Aggregator
Дуализм РНК: NASA доказало случайность фундаментального выбора жизни
2 days 2 hours ago
Исследование бросает вызов традиционным представлениям о молекулах.
Feds Indict 5 Suspects Tied to Scattered Spider Cybercrime
2 days 2 hours ago
FBI Ties Suspects to at Least 45 Attacks and Theft of Cryptocurrency Worth Millions
The U.S. government on Wednesday unsealed criminal charges against five suspected members of the "loosely organized, financially motivated cybercriminal group" Scattered Spider. The suspects have been tied to 45 attacks, disrupting businesses and stealing cryptocurrency worth millions of dollars.
The U.S. government on Wednesday unsealed criminal charges against five suspected members of the "loosely organized, financially motivated cybercriminal group" Scattered Spider. The suspects have been tied to 45 attacks, disrupting businesses and stealing cryptocurrency worth millions of dollars.
Cryptohack Roundup: No Prison Time for FTX's Gary Wang
2 days 2 hours ago
Also: Bitfinex Launderer Razzlekhan Gets 18-Month Sentence
This week, sentences in FTX, Bitfinex and Helix cases, a $25.5M Thala hack, the WazirX hack and South Korea probed UpBit. U.S. lawmakers want a crackdown on Tornado. U.S. Prosecutors may scale back crypto cases. BIT Mining fined $10M and the Chinese Communist Party expelled a key blockchain figure
This week, sentences in FTX, Bitfinex and Helix cases, a $25.5M Thala hack, the WazirX hack and South Korea probed UpBit. U.S. lawmakers want a crackdown on Tornado. U.S. Prosecutors may scale back crypto cases. BIT Mining fined $10M and the Chinese Communist Party expelled a key blockchain figure
Over 145,000 Industrial Control Systems Across 175 Countries Found Exposed Online
2 days 2 hours ago
New research has uncovered more than 145,000 internet-exposed Industrial Control Systems (ICS) acro
CVE-2024-10492 | Keycloak Vault File information disclosure
2 days 2 hours ago
A vulnerability, which was classified as problematic, has been found in Keycloak. This issue affects some unknown processing of the component Vault File Handler. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-10492. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-10451 | Keycloak Build Process information disclosure
2 days 2 hours ago
A vulnerability classified as problematic was found in Keycloak. This vulnerability affects unknown code of the component Build Process. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-10451. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
Microsoft pulls WinAppSDK update breaking Windows 10 app uninstalls
2 days 2 hours ago
Microsoft has confirmed that, since November 12, some Windows 10 users have been unable to update or uninstall packaged applications like Microsoft Teams. [...]
Sergiu Gatlan
CVE-2024-10270 | Keycloak SearchQueryUtils redos
2 days 2 hours ago
A vulnerability classified as problematic has been found in Keycloak. This affects the function SearchQueryUtils. The manipulation leads to inefficient regular expression complexity.
This vulnerability is uniquely identified as CVE-2024-10270. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-10039 | Keycloak mTLS improper authentication
2 days 2 hours ago
A vulnerability was found in Keycloak. It has been rated as critical. Affected by this issue is some unknown functionality of the component mTLS Handler. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2024-10039. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-9666 | Keycloak up to 26 Proxy Header denial of service
2 days 2 hours ago
A vulnerability was found in Keycloak up to 26. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Proxy Header Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-9666. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-52307 | authentik prior 2024.8.5/2024.10.3 /-/metrics/ SECRET_KEY timing discrepancy
2 days 2 hours ago
A vulnerability was found in authentik. It has been classified as problematic. Affected is an unknown function of the file /-/metrics/. The manipulation of the argument SECRET_KEY leads to observable timing discrepancy.
This vulnerability is traded as CVE-2024-52307. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DPRK IT Workers | A Network of Active Front Companies and Their Links to China
2 days 2 hours ago
Executive SummarySentinelLabs has identified unique characteristics of multiple website
CVE-2024-53093 | Linux Kernel up to 6.1.117/6.6.61/6.11.8 nvme-multipath scan_work deadlock
2 days 2 hours ago
A vulnerability was found in Linux Kernel up to 6.1.117/6.6.61/6.11.8 and classified as critical. This issue affects the function scan_work of the component nvme-multipath. The manipulation leads to deadlock.
The identification of this vulnerability is CVE-2024-53093. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53090 | Linux Kernel up to 6.11.8 afs_wake_up_async_call recursion (d7cbf81df996/610a79ffea02)
2 days 2 hours ago
A vulnerability has been found in Linux Kernel up to 6.11.8 and classified as problematic. This vulnerability affects the function afs_wake_up_async_call. The manipulation leads to uncontrolled recursion.
This vulnerability was named CVE-2024-53090. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53094 | Linux Kernel up to 6.6.61/6.11.8 RDMA sendpage_ok stack-based overflow (3406bfc813a9/bb5738957d92/4e1e3dd88a4c)
2 days 2 hours ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.61/6.11.8. This affects the function sendpage_ok of the component RDMA. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-53094. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-51337 | Gibbon up to 27.0.00 user_manage_editProcess.php. email cross site scripting
2 days 2 hours ago
A vulnerability, which was classified as problematic, has been found in Gibbon up to 27.0.00. Affected by this issue is some unknown functionality of the file /Gibbon/modules/User Admin/user_manage_editProcess.php.. The manipulation of the argument email leads to cross site scripting.
This vulnerability is handled as CVE-2024-51337. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53091 | Linux Kernel up to 6.6.61/6.11.8 bpf tls_sw_ctx_rx memory corruption (a078a480ff3f/6781cfa93a6a/44d0469f79bd)
2 days 2 hours ago
A vulnerability classified as critical was found in Linux Kernel up to 6.6.61/6.11.8. Affected by this vulnerability is the function tls_sw_ctx_rx of the component bpf. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2024-53091. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53095 | Linux Kernel up to 6.6.61/6.11.8 SMB Client tcp_write_timer_handler reference count (e8c714941811/c7f9282fc27f/ef7134c7fc48)
2 days 2 hours ago
A vulnerability classified as problematic has been found in Linux Kernel up to 6.6.61/6.11.8. Affected is the function tcp_write_timer_handler of the component SMB Client. The manipulation leads to improper update of reference count.
This vulnerability is traded as CVE-2024-53095. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53089 | Linux Kernel up to 6.11.8 LoongArch stack-based overflow (1e4c384a4be9/73adbd92f322)
2 days 2 hours ago
A vulnerability was found in Linux Kernel up to 6.11.8. It has been rated as critical. This issue affects some unknown processing of the component LoongArch. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-53089. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com