Aggregator
CVE-2022-20484 | Google Android 10.0/11.0/12.0/13.0 NotificationChannel.java NotificationChannel resource consumption (A-242702851)
CVE-2022-20485 | Google Android 10.0/11.0/12.0/13.0 NotificationChannel.java NotificationChannel resource consumption (A-242702935)
CVE-2022-20502 | Google Android 13.0 entrypoint_utils-inl.h GetResolvedMethod information disclosure (A-222166527)
CVE-2022-20477 | Google Android 13.0 KeyguardNotificationVisibilityProvider.kt shouldHideNotification Local Privilege Escalation (A-241611867)
CVE-2022-20501 | Google Android 10.0/11.0/12.0/13.0 EnableAccountPreferenceActivity.java onCreate ui layer (A-246933359)
CVE-2022-20611 | Google Android 10.0/11.0/12.0/13.0 DeletePackageHelper.java deletePackageVersionedInternal permission (A-242996180)
CVE-2023-4238 | Prevent Files Access Plugin up to 2.5.1 on WordPress mo_media_restrict_page unrestricted upload
CVE-2023-4251 | EventPrime Plugin up to 3.1.x on WordPress cross-site request forgery (Duplicate CVE-2023-5519)
玛莎百货确认遭遇“网络事件”
Один клик для кражи, один запрос для ключей: как библиотека Ripple сливала приватные данные хакерам
CVE-2014-3415 | Sharetronix 3.1.1/3.3 invite_users[] sql injection (Advisory 126859 / EDB-33557)
Phishing emails delivering infostealers surge 84%
Cybercriminals continued to shift to stealthier tactics, with lower-profile credential theft spiking, while ransomware attacks on enterprises declined, according to IBM. Researchers observed an 84% increase in emails delivering infostealers in 2024 compared to the prior year, a method threat actors relied heavily on to scale identity attacks. 70% of attacks in 2024 involved critical infrastructure. In this subset, the use of valid accounts made up 31% of initial access vectors, followed by phishing and … More →
The post Phishing emails delivering infostealers surge 84% appeared first on Help Net Security.
Skyhawk Security enhances Autonomous Purple Team to secure custom cloud apps
Skyhawk Security expanded its AI-powered Autonomous Purple Team to include custom cloud applications. For the first time, organizations can preemptively and continuously secure custom cloud applications and their cloud infrastructure without agents. This innovation protects against today’s biggest cloud security issue, one exploited in recent attacks including the MOVEit Transfer breach, the XZ Utils backdoor, a Google Cloud metadata exposure via a web application flaw and Log4j and Log4Shell—thus closing the gap between application security … More →
The post Skyhawk Security enhances Autonomous Purple Team to secure custom cloud apps appeared first on Help Net Security.