Aggregator
SMB Force-Authentication Vulnerability Impacts All OPA Versions For Windows
Open Policy Agent (OPA) recently patched a critical vulnerability that could have exposed NTLM credentials of the OPA server’s local user account to remote attackers, which was present in both the OPA CLI and Go SDK. By exploiting this flaw, attackers could have compromised the OPA server’s authentication mechanisms and potentially gained unauthorized access to […]
The post SMB Force-Authentication Vulnerability Impacts All OPA Versions For Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Latrodectus Employs New anti-Debugging And Sandbox Evasion Techniques
Latrodectus, a new malware loader, has rapidly evolved since its discovery, potentially replacing IcedID. It includes a command to download IcedID and has undergone multiple iterations, likely to evade detection. Extracting configurations from these versions is crucial for effective threat detection, as the Latrodectus malware has evolved over the past year, with new versions released […]
The post Latrodectus Employs New anti-Debugging And Sandbox Evasion Techniques appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-50481 | Stack Themes Bstone Demo Importer Plugin up to 1.0.1 on WordPress privileges assignment
CVE-2024-50426 | Survey Maker Plugin up to 5.0.2 on WordPress cross site scripting
CVE-2024-46872 | Mattermost up to 9.5.9/9.10.2/9.11.1 Playbook cross-site request forgery
CVE-2024-50420 | aDirectory Plugin up to 1.3 on WordPress unrestricted upload
CVE-2024-50476 | Grün Spendino Spendenformular Plugin up to 1.0.1 on WordPress authorization
CVE-2024-10241 | Mattermost up to 9.5.9 Channel Name access control
CVE-2024-50418 | Time Slot Booking Time Slot Plugin up to 1.3.6 on WordPress cross site scripting
CVE-2024-50473 | Ajar in5 Embed Plugin up to 3.1.3 on WordPress unrestricted upload
Hardcoded Creds in Popular Apps Put Millions of Android and iOS Users at Risk
Recent analysis has revealed a concerning trend in mobile app security: Many popular apps store hardcoded and unencrypted cloud service credentials directly within their codebases. It poses a significant security risk as anyone accessing the app’s binary or source code could extract and misuse these credentials to manipulate or exfiltrate data. Examples include Pic Stitch, […]
The post Hardcoded Creds in Popular Apps Put Millions of Android and iOS Users at Risk appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-50415 | Pagup Ads.txt & App-ads.txt Manager Plugin up to 1.1.7.1 on WordPress cross site scripting
CVE-2024-50484 | Mahlamusa Multi Purpose Mail Form Plugin up to 1.0.2 on WordPress unrestricted upload
CVE-2024-47401 | Mattermost up to 9.5.9/9.10.2/9.11.1 GraphQL Response allocation of resources
CVE-2024-50493 | masterhomepage Automatic Translation Plugin up to 1.0.4 on WordPress unrestricted upload
永久激活GPT4.0!有效期至2296年!我上车了!!
PIXM protects MSPs from credential theft and phishing attacks
PIXM Security launched its new Managed Service Provider (MSP) program for zero-day phishing protection. With over 500,000 end users already protected, PIXM shields MSPs and their customers from credential theft and zero-day phishing attacks that can lead to malware and other exploits on their laptops, desktops and mobile platforms. Over 50 percent of phishing links are clicked outside corporate email. While phishing security is often associated solely with email protection, cybercriminals are adapting and increasingly … More →
The post PIXM protects MSPs from credential theft and phishing attacks appeared first on Help Net Security.