Cyberveille
curated by Decio
Nuage de tags
Mur d'images
Quotidien
Rechercher
Flux RSS
Flux RSS
Daily Feed
Weekly Feed
Monthly Feed
tags
search
Blog: Zen and the Art of Microcode Hacking
CVE-2022-31631: High-Risk PHP Vulnerability Demands Immediate Patch
Active Directory Domain Services Elevation of Privilege Vulnerability (CVE-2025-21293)
PoC Exploit Released for macOS Kernel Vulnerability CVE-2025-24118 (CVSS 9.8)
Live Chat Blog #2: Cisco Webex Connect - Access to millions of chats histories
Government and university websites targeted in ScriptAPI[.]dev client-side attack - c/side
Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344
Microsoft: macOS bug lets hackers install malicious kernel drivers
Industrial networking manufacturer Moxa reports 'critical' router bugs
SonicWall urges admins to patch exploitable SSLVPN bug immediately
BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA
zizmor would have caught the Ultralytics workflow vulnerability
CVE-2024-1212: Unauthenticated Command Injection In Progress Kemp LoadMaster - Rhino Security Labs
Windows Server 2012 Mark of the Web Vulnerability (0day) - and Free Micropatches for it
7-Zip flaw enables code smuggling with manipulated archives
Exploit attempts for unpatched Citrix vulnerability
Zero-Click Flaw Exposes Potentially Millions of Popular Storage Devices to Attack
Attacker Abuses Victim Resources to Reap Rewards from Titan Network
Hackers exploit Roundcube webmail flaw to steal email, credentials
Jetpack fixes critical information disclosure flaw existing since 2016
Critical flaw in NVIDIA Container Toolkit allows full host takeover
Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments | Wiz Blog
Progress LoadMaster vulnerable to 10/10 severity RCE flaw
D-Link says it is not fixing four RCE flaws in DIR-846W routers
Veeam warns of critical RCE flaw in Backup & Replication software
The gift that keeps on giving: A new opportunistic Log4j campaign
Windows driver zero-day exploited by Lazarus hackers to install rootkit
SolarWinds fixes critical RCE bug affecting all Web Help Desk versions
Critical SAP flaw allows remote attackers to bypass authentication
Compromising Microsoft's AI Healthcare Chatbot Service
New AMD SinkClose flaw helps install nearly undetectable malware
‘Sinkclose’ Flaw in Hundreds of Millions of AMD Chips Allows Deep, Virtually Unfixable Infections
Telegram zero-day allowed sending malicious Android APKs as videos
Critical Exim bug bypasses security filters on 1.5 million mail servers
New Blast-RADIUS attack breaks 30-year-old protocol used in networks everywhere
CVE-2024-38021: Moniker RCE Vulnerability Uncovered in Microsoft Outlook
Hackers target WordPress calendar plugin used by 150,000 sites
New Intel CPU Vulnerability 'Indirector' Exposes Sensitive Data
RoguePuppet – A Critical Puppet Forge Supply Chain Vulnerability
Critical GitLab bug lets attackers run pipelines as any user
Critical SQLi Vulnerability Found in Fortra FileCatalyst Workflow Application
UEFIcanhazbufferoverflow: Widespread Impact from Vulnerability in Popular PC and Server Firmware
Facebook PrestaShop module exploited to steal credit cards
Zero-Click Critical Microsoft Outlook Vulnerability. What You Need to Know.
Arm Warns of Actively Exploited Zero-Day Vulnerability in Mali GPU Drivers
Black Basta ransomware gang linked to Windows zero-day attacks
Microsoft June 2024 Patch Tuesday fixes 51 flaws, 18 RCEs
Vulnerability in Cisco Webex cloud service exposed government authorities, companies
Zero Day Initiative — CVE-2024-30043: Abusing URL Parsing Confusion to Exploit XXE on SharePoint Server and Cloud
TeamCity Major Bug-Fix Release for All Versions: Update Your Server Now | The TeamCity Blog
Cache Me If You Can: Local Privilege Escalation in Zscaler Client Connector (CVE-2023-41973)
QNAPping At The Wheel (CVE-2024-27130 and friends)
PoC exploit released for RCE zero-day in D-Link EXO AX4800 routers
WP Automatic WordPress plugin hit by millions of SQL injection attacks
Unauthenticated function injection vulnerability in WordPress Shortcode Addons plugin (unpatched). – NinTechNet
Vulnerabilities Identified in LG WebOS
Over 92,000 exposed D-Link NAS devices have a backdoor account
Bringing process injection into view(s): exploiting all macOS apps using nib files · Sector 7
New HTTP/2 DoS attack can crash web servers with a single connection
Google fixes two Pixel zero-day flaws exploited by forensics firms
Ivanti fixes critical Standalone Sentry bug reported by NATO
Loop DoS: New Denial-of-Service attack targets application-layer protocols
'GhostRace' Speculative Execution Attack Impacts All CPU, OS Vendors
JetBrains vulnerability exploitation highlights debate over 'silent patching'
Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities
Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day - Avast Threat Labs
ConnectWise ScreenConnect: Authentication Bypass Deep Dive
ESET fixed high-severity local privilege escalation bug in Windows products
Hackers exploit Ivanti SSRF flaw to deploy new DSLog backdoor
Fortinet warns of new FortiSIEM RCE bugs in confusing disclosure
Leaky Vessels flaws allow hackers to escape Docker, runc containers
Apple fixes zero-day bug in Apple Vision Pro that 'may have been exploited'
Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines
Over 5,300 GitLab servers exposed to zero-click account takeover attacks
Opera MyFlaw Bug Could Let Hackers Run ANY File on Your Mac or Windows
Beware! YouTube Videos Promoting Cracked Software Distribute Lumma Stealer
CVE-2024-21591 - Juniper J-Web OOB Write vulnerability
Qualcomm chip vulnerability enables remote attack by voice call
Chinese Hackers Exploited New Zero-Day in Barracuda's ESG Appliances
Hackers Exploiting MS Excel Vulnerability to Spread Agent Tesla Malware
Unveiling VISS: a revolutionary approach to vulnerability impact scoring
Terrapin attacks can downgrade security of OpenSSH connections
QNAP VioStor NVR vulnerability actively exploited by malware botnet
Exploiting GOG Galaxy XPC service for privilege escalation in macOS
Imperva Uncovers CVE-2023-22524, A RCE Vulnerability
GitHub - yunuscadirci/DIALStranger: details about DIAL protocol vulnerabilities
In a first, cryptographic keys protecting SSH connections stolen in new attack | Ars Technica
CVE-2023-38548
SysAid On-Prem Software CVE-2023-47246 Vulnerability
Common Vulnerability Scoring System
FIRST Announces CVSS 4.0 - New Vulnerability Scoring System
HackerOne paid ethical hackers over $300 million in bug bounties
Compromising F5 BIGIP with Request Smuggling | CVE-2023-46747
VMSA-2023-0023
CVE-2023-4911: Looney Tunables - Local Privilege Escalation in the glibc’s ld.so
Qualcomm says hackers exploit 3 zero-days in its GPU, DSP drivers
Vulnerability in popular ‘libwebp’ code more widespread than expected
Can't Be Contained: Finding a Command Injection Vulnerability in Kubernetes
CVE-2023-34127
New ‘Downfall’ Flaw Exposes Valuable Data in Generations of Intel Chips
CVE-2023-35082 - MobileIron Core Unauthenticated API Access Vulnerability | Rapid7 Blog
Ivanti warns of second vulnerability used in attacks on Norway gov’t
Almost 40% of Ubuntu users vulnerable to new privilege elevation flaws
CVE-2023-38408: Remote Code Execution in OpenSSH’s forwarded ssh-agent
KeePassXC Vulnerability CVE-2023-35866 allows attackers to change the master password and second-factor authentication settings
A simple bug exposed access to thousands of smart security alarm systems
CVE-2023-34362: MOVEit Transfer SQL Injection Vulnerability Threat Brief
Rapid7 Observed Exploitation of Critical MOVEit Transfer Vulnerability
New macOS vulnerability, Migraine, could bypass System Integrity Protection | Microsoft Security Blog
Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft
WordPress Plugin Vulnerability Exposed Ferrari Website to Hackers
The Race to Patch: Attackers Leverage Sample Exploit Code in Wordpress Plugin | Akamai
oss-sec: [CVE-2023-32233] Linux kernel use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary reads and writes in kernel memory
WordPress Advanced Custom Fields Pro plugin <= 6.1.5 - Reflected Cross Site Scripting (XSS) vulnerability
VMware Patches Critical Vulnerability Disclosed at Pwn2Own Hacking Contest
Analysis of Pre-Auth RCE in Sophos Web Appliance (CVE-2023-1671)
Google Chrome emergency update fixes first zero-day of 2023
CVE-2023-27532
PoC exploit for recently patched Microsoft Word RCE is public (CVE-2023-21716)
Technical Advisory: Various Threat Actors Targeting ManageEngine Exploit CVE-2022-47966
OpenSSL fixes High Severity data-stealing bug – patch now!
Apple patches are out – old iPhones get an old zero-day fix at last!
New GTA Online exploit now allows cheaters to ban your account
Jenkins discloses dozens of zero-day bugs in multiple plugins
Hacker claims to be selling Twitter data of 400 million users
Critical Ping Vulnerability Allows Remote Attackers to Take Over FreeBSD Systems
CVE-2022-21661: Exposing Database Info via WordPress SQL Injection
Google pushes emergency Chrome update to fix 8th zero-day in 2022
Firefox fixes fullscreen fakery flaw – get the update now! – Naked Security
Compromising Plesk via its REST API
Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049)
Mirai, RAR1Ransom, and GuardMiner – Multiple Malware Campaigns Target VMware Vulnerability
Analysis of a Remote Code Execution (RCE) Vulnerability in Cobalt Strike 4.7.1
Jamf Threat Labs identifies macOS Archive Utility vulnerability allowing for Gatekeeper bypass (CVE-2022-32910)
CVE-2022-41352
Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server
Unpatched 15-year old Python bug allows code execution in 350k projects
Tarfile: Exploiting the World With a 15-Year-Old Vulnerability
PSA: Nearly 5 Million Attacks Blocked Targeting 0-Day in BackupBuddy Plugin
Researchers found one-click exploits in Discord and Teams
[CVE-2022-34918] A crack in the Linux firewall
Zimbra Email - Stealing Clear-Text Credentials via Memcache injection
Vulnerability discovered in Apple M1 chip
Remote Code Execution on Western Digital PR4100 NAS (CVE-2022-23121)
Exploiting an Unbounded memcpy in Parallels Desktop
Zyxel silently patches command-injection vulnerability with 9.8 severity rating
Vulnerability Analysis - CVE-2022-1388
Nozomi Networks Discovers Unpatched DNS Bug in Popular C Standard Library Putting IoT at Risk
Dec0ne/KrbRelayUp: KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).
Microsoft finds new elevation of privilege Linux vulnerability, Nimbuspwn
Git security vulnerability announced
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
PROPHET SPIDER Exploits Citrix ShareFile
Armis Finds Three Critical Zero-Day Vulnerabilities in APC Smart-UPS Devices, Dubbed "TLStorm," Exposing More than 20 Million Enterprise Devices
New Linux Vulnerability CVE-2022-0492 Affecting Cgroups: Can Containers Escape?