Posts of last 24 hours
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.
https://therecord.media/lawmakers-call-for-investigation-into-impact-of-cisa-cuts
The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data.
The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.
https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.
"When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's
https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html
A vulnerability identified as critical has been detected in Microsoft Azure DevOps Server 2020.1.2. Affected by this vulnerability is an unknown functionality. This manipulation causes code injection.
This vulnerability is tracked as CVE-2023-21553. The attack is possible to be carried out remotely. No exploit exists.
Applying a patch is the recommended action to fix this issue.
https://vuldb.com/vuln/220958
A vulnerability marked as critical has been reported in Microsoft Visual Studio 2017 15.9/2019 16.11/2022 17.0/2022 17.2/2022 17.4. This affects an unknown part. Performing a manipulation results in file inclusion.
This vulnerability is cataloged as CVE-2023-21566. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
https://vuldb.com/vuln/220960
A vulnerability was found in Microsoft Dynamics 365 9.0/9.1. It has been classified as problematic. This affects an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-21807. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to install a patch to address this issue.
https://vuldb.com/vuln/221010
A vulnerability identified as critical has been detected in Microsoft Windows. Affected by this issue is some unknown functionality of the component Common Log File System Driver. Performing a manipulation results in heap-based buffer overflow.
This vulnerability was named CVE-2023-21812. The attack may be initiated remotely. There is no available exploit.
Applying a patch is the recommended action to fix this issue.
https://vuldb.com/vuln/221014
A vulnerability classified as critical has been found in Microsoft Windows. Impacted is an unknown function of the component Kerberos. This manipulation causes improper authentication.
This vulnerability is tracked as CVE-2023-21817. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to install a patch to address this issue.
https://vuldb.com/vuln/221018
A vulnerability, which was classified as critical, was found in Microsoft Windows. This affects an unknown function of the component Distributed File System. Executing a manipulation can lead to buffer over-read.
This vulnerability is registered as CVE-2023-21820. It is possible to launch the attack remotely. No exploit is available.
It is advisable to implement a patch to correct this issue.
https://vuldb.com/vuln/221021