Aggregator
'Sitting Ducks' Attacks Create Hijacking Threat for Domain Name Owners
Twilio kills off Authy for desktop, forcibly logs out all users
Protect your mini-me—How to prevent child identity theft
Most parents work hard thinking about their little one’s future ahead—imagining it bright and full of possibilities, while doing all they can to protect it. But there may be identity thieves snooping around, looking to target your child and mess with that future before they even know what a credit score is.
The post Protect your mini-me—How to prevent child identity theft appeared first on Security Boulevard.
CVE-2024-7029 | AVTECH AVM1203 up to FullImg-1023-1007-1011-1009 command injection (icsa-24-214-07)
CVE-2024-4353 | Concrete CMS up to 9.3.2 Generate Dashboard Board Name cross site scripting
CVE-2024-41259 | Navidrome 0.52.3 Gravatar Service weak hash
CVE-2024-7211 | 1E Platform 8.4.1.229/23.7.1.80/23.11.1.15/24.7 redirect
CVE-2024-41260 | netbird 0.28.4 Initialization encrypt predictable state
CVE-2024-39633 | IdeaBox PowerPack for Beaver Builder Plugin up to 2.33.0 on WordPress privileges management
CVE-2024-6040 | parisneo lollms-webui up to 9.8 lollms_binding_infos client_id cross-site request forgery
CVE-2024-41264 | Casdoor 1.636.0 ssh.InsecureIgnoreHostKey information disclosure
CVE-2024-41265 | Cortex 0.42.1 TLS Certificate Verification makeOperatorRequest information disclosure
CVE-2024-41962 | Yonle bostr up to 3.0.9 authorized_keys improper authorization (GHSA-5cf7-cxrf-mq73)
CVE-2024-23600 | Ping Identity OPENIDM up to 7.5.0 Query Search Result information disclosure
CVE-2024-6242 | Rockwell Automation ControlLogix 5580 1756-L8z Trusted Slot unprotected alternate channel
CVE-2024-41961 | sapcc elektra Live Search code injection (GHSA-6j2h-486h-487q)
CVE-2024-6873 | ClickHouse Native Interface heap-based overflow (GHSA-432f-r822-j66f)
Tech support scam ring leader gets 7 years in prison, $6M fine
Widespread OTP-Stealing Campaign Targets Android Users
Zimperium researchers discovered a widespread and sophisticated malware campaign dubbed SMS Stealer that's being used against Android device users to steal OTPs from text messages, which can lead to account takeover and ransomware attacks.
The post Widespread OTP-Stealing Campaign Targets Android Users appeared first on Security Boulevard.