Aggregator
BlackSuit ransomware stole data of 950,000 from software vendor
4 months 3 weeks ago
Young Consulting is sending data breach notifications to 954,177 people who had their information exposed in a BlackSuit ransomware attack on April 10, 2024. [...]
Bill Toulas
PoC Exploit for Zero-Click Vulnerability Made Available to the Masses
4 months 3 weeks ago
The exploit can be accessed on GitHub and makes it easier for the flaw to be exploited by threat actors.
Dark Reading Staff
How Security Teams are Strengthening Their Threat Hunting
4 months 3 weeks ago
According to "Voice of a Threat Hunter 2024" Security teams need to keep evolving their strategies to protect their organizations against...
The post How Security Teams are Strengthening Their Threat Hunting appeared first on Security Boulevard.
tcblogposts
US Marshals Service disputes ransomware gang's breach claims
4 months 3 weeks ago
The U.S. Marshals Service (USMS) denies its systems were breached by the Hunters International ransomware gang after being listed as a new victim on the cybercrime group's leak site on Monday. [...]
Sergiu Gatlan
Windows Downdate Attacks, Quick Share Vulnerability Exploit, and More: Hacker’s Playbook Threat Coverage Round-up: August 2024
4 months 3 weeks ago
New and updated coverage for Windows Downdate Attacks, Quick Share Vulnerability Exploit, MagicRAT, and More
The post Windows Downdate Attacks, Quick Share Vulnerability Exploit, and More: Hacker’s Playbook Threat Coverage Round-up: August 2024 appeared first on SafeBreach.
The post Windows Downdate Attacks, Quick Share Vulnerability Exploit, and More: Hacker’s Playbook Threat Coverage Round-up: August 2024 appeared first on Security Boulevard.
Kaustubh Jagtap
China-linked APT Volt Typhoon exploited a zero-day in Versa Director
4 months 3 weeks ago
China-linked APT group Volt Typhoon exploited a zero-day flaw in Versa Director to upload a custom webshell in target networks. China-linked APT Volt Typhoon exploited a zero-day vulnerability, tracked as CVE-2024-39717, in Versa Director, to deploy a custom webshell on breached networks. Versa Director is a centralized management and orchestration platform used primarily by Internet […]
Pierluigi Paganini
CVE-2024-6312 | Funnelforms Free Plugin up to 3.7.3.2 on WordPress improper authentication
4 months 3 weeks ago
A vulnerability was found in Funnelforms Free Plugin up to 3.7.3.2 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2024-6312. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6311 | Funnelforms Free Plugin up to 3.7.3.2 on WordPress unrestricted upload
4 months 3 weeks ago
A vulnerability was found in Funnelforms Free Plugin up to 3.7.3.2 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to unrestricted upload.
This vulnerability was named CVE-2024-6311. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Microsoft's Sway Serves as Launchpad for 'Quishing' Campaign
4 months 3 weeks ago
The attack is a mashup of QR codes and phishing that gets users to click on links to malicious webpages.
Dark Reading Staff
CVE-2024-6448 | Mollie Payments for WooCommerce Plugin up to 7.7.0 on WordPress information disclosure
4 months 3 weeks ago
A vulnerability was found in Mollie Payments for WooCommerce Plugin up to 7.7.0 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-6448. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-42851 | exiftags 1.01 paresetag buffer overflow
4 months 3 weeks ago
A vulnerability was found in exiftags 1.01 and classified as critical. Affected by this issue is the function paresetag. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2024-42851. Local access is required to approach this attack. There is no exploit available.
vuldb.com
CVE-2024-45264 | SkySystem Arfa-CMS up to 5.1.3123 cross-site request forgery
4 months 3 weeks ago
A vulnerability has been found in SkySystem Arfa-CMS up to 5.1.3123 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-45264. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-36068 | Rubrik CDM up to 8.1.3-p11/9.0.3-p5/9.1.2 access control
4 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Rubrik CDM up to 8.1.3-p11/9.0.3-p5/9.1.2. Affected is an unknown function. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2024-36068. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40395 | PTC ThingWorx 9.5.0 resource injection
4 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in PTC ThingWorx 9.5.0. This issue affects some unknown processing. The manipulation leads to improper control of resource identifiers.
The identification of this vulnerability is CVE-2024-40395. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-5991 | wolfSSL up to 5.7.0 MatchDomainName out-of-bounds
4 months 3 weeks ago
A vulnerability classified as critical was found in wolfSSL up to 5.7.0. This vulnerability affects the function MatchDomainName. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2024-5991. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-1544 | wolfSSL up to 5.6.4 Elliptic Curve information exposure
4 months 3 weeks ago
A vulnerability classified as problematic has been found in wolfSSL up to 5.6.4. This affects an unknown part of the component Elliptic Curve Handler. The manipulation leads to information exposure through discrepancy.
This vulnerability is uniquely identified as CVE-2024-1544. Local access is required to approach this attack. There is no exploit available.
vuldb.com
Windows 11 KB5041587 update adds sharing to Android devices
4 months 3 weeks ago
Microsoft has released the optional KB5041587 preview cumulative update for Windows 11 23H2 and 22H2, which adds sharing to Android devices and fixes multiple File Explorer issues. [...]
Sergiu Gatlan
CVE-2022-39997 | Teldats RS123/RS123w weak password
4 months 3 weeks ago
A vulnerability was found in Teldats RS123 and RS123w. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to weak password requirements.
This vulnerability is handled as CVE-2022-39997. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-5814 | wolfSSL up to 5.7.0 TLS downgrade
4 months 3 weeks ago
A vulnerability was found in wolfSSL up to 5.7.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component TLS Handler. The manipulation leads to algorithm downgrade.
This vulnerability is known as CVE-2024-5814. The attack can be launched remotely. There is no exploit available.
vuldb.com