Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
14 résultats taggé disclosure  ✕
Micropatches released for SCF File NTLM Hash Disclosure Vulnerability (0day) https://blog.0patch.com/2025/03/scf-file-ntlm-hash-disclosure.html
27/03/2025 08:14:25
QRCode
archive.org
thumbnail

    While patching a SCF File NTLM hash disclosure issue on our security-adopted Windows versions, our researchers discovered a related v...

0patch EN 2025 SCF File NTLM hash disclosure
Jetpack fixes critical information disclosure flaw existing since 2016 https://www.bleepingcomputer.com/news/security/jetpack-fixes-critical-information-disclosure-flaw-existing-since-2016/
16/10/2024 20:47:05
QRCode
archive.org
thumbnail

WordPress plugin Jetpack released a critical security update earlier today, addressing a vulnerability that allowed a logged-in user to access forms submitted by other visitors to the site.

bleepingcomputer 2024 EN Information Security Vulnerability WordPress Computer InfoSec Plugin Disclosure Jetpack
Microsoft Copilot Studio Vulnerability Led to Information Disclosure https://www.securityweek.com/microsoft-copilot-studio-vulnerability-led-to-information-disclosure/
24/08/2024 12:38:26
QRCode
archive.org

A vulnerability in Microsoft Copilot Studio could be exploited to access sensitive information on the internal infrastructure used by the service, Tenable reports.

The flaw, tracked as CVE-2024-38206 (CVSS score of 8.5) and described as a ‘critical’ information disclosure bug, has been fully mitigated, Microsoft said in an August 6 advisory.

securityweek EN 2024 Microsoft Copilot Studio Vulnerability information disclosure bug CVE-2024-38206
Israel Maneuvered to Prevent Disclosure of State Secrets amid WhatsApp vs NSO Lawsuit - Forbidden Stories https://forbiddenstories.org/actualites_posts/israel-maneuvered-to-prevent-disclosure-of-state-secrets-amid-whatsapp-vs-nso-lawsuit/?ref=news.risky.biz
26/07/2024 08:18:38
QRCode
archive.org
thumbnail

Documents reveal how Israel seized files, suppressed information related to WhatsApp’s lawsuit against Pegasus spyware vendor NSO

  • Amid a lawsuit pitting WhatsApp against the Israeli company NSO, the state of Israel ordered documents to be seized from the offices of the Pegasus spyware vendor
  • Israel also emitted a gag order on the seizure to prevent further dissemination of the information
  • Leaked files from the Israeli Ministry of Justice accessed by Forbidden Stories suggest that the MoJ pushed for language in NSO court filings to be modified
forbiddenstories EN 2024 lawsuit WhatsApp NSO Pegasus Israel Disclosure
Uncoordinated Vulnerability Disclosure: The Continuing Issues with CVD https://www.zerodayinitiative.com/blog/2024/7/15/uncoordinated-vulnerability-disclosure-the-continuing-issues-with-cvd
16/07/2024 21:51:28
QRCode
archive.org
thumbnail

On patch Tuesday last week, Microsoft released an update for CVE-2024-38112, which they said was being exploited in the wild. We at the Trend Micro Zero Day Initiative (ZDI) agree with them because that’s what we told them back in May when we detected this exploit in the wild and reported it to Microsoft. However, you may notice that no one from Trend or ZDI was acknowledged by Microsoft. This case has become a microcosm of the problems with coordinated vulnerability disclosure (CVD) as vendors push for coordinated disclosure from researchers but rarely practice any coordination regarding the fix. This lack of transparency from vendors often leaves researchers who practice CVD with more questions than answers.

zerodayinitiative EN 2024 CVE-2024-38112 Microsoft CVD transparency disclosure
D-Link D-View 8 Unauthenticated Probe-Core Server Communication https://www.tenable.com/security/research/tra-2023-43
03/01/2024 12:31:36
QRCode
archive.org

A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclosure of info

tenable EN 2023 D-Link D-View vulnerability disclosure
Amazon’s Q has ‘severe hallucinations’ and leaks confidential data in public preview, employees warn https://www.platformer.news/p/amazons-q-has-severe-hallucinations?r=2d5oq
02/12/2023 11:39:50
QRCode
archive.org

Some hallucinations could ‘potentially induce cardiac incidents in Legal,’ according to internal documents

platformer EN 2023 AI Amazon Legal Q hallucinations confidential disclosure
The Ticking Supply Chain Attack Bomb of Exposed Kubernetes Secrets https://blog.aquasec.com/the-ticking-supply-chain-attack-bomb-of-exposed-kubernetes-secrets
24/11/2023 12:16:29
QRCode
archive.org
thumbnail

Aqua Nautilus researchers found exposed Kubernetes secrets that pose a critical threat of supply chain attack to hundreds of organizations and OSS.

aquasec EN 2023 secrets Kubernetes disclosure Supply-chain-attack
SysAid On-Prem Software CVE-2023-47246 Vulnerability Disclosure https://profero.io/posts/sysaidonpremvulnerability/
10/11/2023 08:45:17
QRCode
archive.org

On Nov 2nd, our security team received reports regarding a potential vulnerability in our on-premise software which was being actively exploited. We immediately initiated our incident response protocol and began proactively communicating with our on-premise customers to ensure they could implement a mitigation solution we had identified. We engaged Profero, a cyber security incident response company, to assist us in our investigation. The investigation determined that there was a zero-day vulnerability in the SysAid on-premises software. We urge all customers with SysAid on-prem server installations to ensure that your SysAid systems are updated to version 23.3.36, which remediates the identified vulnerability, and conduct a comprehensive compromise assessment of your network to look for any indicators further discussed below. Should you identify any indicators, take immediate action and follow your incident response protocols.

profero EN 2023 CVE-2023-47246 disclosure vulnerability SysAid
How China Demands Tech Firms Reveal Hackable Flaws in Their Products https://www.wired.com/story/china-vulnerability-disclosure-law/
07/09/2023 20:53:58
QRCode
archive.org
thumbnail

Some foreign companies may be complying—potentially offering China’s spies hints for hacking their customers.

wired EN 2023 China Reveal Hackable Flaws disclosure product disclosure-law
Remote Code Execution Vulnerability in Google They Are Not Willing To Fix https://giraffesecurity.dev/posts/google-remote-code-execution/
16/04/2023 22:03:00
QRCode
archive.org

This is a story about a security vulnerability in Google that allowed me to run arbitrary code on the computers of 50+ Google employees. Although Google initially considered my finding a serious security incident, later on, it changed its mind and stated that my finding is not, in fact, a vulnerability, but the intended behavior of their software.

giraffesecurity EN 2023 vulnerability disclosure Google RCE intended
CVD, EU-DSGVO and revDSG - A personal responsible disclosure experience of a data breach in the Swiss cyber landscape in 2022/23 https://andreaskuster.ch/blog/2023/CVD-Swiss-Cyber/?s=09
12/02/2023 14:52:38
QRCode
archive.org

n late November 2022, a few days after ETH Alumni launched their new feature “Who is who” which allows them to look up and connect to other members, I came across a severe access control vulnerability. Without any authorization over the internet, it allowed extracting at least 35418 member profiles, including full name, postal address, nationality, title, graduation field, study start year, gender, profile picture and hashed passwords.

andreaskuster EN 2023 ETHZ Zurich bugbounty blog vulnerability disclosure CH
Microsoft Office 365 Message Encryption Insecure Mode of Operation | WithSecure™ Labs https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation
14/10/2022 16:11:00
QRCode
archive.org
thumbnail

Microsoft Office 365 Message Encryption (OME) utilitises Electronic Codebook (ECB) mode of operation. This mode is insecure and leaks information about the structure of the messages sent and can lead to partial or full message disclosure.

withsecure EN 2022 Security-advisory 365 office365 leak Encryption ECB disclosure
Zimbra Open Bucket Data Leak – Responsible Disclosure https://members.backbox.org/zimbra-open-bucket-data-leak-responsible-disclosure/
31/08/2022 10:14:16
QRCode
archive.org

Hundreds of millions use Zimbra, an all-in-one business productivity suite for micro, small, medium & enterprise in-office and remote work teams. The Zimbra Inc company was acquired by Synacor Inc

backbox EN 2022 Leak Zimbra Disclosure Bucket
4368 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio