypass Vulnerability
Patch or Peril: A Veeam vulnerability incident https://www.group-ib.com/blog/estate-ransomware/
12/07/2024 22:21:57
QRCode
archive.org

Delaying security updates and neglecting regular reviews created vulnerabilities that were exploited by attackers, resulting in severe ransomware consequences.

  • Initial access via FortiGate Firewall SSL VPN using a dormant account
  • Deployed persistent backdoor (“svchost.exe”) on the failover server, and conducted lateral movement via RDP.
  • Exploitation attempts of CVE-2023-27532 was followed by activation of xp_cmdshell and rogue user account creation.
  • Threat actors made use of NetScan, AdFind, and various tools provided by NirSoft to conduct network discovery, enumeration, and credential harvesting.
  • Windows Defender was permanently disabled using DC.exe, followed by ransomware deployment and execution with PsExec.exe.
group-ib EN 2024 Veeam vulnerability incident ransomware FortiGate NirSoft
New Blast-RADIUS attack breaks 30-year-old protocol used in networks everywhere https://arstechnica.com/security/2024/07/new-blast-radius-attack-breaks-30-year-old-protocol-used-in-networks-everywhere/
10/07/2024 17:36:32
QRCode
archive.org
thumbnail

Ubiquitous RADIUS scheme uses homegrown authentication based on MD5. Yup, you heard right.

arstechnica EN 2024 blastradius RADIUS vulnerability
BLAST RADIUS https://www.blastradius.fail/#page-top
10/07/2024 17:33:48
QRCode
archive.org

Blast-RADIUS is a vulnerability that affects the RADIUS protocol. RADIUS is a very common protocol used for authentication, authorization, and accounting (AAA) for networked devices on enterprise and telecommunication networks.

blastradius EN 2024 RADIUS vulnerability protocol
CVE-2024-38021: Moniker RCE Vulnerability Uncovered in Microsoft Outlook https://blog.morphisec.com/cve-2024-38021-microsoft-outlook-moniker-rce-vulnerability
10/07/2024 08:42:17
QRCode
archive.org
thumbnail

Morphisec researchers have discovered an important Microsoft Outlook vulnerability. Read on for CVE-2024- 38021 details and technical impact.

morphisec EN 2024 CVE-2024-38021Microsoft Outlook vulnerability July2024-PatchTuesday
Hackers target WordPress calendar plugin used by 150,000 sites https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-calendar-plugin-used-by-150-000-sites/
09/07/2024 19:42:11
QRCode
archive.org
thumbnail

Hackers are trying to exploit a vulnerability in the Modern Events Calendar WordPress plugin that is present on more than 150,000 websites to upload arbitrary files to a vulnerable site and execute code remotely.
#Actively #Calendar #Computer #Events #Exploited #File #InfoSec #Modern #Plugin #Security #Upload #Vulnerability #WordPress

Plugin Calendar Events Vulnerability File InfoSec Actively WordPress Security Upload Exploited Modern Computer
New Intel CPU Vulnerability 'Indirector' Exposes Sensitive Data https://thehackernews.com/2024/07/new-intel-cpu-vulnerability-indirector.html
07/07/2024 22:04:14
QRCode
archive.org
thumbnail

Discover how the 'Indirector' attack threatens Intel CPUs and learn about the 'TIKTAG' vulnerability in Arm processors.

thehackernews EN 2024 Indicator Intel CPU Vulnerability
RoguePuppet – A Critical Puppet Forge Supply Chain Vulnerability https://adnanthekhan.com/2024/07/02/roguepuppet-a-critical-puppet-forge-supply-chain-vulnerability/
05/07/2024 10:16:03
QRCode
archive.org
thumbnail

What if there was a supply chain attack that could provide an attacker with direct access to core infrastructure within thousands of companies worldwide. What if that attack required no social engi…

adnanthekhan EN 2024 Critical Puppet Forge Vulnerability Supply-Chain-Attack
Critical GitLab bug lets attackers run pipelines as any user https://www.bleepingcomputer.com/news/security/critical-gitlab-bug-lets-attackers-run-pipelines-as-any-user/
27/06/2024 17:23:35
QRCode
archive.org
thumbnail

A critical vulnerability is affecting certain versions of GitLab Community and Enterprise Edition products, which could be exploited to run pipelines as any user.

bleepingcomputer EN 2024 GitLab Pipeline Security-Advisory Vulnerability
Critical SQLi Vulnerability Found in Fortra FileCatalyst Workflow Application https://thehackernews.com/2024/06/critical-sqli-vulnerability-found-in.html
27/06/2024 09:58:20
QRCode
archive.org
thumbnail

Critical security flaw in Fortra FileCatalyst Workflow allows database tampering. Patch available.

thehackernews EN 2024 Critical SQLi Vulnerability Fortra FileCatalyst Workflow Application CVE-2024-5276
UEFIcanhazbufferoverflow: Widespread Impact from Vulnerability in Popular PC and Server Firmware https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/
26/06/2024 13:51:38
QRCode
archive.org
thumbnail

Summary Eclypsium Automata, our automated binary analysis system, has identified a high impact vulnerability (CVE-2024-0762 with a reported CVSS of 7.5) in the Phoenix SecureCore UEFI firmware that runs on multiple families of Intel Core desktop and mobile processors. The issue involves an unsafe variable in the Trusted Platform Module (TPM) configuration that could lead […]

eclypsium.com EN 2024 UEFIcanhazbufferoverflow Vulnerability Phoenix CVE-2024-0762 SecureCore UEFI
Facebook PrestaShop module exploited to steal credit cards https://www.bleepingcomputer.com/news/security/facebook-prestashop-module-exploited-to-steal-credit-cards/
24/06/2024 11:26:54
QRCode
archive.org
thumbnail

Hackers are exploiting a flaw in a premium Facebook module for PrestaShop named pkfacebook to deploy a card skimmer on vulnerable e-commerce sites and steal people's payment credit card details.

bleepingcomputer EN 2024 E-Commerce Prestashop SQL-Injection Vulnerability Website
Zero-Click Critical Microsoft Outlook Vulnerability. What You Need to Know. https://ironscales.com/blog/zero-click-critical-microsoft-outlook-vulnerability.-what-you-need-to-know
19/06/2024 23:33:35
QRCode
archive.org
thumbnail

Critical Microsoft Outlook vulnerability, CVE-2024-30103, and step-by-step instructions to force an update to all your end points.

ironscales EN 2024 CVE-2024-30103 Microsoft Outlook vulnerability
Arm Warns of Actively Exploited Zero-Day Vulnerability in Mali GPU Drivers https://thehackernews.com/2024/06/arm-warns-of-actively-exploited-zero.html
16/06/2024 00:13:01
QRCode
archive.org
thumbnail

Arm discloses a critical vulnerability (CVE-2024-4610) in Mali GPU Kernel Drivers. This flaw, actively exploited, affects versions from r34p0 to r40p0

thehackernews EN 2024 ARM CVE-2024-4610 Mali GPU Kernel Drivers ero-Day Vulnerability
Black Basta ransomware gang linked to Windows zero-day attacks https://www.bleepingcomputer.com/news/security/black-basta-ransomware-gang-linked-to-windows-zero-day-attacks/
16/06/2024 00:11:34
QRCode
archive.org
thumbnail

The Cardinal cybercrime group (Storm-1811, UNC4394), who are the main operators of the Black Basta ransomware, is suspected of exploiting a Windows privilege escalation vulnerability, CVE-2024-26169, before a fix was made available.

bleepingcomputer en 2024 Actively-Exploited Black-Basta Ransomware Vulnerability Zero-Day CVE-2024-26169
Microsoft June 2024 Patch Tuesday fixes 51 flaws, 18 RCEs https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2024-patch-tuesday-fixes-51-flaws-18-rces/
11/06/2024 19:47:40
QRCode
archive.org
thumbnail

Today is Microsoft's June 2024 Patch Tuesday, which includes security updates for 51 flaws, eighteen remote code execution flaws, and one publicly disclosed zero-day vulnerability.
#Microsoft #Patch #Security #Tuesday #Update #Vulnerability #Windows

Vulnerability Windows Patch Security Tuesday Microsoft Update
Vulnerability in Cisco Webex cloud service exposed government authorities, companies https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/
05/06/2024 22:46:17
QRCode
archive.org
thumbnail

A previously discovered vulnerability affecting self-hosted Cisco Webex instances similarly affected the Webex cloud service.

helpnetsecurity EN 2024 Vulnerability Cisco Webex cloud service exposed government
NIST Getting Outside Help for National Vulnerability Database https://www.securityweek.com/nist-getting-outside-help-for-national-vulnerability-database/
01/06/2024 14:04:01
QRCode
archive.org

NIST announced on Wednesday that it will be receiving outside help to get the National Vulnerability Database (NVD) back on track within the next few months.

The organization informed the cybersecurity community in February that it should expect delays in the analysis of Common Vulnerabilities and Exposures (CVE) identifiers in the NVD, saying that it was working to establish a consortium to improve the program.

securityweek EN 2024 NIST CVE National Vulnerability Database NVD
Zero Day Initiative — CVE-2024-30043: Abusing URL Parsing Confusion to Exploit XXE on SharePoint Server and Cloud https://www.zerodayinitiative.com/blog/2024/5/29/cve-2024-30043-abusing-url-parsing-confusion-to-exploit-xxe-on-sharepoint-server-and-cloud#/
31/05/2024 09:47:53
QRCode
archive.org
thumbnail

Yes, the title is right. This blog covers an XML eXternal Entity (XXE) injection vulnerability that I found in SharePoint. The bug was recently patched by Microsoft. In general, XXE vulnerabilities are not very exciting in terms of discovery and related technical aspects. They may sometimes be fun t

zerodayinitiative EN 2024 SharePoint XML eXternal vulnerability CVE-2024-30043
Researchers Uncover Active Exploitation of WordPress Plugin Vulnerabilities https://thehackernews.com/2024/05/researchers-uncover-active-exploitation.html?m=1
30/05/2024 16:30:28
QRCode
archive.org

Researchers have discovered several vulnerabilities in popular WordPress plugins that allow attackers to create rogue admin accounts.
#attacks #breach #computer #cyber #data #hack #hacker #hacking #how #information #malware #network #news #ransomware #security #software #the #to #today #updates #vulnerability

thehackernews EN 2024 WordPress Plugin Vulnerabilities
page 6 / 13
4888 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn