Aggregator
The DxSale Liquidity Drain: Exploiting Legacy Web3 Architecture
The Awakening of Dormant Exploits Legacy tools within the cryptographic ecosystem can remain dormant for years. Subsequently, a solitary vulnerability transforms them into a source of catastrophic losses. This exact scenario plagued DxSale, a...
The post The DxSale Liquidity Drain: Exploiting Legacy Web3 Architecture appeared first on Information Security News.
The Sophistication of Kimsuky: Deceptive Social Engineering and Tiered Infection
Evolution of Tactical Delivery The North Korean cyber-adversary Kimsuky has abandoned rudimentary malware distribution strategies. Instead, their modern campaigns target South Korean military and corporate structures with immense precision. These operations deploy impeccably forged...
The post The Sophistication of Kimsuky: Deceptive Social Engineering and Tiered Infection appeared first on Information Security News.
CVE-2020-8554 | Oracle Communications Cloud Native Core Service Communication Proxy SCP authorization
CVE-2020-8554 | Oracle Communications Cloud Native Core Unified Data Repository UDR authorization
CVE-2020-8554 | Kubernetes API Server permission
CVE-2020-8561 | Kubernetes kube-apiserver Request confused deputy (Issue 10472)
CVE-2021-25740 | Kubernetes Network Traffic confused deputy (Issue 10367)
CVE-2020-8562 | Kubernetes DNS Resolution toctou (Issue 10149 / Nessus ID 256688)
CVE-2020-8554 | Oracle Communications Cloud Native Core Policy 1.15.0 authorization
CVE-2024-12146 | Finder Fire Safety Finder ERP CRM prior 18.12.2024 improper validation of syntactic correctness of input
CVE-2024-12604 | Tapandsign Tap&Sign App prior 1.025 Environment Variable exposure of sensitive information through environmental variables
CVE-2025-21847 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 sof_ipc_msg_data null pointer dereference (Nessus ID 236983 / WID-SEC-2025-0545)
CVE-2025-21863 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 io_uring privilege escalation (Nessus ID 236983 / WID-SEC-2025-0545)
Supply Chain Sabotage: The Infiltration of the npm Registry
The Threat of Weaponized Packages Attacks on software developers no longer require breaching a massive corporate platform. Instead, a single cleverly disguised package achieves the same devastating result. A recent incident within the npm...
The post Supply Chain Sabotage: The Infiltration of the npm Registry appeared first on Information Security News.
礼盒上线!地球Online日历提醒您,端午副本已开启
CVE-2023-2058 | EyouCms up to 1.6.2 HTTP POST Request mesedit&tabid=12&id=4 web_ico cross site scripting (Nessus ID 318102)
CVE-2024-14027 | Linux Kernel xattr memory allocation (EUVD-2024-55470 / Nessus ID 318102)
CVE-2026-49017 | OpenStack Swift up to 2.36.1/2.37.1 StreamingInput infinite loop (EUVD-2026-32040 / Nessus ID 318110)
The Distributed Extraction: Masking Scrapers Behind Residential Networks
The Anatomy of the Data Harvest Millions of standard residential IP addresses across the internet can convincingly mimic human readers. However, a malicious automated scraper often lurks behind this facade. Consequently, the website Arab...
The post The Distributed Extraction: Masking Scrapers Behind Residential Networks appeared first on Information Security News.