Aggregator
新型 SteelFox 恶意软件冒充流行软件窃取浏览器数据
1 year 5 months ago
安全客
CVE-2024-11026 | Intelligent Apps Freenow App 12.10.0 on Android Keystore SSL.java DEFAULT_KEYSTORE_PASSWORD hard-coded password
1 year 5 months ago
A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ch/qos/logback/core/net/ssl/SSL.java of the component Keystore Handler. The manipulation of the argument DEFAULT_KEYSTORE_PASSWORD with the input changeit leads to use of hard-coded password.
This vulnerability is handled as CVE-2024-11026. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
APT73
1 year 5 months ago
cohenido
Apache ZooKeeper 安全警报:影响 Admin Server 的重要缺陷 (CVE-2024-51504)
1 year 5 months ago
安全客
CVE-2015-0569 | Google Android Qualcomm Wi-Fi Driver memory corruption (EDB-39308 / BID-77691)
1 year 5 months ago
A vulnerability was found in Google Android. It has been classified as critical. Affected is an unknown function of the component Qualcomm Wi-Fi Driver. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2015-0569. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #434538: Intelligent Apps GmbH FREENOW (ex Beat app) 12.10.0 Use of Hard-coded, Security-relevant Constants [Accepted]
1 year 5 months ago
Submit #434538 / VDB-283544
secuserx
小心 Python 开发人员: 恶意 “fabrice ”软件包从 37,000 多次下载中窃取 AWS 凭据
1 year 5 months ago
安全客
CVE-2024-50592 | Hasomed Elefant prior 1.4.2.1811 Update Service PostESUUpdate.exe toctou
1 year 5 months ago
A vulnerability was found in Hasomed Elefant. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file PostESUUpdate.exe of the component Update Service. The manipulation leads to time-of-check time-of-use.
This vulnerability is known as CVE-2024-50592. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CISA 扩展了 KEV 目录,增加了四个被积极利用的漏洞
1 year 5 months ago
安全客
CVE-2024-40715 | Veeam Enterprise Manager up to 12.2 channel accessible (kb4682)
1 year 5 months ago
A vulnerability was found in Veeam Enterprise Manager up to 12.2. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to channel accessible by non-endpoint.
This vulnerability was named CVE-2024-40715. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Veeam security advisory (AV24-637)
1 year 5 months ago
Canadian Centre for Cyber Security
Xlight FTP Server整数溢出漏洞(CVE-2024-46483)分析与复现
1 year 5 months ago
Xlight FTP Server整数溢出漏洞(CVE-2024-46483)分析与复现
AndroxGh0st Malware Integrates Mozi Botnet to Target IoT and Cloud Services
1 year 5 months ago
The threat actors behind the AndroxGh0st malware are now exploiting a broader set of security flaws impacting various internet-facing applications, while also deploying the Mozi botnet malware.
"This botnet utilizes remote code execution and credential-stealing methods to maintain persistent access, leveraging unpatched vulnerabilities to infiltrate critical infrastructures," CloudSEK said in a
The Hacker News
CVE-2024-20697 | Microsoft Windows 11 22H2/11 23H2/Server 2022 23H2 Libarchive Remote Code Execution (Nessus ID 210576)
1 year 5 months ago
A vulnerability was found in Microsoft Windows 11 22H2/11 23H2/Server 2022 23H2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Libarchive. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2024-20697. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-51504 | Apache ZooKeeper up to 3.9.2 HTTP Request Header improper authentication (Nessus ID 210584)
1 year 5 months ago
A vulnerability has been found in Apache ZooKeeper up to 3.9.2 and classified as critical. This vulnerability affects unknown code of the component HTTP Request Header Handler. The manipulation leads to improper authentication.
This vulnerability was named CVE-2024-51504. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
知行合一:丈八网络靶场平台赋能“实战型”网络安全人才建设
1 year 5 months ago
丈八网安作为网络仿真技术及应用服务提供商,通过创新型网络靶场产品和技术提供了行之有效的解决方案。
Microsoft SharePoint RCE 漏洞可被利用来破坏公司网络
1 year 5 months ago
自 2024 年 6 月以来未应用 SharePoint 更新的系统管理员必须尽快执行此操作。
AI Summit Vancouver 2024: Exploring AI’s Role, Risks, and Transformative Power
1 year 5 months ago
At AI Summit Vancouver, experts explored AI ethics, security practices, and balancing innovation with a responsibility to shape a safer AI-empowered future.
The post AI Summit Vancouver 2024: Exploring AI’s Role, Risks, and Transformative Power appeared first on Security Boulevard.
Dwayne McDaniel
More From Our Main Blog: The Good, the Bad and the Ugly in Cybersecurity – Week 45
1 year 5 months ago
Authorities arrest data thief and disrupt cybercrime infrastructure, North Korean APT targets Macs for crypto, and AWS keys stolen via fake PyPi package.
The post The Good, the Bad and the Ugly in Cybersecurity – Week 45 appeared first on SentinelOne.
SentinelOne